From aa7112d6bc4621be487f887a691ad2569f05fe0c Mon Sep 17 00:00:00 2001 From: delgado-jacob <29643013+delgado-jacob@users.noreply.github.com> Date: Tue, 21 Jan 2025 13:40:35 -0700 Subject: [PATCH 01/67] Add descriptions and mitre components to data sources --- data_sources/asl_aws_cloudtrail.yml | 15 ++++++++++++++- data_sources/aws_cloudfront.yml | 9 ++++++++- data_sources/aws_cloudtrail.yml | 2 +- .../aws_cloudtrail_assumerolewithsaml.yml | 10 +++++++++- data_sources/aws_cloudtrail_consolelogin.yml | 9 ++++++++- data_sources/aws_cloudtrail_copyobject.yml | 8 +++++++- data_sources/aws_cloudtrail_createaccesskey.yml | 8 +++++++- data_sources/aws_cloudtrail_createkey.yml | 8 +++++++- .../aws_cloudtrail_createloginprofile.yml | 8 +++++++- .../aws_cloudtrail_createnetworkaclentry.yml | 8 +++++++- .../aws_cloudtrail_createpolicyversion.yml | 8 +++++++- data_sources/aws_cloudtrail_createsnapshot.yml | 8 +++++++- data_sources/aws_cloudtrail_createtask.yml | 8 +++++++- .../aws_cloudtrail_createvirtualmfadevice.yml | 8 +++++++- .../aws_cloudtrail_deactivatemfadevice.yml | 8 +++++++- ...aws_cloudtrail_deleteaccountpasswordpolicy.yml | 6 +++++- data_sources/aws_cloudtrail_deletealarms.yml | 8 +++++++- data_sources/aws_cloudtrail_deletedetector.yml | 8 +++++++- data_sources/aws_cloudtrail_deletegroup.yml | 8 +++++++- data_sources/aws_cloudtrail_deleteipset.yml | 7 ++++++- data_sources/aws_cloudtrail_deleteloggroup.yml | 8 +++++++- data_sources/aws_cloudtrail_deletelogstream.yml | 8 +++++++- .../aws_cloudtrail_deletenetworkaclentry.yml | 7 ++++++- data_sources/aws_cloudtrail_deletepolicy.yml | 6 +++++- data_sources/aws_cloudtrail_deleterule.yml | 8 +++++++- data_sources/aws_cloudtrail_deletesnapshot.yml | 8 +++++++- data_sources/aws_cloudtrail_deletetrail.yml | 8 +++++++- .../aws_cloudtrail_deletevirtualmfadevice.yml | 6 +++++- data_sources/aws_cloudtrail_deletewebacl.yml | 6 +++++- .../aws_cloudtrail_describeeventaggregates.yml | 6 +++++- .../aws_cloudtrail_describeimagescanfindings.yml | 7 ++++++- .../aws_cloudtrail_getaccountpasswordpolicy.yml | 6 +++++- data_sources/aws_cloudtrail_getobject.yml | 7 ++++++- data_sources/aws_cloudtrail_getpassworddata.yml | 6 +++++- data_sources/aws_cloudtrail_jobcreated.yml | 6 +++++- data_sources/aws_cloudtrail_modifydbinstance.yml | 7 ++++++- .../aws_cloudtrail_modifyimageattribute.yml | 6 +++++- .../aws_cloudtrail_modifysnapshotattribute.yml | 5 ++++- data_sources/aws_cloudtrail_putbucketacl.yml | 6 +++++- .../aws_cloudtrail_putbucketlifecycle.yml | 6 +++++- .../aws_cloudtrail_putbucketreplication.yml | 5 ++++- .../aws_cloudtrail_putbucketversioning.yml | 5 ++++- data_sources/aws_cloudtrail_putimage.yml | 6 +++++- data_sources/aws_cloudtrail_putkeypolicy.yml | 4 +++- .../aws_cloudtrail_replacenetworkaclentry.yml | 6 +++++- .../aws_cloudtrail_setdefaultpolicyversion.yml | 6 +++++- data_sources/aws_cloudtrail_stoplogging.yml | 5 ++++- ...aws_cloudtrail_updateaccountpasswordpolicy.yml | 6 +++++- .../aws_cloudtrail_updateloginprofile.yml | 6 +++++- .../aws_cloudtrail_updatesamlprovider.yml | 7 ++++++- data_sources/aws_cloudtrail_updatetrail.yml | 6 +++++- data_sources/aws_cloudwatchlogs_vpcflow.yml | 6 ++++-- data_sources/aws_security_hub.yml | 7 ++++++- data_sources/azure_active_directory.yml | 2 +- ...d_app_role_assignment_to_service_principal.yml | 9 +++++++-- .../azure_active_directory_add_member_to_role.yml | 8 +++++++- ..._active_directory_add_owner_to_application.yml | 8 +++++++- ...ure_active_directory_add_service_principal.yml | 8 +++++++- ...ure_active_directory_add_unverified_domain.yml | 8 +++++++- ...re_active_directory_consent_to_application.yml | 8 +++++++- ...ve_directory_disable_strong_authentication.yml | 7 ++++++- .../azure_active_directory_enable_account.yml | 7 ++++++- ...zure_active_directory_invite_external_user.yml | 7 ++++++- ...active_directory_reset_password_(by_admin).yml | 7 ++++++- ...active_directory_set_domain_authentication.yml | 7 ++++++- .../azure_active_directory_sign_in_activity.yml | 7 ++++++- .../azure_active_directory_update_application.yml | 7 ++++++- ...tive_directory_update_authorization_policy.yml | 7 ++++++- .../azure_active_directory_update_user.yml | 6 +++++- ...ve_directory_user_registered_security_info.yml | 7 +++++-- ...eate_or_update_an_azure_automation_account.yml | 8 ++++++-- ...eate_or_update_an_azure_automation_runbook.yml | 7 +++++-- ...eate_or_update_an_azure_automation_webhook.yml | 8 ++++++-- data_sources/bro.yml | 9 --------- data_sources/bro_conn.yml | 15 +++++++++++++++ data_sources/bro_dns.yml | 15 +++++++++++++++ data_sources/bro_files.yml | 15 +++++++++++++++ data_sources/bro_http.yml | 15 +++++++++++++++ data_sources/bro_loaded_scripts.yml | 14 ++++++++++++++ data_sources/bro_ntp.yml | 14 ++++++++++++++ data_sources/bro_ocsp.yml | 15 +++++++++++++++ data_sources/bro_ssl.yml | 15 +++++++++++++++ data_sources/bro_weird.yml | 15 +++++++++++++++ data_sources/bro_x509.yml | 15 +++++++++++++++ data_sources/circleci.yml | 8 +++++++- data_sources/crowdstrike_processrollup2.yml | 9 ++++++++- data_sources/crushftp.yml | 8 +++++++- data_sources/g_suite_drive.yml | 8 +++++++- data_sources/g_suite_gmail.yml | 7 ++++++- data_sources/github.yml | 8 +++++++- data_sources/google_workspace_login_failure.yml | 8 +++++++- data_sources/google_workspace_login_success.yml | 8 +++++++- data_sources/ivanti_vtm_audit.yml | 8 +++++++- data_sources/kubernetes_audit.yml | 9 ++++++++- data_sources/kubernetes_falco.yml | 9 ++++++++- data_sources/linux_auditd_add_user.yml | 9 ++++++++- data_sources/linux_auditd_execve.yml | 10 +++++++++- data_sources/linux_auditd_path.yml | 10 +++++++++- data_sources/linux_auditd_proctitle.yml | 9 ++++++++- data_sources/linux_auditd_service_stop.yml | 9 ++++++++- data_sources/linux_auditd_syscall.yml | 9 ++++++++- data_sources/linux_secure.yml | 8 +++++++- data_sources/ms365_defender_incident_alerts.yml | 8 +++++++- data_sources/ms_defender_atp_alerts.yml | 8 +++++++- data_sources/nginx_access.yml | 8 +++++++- data_sources/o365.yml | 8 +++++++- ...365_add_app_role_assignment_grant_to_user_.yml | 8 +++++++- ..._app_role_assignment_to_service_principal_.yml | 8 +++++++- data_sources/o365_add_mailboxpermission.yml | 8 +++++++- data_sources/o365_add_member_to_role_.yml | 8 +++++++- data_sources/o365_add_owner_to_application_.yml | 8 +++++++- data_sources/o365_add_service_principal_.yml | 8 +++++++- data_sources/o365_change_user_license_.yml | 8 +++++++- data_sources/o365_consent_to_application_.yml | 8 +++++++- .../o365_disable_strong_authentication_.yml | 8 +++++++- data_sources/o365_mailitemsaccessed.yml | 8 +++++++- data_sources/o365_modifyfolderpermissions.yml | 8 +++++++- data_sources/o365_set_company_information_.yml | 8 +++++++- data_sources/o365_set_mailbox.yml | 8 +++++++- data_sources/o365_update_application_.yml | 8 +++++++- .../o365_update_authorization_policy_.yml | 8 +++++++- data_sources/o365_update_user_.yml | 8 +++++++- data_sources/o365_userloggedin.yml | 8 +++++++- data_sources/o365_userloginfailed.yml | 8 +++++++- data_sources/okta.yml | 8 +++++++- data_sources/osquery.yml | 8 +++++++- data_sources/palo_alto_network_threat.yml | 8 +++++++- data_sources/palo_alto_network_traffic.yml | 8 +++++++- data_sources/pingid.yml | 8 +++++++- data_sources/powershell_installed_iis_modules.yml | 7 ++++++- .../powershell_script_block_logging_4104.yml | 10 +++++++++- data_sources/powershell_sip_inventory.yml | 7 ++++++- data_sources/splunk.yml | 8 +++++++- data_sources/splunk_stream_http.yml | 8 +++++++- data_sources/splunk_stream_ip.yml | 8 +++++++- data_sources/splunk_stream_tcp.yml | 8 +++++++- data_sources/suricata.yml | 8 +++++++- data_sources/sysmon_eventid_1.yml | 8 +++++++- data_sources/sysmon_eventid_10.yml | 8 +++++++- data_sources/sysmon_eventid_11.yml | 9 ++++++++- data_sources/sysmon_eventid_12.yml | 8 +++++++- data_sources/sysmon_eventid_13.yml | 8 +++++++- data_sources/sysmon_eventid_15.yml | 9 ++++++++- data_sources/sysmon_eventid_17.yml | 5 ++++- data_sources/sysmon_eventid_18.yml | 8 +++++++- data_sources/sysmon_eventid_20.yml | 7 ++++++- data_sources/sysmon_eventid_21.yml | 8 +++++++- data_sources/sysmon_eventid_22.yml | 9 ++++++++- data_sources/sysmon_eventid_23.yml | 9 ++++++++- data_sources/sysmon_eventid_3.yml | 9 ++++++++- data_sources/sysmon_eventid_5.yml | 8 +++++++- data_sources/sysmon_eventid_6.yml | 8 +++++++- data_sources/sysmon_eventid_7.yml | 9 ++++++++- data_sources/sysmon_eventid_8.yml | 8 +++++++- data_sources/sysmon_eventid_9.yml | 9 ++++++++- data_sources/sysmon_for_linux_eventid_1.yml | 9 ++++++++- data_sources/sysmon_for_linux_eventid_11.yml | 8 +++++++- data_sources/windows_active_directory_admon.yml | 8 +++++++- data_sources/windows_defender_alerts.yml | 8 +++++++- .../windows_event_log_application_2282.yml | 7 ++++++- .../windows_event_log_application_3000.yml | 8 +++++++- data_sources/windows_event_log_capi2_70.yml | 9 ++++++++- data_sources/windows_event_log_capi2_81.yml | 9 ++++++++- ...s_event_log_certificateservicesclient_1007.yml | 9 ++++++++- data_sources/windows_event_log_defender_1121.yml | 7 ++++++- data_sources/windows_event_log_defender_1122.yml | 7 ++++++- data_sources/windows_event_log_defender_1129.yml | 7 ++++++- data_sources/windows_event_log_defender_5007.yml | 5 ++++- ...ft_windows_terminalservices_rdpclient_1024.yml | 5 ++++- .../windows_event_log_printservice_316.yml | 6 +++++- .../windows_event_log_printservice_808.yml | 7 ++++++- ...ows_event_log_remoteconnectionmanager_1149.yml | 7 ++++++- data_sources/windows_event_log_security_1100.yml | 6 +++++- data_sources/windows_event_log_security_1102.yml | 7 ++++++- data_sources/windows_event_log_security_4624.yml | 7 ++++++- data_sources/windows_event_log_security_4625.yml | 6 +++++- data_sources/windows_event_log_security_4627.yml | 7 ++++++- data_sources/windows_event_log_security_4648.yml | 6 +++++- data_sources/windows_event_log_security_4662.yml | 6 +++++- data_sources/windows_event_log_security_4663.yml | 6 +++++- data_sources/windows_event_log_security_4672.yml | 6 +++++- data_sources/windows_event_log_security_4688.yml | 6 +++++- data_sources/windows_event_log_security_4698.yml | 6 +++++- data_sources/windows_event_log_security_4699.yml | 6 +++++- data_sources/windows_event_log_security_4703.yml | 6 +++++- data_sources/windows_event_log_security_4719.yml | 6 +++++- data_sources/windows_event_log_security_4720.yml | 5 ++++- data_sources/windows_event_log_security_4724.yml | 5 ++++- data_sources/windows_event_log_security_4725.yml | 5 ++++- data_sources/windows_event_log_security_4726.yml | 5 ++++- data_sources/windows_event_log_security_4732.yml | 5 ++++- data_sources/windows_event_log_security_4738.yml | 5 ++++- data_sources/windows_event_log_security_4739.yml | 6 +++++- data_sources/windows_event_log_security_4741.yml | 8 +++++++- data_sources/windows_event_log_security_4742.yml | 7 ++++++- data_sources/windows_event_log_security_4768.yml | 8 +++++++- data_sources/windows_event_log_security_4769.yml | 8 +++++++- data_sources/windows_event_log_security_4771.yml | 8 +++++++- data_sources/windows_event_log_security_4776.yml | 8 +++++++- data_sources/windows_event_log_security_4781.yml | 8 +++++++- data_sources/windows_event_log_security_4794.yml | 8 +++++++- data_sources/windows_event_log_security_4798.yml | 7 ++++++- data_sources/windows_event_log_security_4876.yml | 8 +++++++- data_sources/windows_event_log_security_4886.yml | 8 +++++++- data_sources/windows_event_log_security_4887.yml | 8 +++++++- data_sources/windows_event_log_security_5136.yml | 8 +++++++- data_sources/windows_event_log_security_5137.yml | 8 +++++++- data_sources/windows_event_log_security_5140.yml | 8 +++++++- data_sources/windows_event_log_security_5141.yml | 8 +++++++- data_sources/windows_event_log_security_5145.yml | 8 +++++++- data_sources/windows_event_log_system_4720.yml | 8 +++++++- data_sources/windows_event_log_system_4726.yml | 8 +++++++- data_sources/windows_event_log_system_4728.yml | 8 +++++++- data_sources/windows_event_log_system_7036.yml | 8 +++++++- data_sources/windows_event_log_system_7040.yml | 8 +++++++- data_sources/windows_event_log_system_7045.yml | 8 +++++++- .../windows_event_log_taskscheduler_200.yml | 8 +++++++- data_sources/windows_iis.yml | 7 ++++++- data_sources/windows_iis_29.yml | 8 +++++++- 219 files changed, 1482 insertions(+), 223 deletions(-) delete mode 100644 data_sources/bro.yml create mode 100644 data_sources/bro_conn.yml create mode 100644 data_sources/bro_dns.yml create mode 100644 data_sources/bro_files.yml create mode 100644 data_sources/bro_http.yml create mode 100644 data_sources/bro_loaded_scripts.yml create mode 100644 data_sources/bro_ntp.yml create mode 100644 data_sources/bro_ocsp.yml create mode 100644 data_sources/bro_ssl.yml create mode 100644 data_sources/bro_weird.yml create mode 100644 data_sources/bro_x509.yml diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml index 743e34d3eb..8311be25cc 100644 --- a/data_sources/asl_aws_cloudtrail.yml +++ b/data_sources/asl_aws_cloudtrail.yml @@ -3,7 +3,20 @@ id: 1dcf9cfb-0e91-44c6-81b3-61b2574ec898 version: 1 date: '2025-01-14' author: Patrick Bareiss, Splunk -description: Data source object for ASL AWS CloudTrail +description: Represents AWS API dataset data collection from Amazon Security Lake. +mitre_components: +- Cloud Service Metadata +- Cloud Service Modification +- Cloud Storage Access +- Instance Creation +- Instance Deletion +- Instance Start +- Instance Stop +- Instance Modification +- Cloud Storage Creation +- Cloud Storage Deletion +- Cloud Service Enumeration +- Cloud Storage Enumeration source: aws_asl sourcetype: aws:asl separator: api.operation diff --git a/data_sources/aws_cloudfront.yml b/data_sources/aws_cloudfront.yml index c4f146026d..bc4196951d 100644 --- a/data_sources/aws_cloudfront.yml +++ b/data_sources/aws_cloudfront.yml @@ -3,7 +3,14 @@ id: 780086dc-2384-45b6-ade7-56cb00105464 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS Cloudfront +description: Logs requests made to AWS CloudFront distributions, including details on client access, response data, and performance metrics. +mitre_components: +- Network Traffic Content +- Network Traffic Flow +- Response Metadata +- Response Content +- Logon Session Metadata +- Cloud Service Metadata source: aws sourcetype: aws:cloudfront:accesslogs supported_TA: diff --git a/data_sources/aws_cloudtrail.yml b/data_sources/aws_cloudtrail.yml index af1afc59c0..1cdd7ac821 100644 --- a/data_sources/aws_cloudtrail.yml +++ b/data_sources/aws_cloudtrail.yml @@ -3,7 +3,7 @@ id: e8ace6db-1dbd-4c72-a1fb-334684619a38 version: 1 date: '2024-07-24' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail +description: All AWS CloudTrail events source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml index ef4041930f..acd5a6247f 100644 --- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml +++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml @@ -3,10 +3,18 @@ id: 1e28f2a6-2db9-405f-b298-18734a293f77 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail AssumeRoleWithSAML +description: Logs attempts to assume roles via SAML authentication in AWS, including + details of identity provider and role mapping. +mitre_components: +- User Account Authentication +- Logon Session Creation +- User Account Metadata +- Cloud Service Metadata +- Instance Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: AssumeRoleWithSAML supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml index 0ddc77ce93..934d502f32 100644 --- a/data_sources/aws_cloudtrail_consolelogin.yml +++ b/data_sources/aws_cloudtrail_consolelogin.yml @@ -3,10 +3,17 @@ id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail ConsoleLogin +description: Logs attempts to sign in to the AWS Management Console, including successful and failed login events. +mitre_components: +- User Account Authentication +- Logon Session Creation +- User Account Metadata +- Logon Session Metadata +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: ConsoleLogin supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml index 44fabed1bb..72a9c6af4b 100644 --- a/data_sources/aws_cloudtrail_copyobject.yml +++ b/data_sources/aws_cloudtrail_copyobject.yml @@ -3,10 +3,16 @@ id: 965083f4-64a8-403f-99cc-252e1a6bd3b6 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail CopyObject +description: Logs operations that copy objects within or between AWS S3 buckets, including details of source and destination. +mitre_components: +- Cloud Storage Access +- Cloud Storage Modification +- Cloud Storage Metadata +- Instance Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_values: CopyObject supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml index 4834e03b5d..6e95f8ab0f 100644 --- a/data_sources/aws_cloudtrail_createaccesskey.yml +++ b/data_sources/aws_cloudtrail_createaccesskey.yml @@ -3,10 +3,16 @@ id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail CreateAccessKey +description: Logs the creation of new AWS access keys, including details of the associated user and permissions. +mitre_components: +- User Account Creation +- User Account Metadata +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: CreateAccessKey supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml index 8c2aa289b1..655ce8762f 100644 --- a/data_sources/aws_cloudtrail_createkey.yml +++ b/data_sources/aws_cloudtrail_createkey.yml @@ -3,10 +3,16 @@ id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail CreateKey +description: Logs the creation of new AWS KMS keys, including details of key properties and associated metadata. +mitre_components: +- Cloud Service Creation +- Cloud Service Metadata +- Instance Creation +- Volume Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: CreateKey supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml index 7f09482a94..7c272ab23f 100644 --- a/data_sources/aws_cloudtrail_createloginprofile.yml +++ b/data_sources/aws_cloudtrail_createloginprofile.yml @@ -3,10 +3,16 @@ id: 0024fdb1-0d62-4449-970a-746952cf80b6 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail CreateLoginProfile +description: Logs the creation of login profiles for IAM users, including associated metadata and authentication settings. +mitre_components: +- User Account Creation +- User Account Metadata +- Logon Session Metadata +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: CreateLoginProfile supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml index b9eb2d9e66..65830e0d0c 100644 --- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml @@ -3,10 +3,16 @@ id: 45934028-10ec-4ab5-a7b1-a6349b833e67 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail CreateNetworkAclEntry +description: Logs the creation of new entries in a network ACL, including rules to allow or deny specific network traffic. +mitre_components: +- Firewall Rule Modification +- Network Connection Creation +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: CreateNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml index 49b4ea9e54..cc6b2d03f0 100644 --- a/data_sources/aws_cloudtrail_createpolicyversion.yml +++ b/data_sources/aws_cloudtrail_createpolicyversion.yml @@ -3,10 +3,16 @@ id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail CreatePolicyVersion +description: Logs the creation of new versions of IAM policies, including changes to permissions and attached roles or resources. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata +- User Account Metadata +- Group Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: CreatePolicyVersion supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml index d8140341e4..db7c828449 100644 --- a/data_sources/aws_cloudtrail_createsnapshot.yml +++ b/data_sources/aws_cloudtrail_createsnapshot.yml @@ -3,10 +3,16 @@ id: 514135a2-f4b2-4d32-8f31-d87824887f9f version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail CreateSnapshot +description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon EBS volume, including details about the snapshot ID and resource type. +mitre_components: +- Snapshot Creation +- Snapshot Metadata +- Volume Metadata +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: CreateSnapshot supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml index 64c885e902..ee7394b6e4 100644 --- a/data_sources/aws_cloudtrail_createtask.yml +++ b/data_sources/aws_cloudtrail_createtask.yml @@ -3,10 +3,16 @@ id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail CreateTask +description: Logs the creation of a new task in AWS services, such as ECS, including details about the task definition and resource allocation. +mitre_components: +- Scheduled Job Creation +- Scheduled Job Metadata +- Cloud Service Metadata +- Instance Creation source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_name: CreateTask supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml index 579ea87956..ba978e3343 100644 --- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml @@ -3,10 +3,16 @@ id: 13e6e952-0dad-4190-865c-fb5911725f7a version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail CreateVirtualMFADevice +description: Logs the creation of a new virtual multi-factor authentication (MFA) device, including details about the associated user and configuration. +mitre_components: +- User Account Creation +- User Account Metadata +- Cloud Service Creation +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: CreateVirtualMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml index bfef68070f..a62bdde87c 100644 --- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml +++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml @@ -3,10 +3,16 @@ id: 7397a10b-1150-4de9-8062-a96454ae53b2 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeactivateMFADevice +description: Logs the deactivation of a multi-factor authentication (MFA) device, including details about the associated user and the device. +mitre_components: +- User Account Modification +- User Account Metadata +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeactivateMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml index 3998089a44..631ac8d253 100644 --- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml @@ -3,10 +3,14 @@ id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeleteAccountPasswordPolicy +description: Logs the deletion of an account-level password policy in AWS, including details about the account and policy being removed. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml index d7b436d019..2fdf221e51 100644 --- a/data_sources/aws_cloudtrail_deletealarms.yml +++ b/data_sources/aws_cloudtrail_deletealarms.yml @@ -3,10 +3,16 @@ id: b0730ac8-0992-4de8-b000-2c7d0fc7a61f version: 1 date: '2024-07-18' author: Bhavin Patel, Splunk -description: Data source object for AWS CloudTrail DeleteAlarms +description: Logs the deletion of CloudWatch alarms, including details about the alarm names and associated monitoring configurations. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata +- Application Log Content +- Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteAlarms supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml index df3b6cea4e..f467d9348d 100644 --- a/data_sources/aws_cloudtrail_deletedetector.yml +++ b/data_sources/aws_cloudtrail_deletedetector.yml @@ -3,10 +3,16 @@ id: 5d8bd475-c8bc-4447-b27f-efa508728b90 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeleteDetector +description: Logs the deletion of an Amazon GuardDuty detector, including details about the detector ID and associated configurations. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata +- Host Status +- Application Log Content source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteDetector supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml index f383f21440..a683fd2697 100644 --- a/data_sources/aws_cloudtrail_deletegroup.yml +++ b/data_sources/aws_cloudtrail_deletegroup.yml @@ -3,10 +3,16 @@ id: c95308a4-a943-42ca-b112-f90a05c21bd3 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeleteGroup +description: Logs the deletion of an IAM group in AWS, including details about the group name and its associated policies or members. +mitre_components: +- Group Modification +- Group Metadata +- User Account Metadata +- Cloud Service Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteGroup supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml index 9e70698a5f..4c8770dcb2 100644 --- a/data_sources/aws_cloudtrail_deleteipset.yml +++ b/data_sources/aws_cloudtrail_deleteipset.yml @@ -3,10 +3,15 @@ id: ebdeeb63-77a0-4808-a6fe-549956731377 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeleteIPSet +description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details about the IP set ID and its associated configurations. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata +- Firewall Rule Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteIPSet supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml index 936f52788a..04895c5bab 100644 --- a/data_sources/aws_cloudtrail_deleteloggroup.yml +++ b/data_sources/aws_cloudtrail_deleteloggroup.yml @@ -3,10 +3,16 @@ id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeleteLogGroup +description: Logs the deletion of a CloudWatch log group, including details about the log group name and associated resources. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata +- Application Log Content +- Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteLogGroup supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml index 591ea64693..998218f3d2 100644 --- a/data_sources/aws_cloudtrail_deletelogstream.yml +++ b/data_sources/aws_cloudtrail_deletelogstream.yml @@ -3,10 +3,16 @@ id: 6f8bb808-89f8-465e-a34d-229df2f46402 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeleteLogStream +description: Logs the deletion of a log stream within a CloudWatch log group, including details about the stream name and associated log group. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata +- Application Log Content +- Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteLogStream supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml index 7c0003f08b..ce7ac268b0 100644 --- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml @@ -3,10 +3,15 @@ id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeleteNetworkAclEntry +description: Logs the deletion of a network ACL entry in AWS, including details about the rule number and associated network ACL. +mitre_components: +- Firewall Rule Modification +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml index 44cd10188c..fd3dbe18c2 100644 --- a/data_sources/aws_cloudtrail_deletepolicy.yml +++ b/data_sources/aws_cloudtrail_deletepolicy.yml @@ -3,10 +3,14 @@ id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeletePolicy +description: Logs the deletion of an IAM policy in AWS, including details about the policy name and its associated roles or users. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeletePolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml index 545fbcec9a..b5bf81865b 100644 --- a/data_sources/aws_cloudtrail_deleterule.yml +++ b/data_sources/aws_cloudtrail_deleterule.yml @@ -3,10 +3,16 @@ id: b5760623-f3ca-492d-a372-d5c2b3567dfc version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeleteRule +description: Logs the deletion of an event rule in AWS EventBridge, including details about the rule name and its associated targets or schedules. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata +- Scheduled Job Modification +- Application Log Content source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteRule supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml index 6b586a2a3e..dc157cb6bd 100644 --- a/data_sources/aws_cloudtrail_deletesnapshot.yml +++ b/data_sources/aws_cloudtrail_deletesnapshot.yml @@ -3,10 +3,16 @@ id: b0731ac8-0992-4de8-b000-2c7d0fc2a61f version: 1 date: '2024-07-18' author: Bhavin Patel, Splunk -description: Data source object for AWS CloudTrail DeleteSnapshot +description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS snapshot, including details about the snapshot ID and associated resource. +mitre_components: +- Snapshot Deletion +- Snapshot Metadata +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteSnapshot supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml index 1555fafdac..50d8ba5c17 100644 --- a/data_sources/aws_cloudtrail_deletetrail.yml +++ b/data_sources/aws_cloudtrail_deletetrail.yml @@ -3,10 +3,16 @@ id: a5af09ff-07b6-4df6-92a0-2146bfe402c8 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeleteTrail +description: Logs the deletion of an AWS CloudTrail trail, including details about the trail name and its associated logging configurations. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata +- Application Log Content +- Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteTrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml index e03ef28b7d..64de0ba5eb 100644 --- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml @@ -3,10 +3,14 @@ id: 84a08d6b-3d59-4260-8cab-84278ada262f version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeleteVirtualMFADevice +description: Logs an event when a virtual Multi-Factor Authentication (MFA) device is deleted in AWS CloudTrail. +mitre_components: +- User Account Authentication +- User Account Deletion source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteVirtualMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml index 2368ae2314..8d9c4b1cb9 100644 --- a/data_sources/aws_cloudtrail_deletewebacl.yml +++ b/data_sources/aws_cloudtrail_deletewebacl.yml @@ -3,10 +3,14 @@ id: 90da5f08-7961-4c29-8de8-01364982aadf version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DeleteWebACL +description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS CloudTrail. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DeleteWebACL supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml index ae72fb9931..68042cdaa6 100644 --- a/data_sources/aws_cloudtrail_describeeventaggregates.yml +++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml @@ -3,10 +3,14 @@ id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DescribeEventAggregates +description: Logs an event when aggregate details about AWS events are queried, often for analysis. +mitre_components: +- Cloud Service Enumeration +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DescribeEventAggregates supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml index 79696cbffc..d29dc3e798 100644 --- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml +++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml @@ -3,10 +3,15 @@ id: 688ea789-9ba2-4970-90a2-17e541e273c9 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail DescribeImageScanFindings +description: Logs an event when findings from an image vulnerability scan are described using the DescribeImageScanFindings operation in AWS CloudTrail. +mitre_components: +- Image Metadata +- Image Modification +- Malware Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: DescribeImageScanFindings supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml index 376fecc828..d4abfd2473 100644 --- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml @@ -3,10 +3,14 @@ id: 439bdc53-6e4b-4cd7-b326-86c7317fd396 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail GetAccountPasswordPolicy +description: Logs an event when a request is made to get the account password policy in AWS CloudTrail. +mitre_components: +- User Account Authentication +- User Account Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: GetAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml index 27d29dea5d..3a3c9a6e10 100644 --- a/data_sources/aws_cloudtrail_getobject.yml +++ b/data_sources/aws_cloudtrail_getobject.yml @@ -3,10 +3,15 @@ id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail GetObject +description: Logs an event when a request is made to access an object stored in an AWS S3 bucket. +mitre_components: +- Cloud Storage Access +- Cloud Storage Metadata +- Cloud Storage Enumeration source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: GetObject supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml index fc6857d804..7b86ddd0fe 100644 --- a/data_sources/aws_cloudtrail_getpassworddata.yml +++ b/data_sources/aws_cloudtrail_getpassworddata.yml @@ -3,10 +3,14 @@ id: 6ff2ce99-85b1-4c17-888a-56dbc3570671 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail GetPasswordData +description: Logs an event when a request is made to retrieve the administrator password of an EC2 instance. +mitre_components: +- Instance Metadata +- User Account Authentication source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: GetPasswordData supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml index b33710f139..fb86a52163 100644 --- a/data_sources/aws_cloudtrail_jobcreated.yml +++ b/data_sources/aws_cloudtrail_jobcreated.yml @@ -3,10 +3,14 @@ id: 6473289b-d097-4c86-a837-3cc5ae408155 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail JobCreated +description: Logs an event when a new job is created in AWS CloudTrail. +mitre_components: +- Scheduled Job Creation +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: JobCreated supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml index 813b021c40..df5c25ffe5 100644 --- a/data_sources/aws_cloudtrail_modifydbinstance.yml +++ b/data_sources/aws_cloudtrail_modifydbinstance.yml @@ -3,10 +3,15 @@ id: bfa2912d-1a33-4b05-be46-543874d68241 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail ModifyDBInstance +description: Logs an event when a modification is made to an AWS database instance, such as parameters or configurations. +mitre_components: +- Instance Modification +- Cloud Service Modification +- Instance Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: ModifyDBInstance supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml index e73a70ec35..3d415b44b9 100644 --- a/data_sources/aws_cloudtrail_modifyimageattribute.yml +++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml @@ -3,10 +3,14 @@ id: 667c2115-8082-419e-b541-8150066bda4d version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail ModifyImageAttribute +description: Logs an event when the attributes of an Amazon Machine Image (AMI) are modified. +mitre_components: +- Image Modification +- Image Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: ModifyImageAttribute supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml index 373a15ede9..211ccdf1dc 100644 --- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml @@ -3,10 +3,13 @@ id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail ModifySnapshotAttribute +description: Logs an event when modifications are made to the attributes of a snapshot in AWS CloudTrail. +mitre_components: +- Snapshot Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: ModifySnapshotAttribute supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml index 10765a8703..24be91aea5 100644 --- a/data_sources/aws_cloudtrail_putbucketacl.yml +++ b/data_sources/aws_cloudtrail_putbucketacl.yml @@ -3,10 +3,14 @@ id: 28fffbfd-d98d-4a42-990b-b04ab47422eb version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail PutBucketAcl +description: Logs an event when an ACL is set or modified for an S3 bucket in AWS CloudTrail. +mitre_components: +- Cloud Storage Modification +- Cloud Storage Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: PutBucketAcl supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml index c9d8491a16..a01d2b76d2 100644 --- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml +++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml @@ -3,10 +3,14 @@ id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail PutBucketLifecycle +description: Logs an event when a lifecycle configuration is added to an S3 bucket in AWS CloudTrail. +mitre_components: +- Cloud Storage Modification +- Cloud Storage Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: PutBucketLifecycle supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml index 50c9bb4051..b16eec7546 100644 --- a/data_sources/aws_cloudtrail_putbucketreplication.yml +++ b/data_sources/aws_cloudtrail_putbucketreplication.yml @@ -3,10 +3,13 @@ id: 0e1362eb-e592-419f-8fa5-556d3a122417 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail PutBucketReplication +description: Logs an event when replication configurations are added or modified for an S3 bucket. +mitre_components: +- Cloud Storage Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: PutBucketReplication supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml index 4d928ee0d2..1fcc3c6668 100644 --- a/data_sources/aws_cloudtrail_putbucketversioning.yml +++ b/data_sources/aws_cloudtrail_putbucketversioning.yml @@ -3,10 +3,13 @@ id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail PutBucketVersioning +description: Logs an event when the bucket versioning state is modified in an AWS S3 bucket. +mitre_components: +- Cloud Storage Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: PutBucketVersioning supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml index 707c03fcf6..263b630172 100644 --- a/data_sources/aws_cloudtrail_putimage.yml +++ b/data_sources/aws_cloudtrail_putimage.yml @@ -3,10 +3,14 @@ id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail PutImage +description: Logs an event when a container image is uploaded to a repository in AWS CloudTrail. +mitre_components: +- Image Creation +- Image Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: PutImage supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml index 9b2786fadb..edac5877b5 100644 --- a/data_sources/aws_cloudtrail_putkeypolicy.yml +++ b/data_sources/aws_cloudtrail_putkeypolicy.yml @@ -3,7 +3,7 @@ id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail PutKeyPolicy +description: Logs changes made to AWS Key Management Service (KMS) key policies, including updates and permission assignments. source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName @@ -94,6 +94,8 @@ fields: - vendor_account - vendor_product - vendor_region +mitre_components: +- Cloud Service Modification example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext": diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml index 4ce1405960..af51b981b1 100644 --- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml @@ -3,10 +3,14 @@ id: db0c240e-3754-40e4-86ef-cde018ee9f65 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail ReplaceNetworkAclEntry +description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail. +mitre_components: +- Firewall Rule Modification +- Cloud Service Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: ReplaceNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml index 9797971379..df1e0b4657 100644 --- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml +++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml @@ -3,10 +3,14 @@ id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail SetDefaultPolicyVersion +description: Logs an event when the default version of a resource policy in AWS is set or changed. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: SetDefaultPolicyVersion supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml index f285ce143e..69859da19d 100644 --- a/data_sources/aws_cloudtrail_stoplogging.yml +++ b/data_sources/aws_cloudtrail_stoplogging.yml @@ -3,10 +3,13 @@ id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail StopLogging +description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated or stopped. +mitre_components: +- Cloud Service Disable source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: StopLogging supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml index de90a002fe..3959397892 100644 --- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml @@ -3,10 +3,14 @@ id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail UpdateAccountPasswordPolicy +description: Logs an event when an AWS account's password policy is updated. +mitre_components: +- User Account Modification +- Cloud Service Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: UpdateAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml index 6978637a08..e8d28c061a 100644 --- a/data_sources/aws_cloudtrail_updateloginprofile.yml +++ b/data_sources/aws_cloudtrail_updateloginprofile.yml @@ -3,10 +3,14 @@ id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail UpdateLoginProfile +description: Logs an event when an IAM user's login profile is updated. +mitre_components: +- User Account Modification +- User Account Authentication source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: UpdateLoginProfile supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml index 2f2cd5b188..9477d6a455 100644 --- a/data_sources/aws_cloudtrail_updatesamlprovider.yml +++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml @@ -3,10 +3,15 @@ id: e5eb628d-711e-499c-87d9-8fa5dee419ec version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail UpdateSAMLProvider +description: Logs an event when a SAML provider is updated in AWS. +mitre_components: +- Cloud Service Modification +- User Account Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: UpdateSAMLProvider supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml index f22ec6b7ba..edc2d3ff2a 100644 --- a/data_sources/aws_cloudtrail_updatetrail.yml +++ b/data_sources/aws_cloudtrail_updatetrail.yml @@ -3,10 +3,14 @@ id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS CloudTrail UpdateTrail +description: Logs an event when an AWS CloudTrail trail is updated, typically involving changes to settings or configuration. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName +separator_value: UpdateTrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudwatchlogs_vpcflow.yml b/data_sources/aws_cloudwatchlogs_vpcflow.yml index b20242046f..bec254d4fa 100644 --- a/data_sources/aws_cloudwatchlogs_vpcflow.yml +++ b/data_sources/aws_cloudwatchlogs_vpcflow.yml @@ -3,10 +3,12 @@ id: 38a34fc4-e128-4478-a8f4-7835d51d5135 version: 1 author: Bhavin Patel, Splunk date: '2024-07-18' -description: Data source object for AWS CloudWatchLogs VPCflow +description: Logs an event when network traffic flow information such as source and destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in AWS. +mitre_components: +- Network Traffic Flow +- Network Connection Creation source: aws_cloudwatchlogs_vpcflow sourcetype: aws:cloudwatchlogs:vpcflow -separator: eventName supported_TA: - name: Splunk Add-on for AWS version: 7.9.0 diff --git a/data_sources/aws_security_hub.yml b/data_sources/aws_security_hub.yml index 5d4d52b2e7..5d72ddeb75 100644 --- a/data_sources/aws_security_hub.yml +++ b/data_sources/aws_security_hub.yml @@ -3,7 +3,12 @@ id: b02bfbf3-294f-478e-99a1-e24b8c692d7e version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for AWS Security Hub +description: Logs an event when AWS Security Hub identifies potential security risks or deviations from configured best practices across AWS accounts. +mitre_components: +- Cloud Service Metadata +- Cloud Service Enumeration +- Cloud Service Modification +- Cloud Service Disable source: aws_securityhub_finding sourcetype: aws:securityhub:finding supported_TA: diff --git a/data_sources/azure_active_directory.yml b/data_sources/azure_active_directory.yml index 5acf9c76b5..20f8362da1 100644 --- a/data_sources/azure_active_directory.yml +++ b/data_sources/azure_active_directory.yml @@ -3,7 +3,7 @@ id: 51ca21e5-bda2-4652-bb29-27c7bc18a81c version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory +description: All Azure Active Directory events source: Azure AD sourcetype: azure:monitor:aad separator: operationName diff --git a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml index 9db213655d..2afbd8e4ba 100644 --- a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml +++ b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml @@ -3,11 +3,16 @@ id: 8b2e84cd-6db0-47e9-badc-75c17df1995f version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Add app role assignment - to service principal +description: Logs the addition of an application role assignment to a service principal in Azure Active Directory, including details about the role, service principal, and the user or process performing the action. +mitre_components: +- User Account Modification +- Group Modification +- Cloud Service Modification +- Cloud Service Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Add app role assignment to service principal supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml index c62d91a8c2..c2dfa64ecb 100644 --- a/data_sources/azure_active_directory_add_member_to_role.yml +++ b/data_sources/azure_active_directory_add_member_to_role.yml @@ -3,10 +3,16 @@ id: 1660d196-127f-4678-81b2-472d51711b07 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Add member to role +description: Logs the addition of a member to a directory role in Azure Active Directory, including details about the role, the member added, and the user or process performing the action. +mitre_components: +- Group Modification +- Group Metadata +- User Account Metadata +- Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Add member to role supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml index 6e3b00d39a..f174ee00b6 100644 --- a/data_sources/azure_active_directory_add_owner_to_application.yml +++ b/data_sources/azure_active_directory_add_owner_to_application.yml @@ -3,10 +3,16 @@ id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Add owner to application +description: Logs the addition of an owner to an application in Azure Active Directory, including details about the application, the owner added, and the user or process performing the action. +mitre_components: +- User Account Modification +- Group Modification +- Cloud Service Modification +- Cloud Service Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Add owner to application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml index 798a1dd0c9..d100855262 100644 --- a/data_sources/azure_active_directory_add_service_principal.yml +++ b/data_sources/azure_active_directory_add_service_principal.yml @@ -3,10 +3,16 @@ id: fd89d337-e4c0-4162-ad13-bca36f096fe6 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Add service principal +description: Logs the creation of a new service principal in Azure Active Directory, including details about the service principal, associated application, and the user or process performing the action. +mitre_components: +- Cloud Service Creation +- Cloud Service Metadata +- User Account Metadata +- Active Directory Object Creation source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Add service principal supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml index 2cb8e93738..1b06002e40 100644 --- a/data_sources/azure_active_directory_add_unverified_domain.yml +++ b/data_sources/azure_active_directory_add_unverified_domain.yml @@ -3,10 +3,16 @@ id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Add unverified domain +description: Logs the addition of an unverified domain to Azure Active Directory, including details about the domain name and the user or process performing the action. +mitre_components: +- Domain Registration +- Cloud Service Modification +- Cloud Service Metadata +- Configuration Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Add unverified domain supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml index 9464b69c7a..cc0ee34156 100644 --- a/data_sources/azure_active_directory_consent_to_application.yml +++ b/data_sources/azure_active_directory_consent_to_application.yml @@ -3,10 +3,16 @@ id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Consent to application +description: Logs user or admin consent to an application's permissions in Azure Active Directory, including details about the application, granted permissions, and the consenting user or process. +mitre_components: +- User Account Modification +- Cloud Service Modification +- Cloud Service Metadata +- Configuration Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Consent to application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml index 2b1fd79f79..c32bf6b639 100644 --- a/data_sources/azure_active_directory_disable_strong_authentication.yml +++ b/data_sources/azure_active_directory_disable_strong_authentication.yml @@ -3,10 +3,15 @@ id: 8f31966d-c496-496d-8837-f7fd11f31255 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Disable Strong Authentication +description: Logs an event when strong authentication methods are disabled in Azure Active Directory. +mitre_components: +- User Account Authentication +- User Account Modification +- Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Disable Strong Authentication supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml index 710007e9f8..d335c79ffc 100644 --- a/data_sources/azure_active_directory_enable_account.yml +++ b/data_sources/azure_active_directory_enable_account.yml @@ -3,10 +3,15 @@ id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Enable account +description: Logs an event when an Azure Active Directory account is enabled. +mitre_components: +- User Account Modification +- User Account Authentication +- User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Enable account supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml index ebb0a4dea9..d7cb59bbba 100644 --- a/data_sources/azure_active_directory_invite_external_user.yml +++ b/data_sources/azure_active_directory_invite_external_user.yml @@ -3,10 +3,15 @@ id: d3818bd5-f283-4518-8b67-df19240c3e40 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Invite external user +description: Logs an event when an external user is invited to join an Azure Active Directory tenant. +mitre_components: +- Active Directory Object Creation +- User Account Creation +- User Account Authentication source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Invite external user supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml index 1247baa3b5..9c4db01f1f 100644 --- a/data_sources/azure_active_directory_reset_password_(by_admin).yml +++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml @@ -3,10 +3,15 @@ id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Reset password (by admin) +description: Logs an event when an admin resets a user's password in Azure Active Directory. +mitre_components: +- User Account Authentication +- User Account Modification +- Active Directory Object Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Reset password (by admin) supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml index 07fbd4945f..c20d10043c 100644 --- a/data_sources/azure_active_directory_set_domain_authentication.yml +++ b/data_sources/azure_active_directory_set_domain_authentication.yml @@ -3,10 +3,15 @@ id: e7bcdab9-908c-40ab-ba38-5db54fa87750 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Set domain authentication +description: Logs an event when the authentication method for a domain in Azure Active Directory is set or modified. +mitre_components: +- Active Directory Object Modification +- User Account Authentication +- Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Set domain authentication supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml index 71e28dc986..3fca810c95 100644 --- a/data_sources/azure_active_directory_sign_in_activity.yml +++ b/data_sources/azure_active_directory_sign_in_activity.yml @@ -3,10 +3,15 @@ id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Sign-in activity +description: Logs an event when a user attempts to sign into Azure Active Directory, capturing authentication details and outcomes. +mitre_components: +- User Account Authentication +- Logon Session Creation +- User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Sign-in activity supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml index 821d432ecf..cc9da95340 100644 --- a/data_sources/azure_active_directory_update_application.yml +++ b/data_sources/azure_active_directory_update_application.yml @@ -3,10 +3,15 @@ id: 2c08188a-ba25-496e-87c7-803cf28b6c90 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Update application +description: Logs an event when an application in Azure Active Directory is updated, such as changes to its settings or permissions. +mitre_components: +- Service Modification +- User Account Modification +- Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Update application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml index 6d43b471e6..37b2c7c4be 100644 --- a/data_sources/azure_active_directory_update_authorization_policy.yml +++ b/data_sources/azure_active_directory_update_authorization_policy.yml @@ -3,10 +3,15 @@ id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Update authorization policy +description: Logs an event when an authorization policy is updated in Azure Active Directory. +mitre_components: +- User Account Modification +- Group Modification +- Active Directory Object Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Update authorization policy supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml index 4efa2a3816..a37a792233 100644 --- a/data_sources/azure_active_directory_update_user.yml +++ b/data_sources/azure_active_directory_update_user.yml @@ -3,10 +3,14 @@ id: 5495c90a-047c-4b8e-b2fe-1db6282d3872 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory Update user +description: Logs an event when a user account is updated in Azure Active Directory. +mitre_components: +- User Account Modification +- User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: Update user supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml index f7bef825fe..ae651e960d 100644 --- a/data_sources/azure_active_directory_user_registered_security_info.yml +++ b/data_sources/azure_active_directory_user_registered_security_info.yml @@ -3,11 +3,14 @@ id: b63240de-8a01-4ba8-8987-89d18d4b375d version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Active Directory User registered security - info +description: Logs an event when a user registers or updates their security information in Azure Active Directory. +mitre_components: +- User Account Modification +- User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName +separator_value: User registered security info supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml index 8e30686b23..290688b816 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml @@ -3,11 +3,15 @@ id: 2ab182e7-feda-4249-9418-32710b55a885 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Audit Create or Update an Azure Automation - account +description: Logs an event when an Azure Automation account is created or updated. +mitre_components: +- Cloud Service Creation +- Cloud Service Modification +- Cloud Service Metadata source: mscs:azure:audit sourcetype: mscs:azure:audit separator: operationName.localizedValue +separator_value: Create or Update an Azure Automation account supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml index 024427c038..e7ee46661a 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml @@ -3,11 +3,14 @@ id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Audit Create or Update an Azure Automation - Runbook +description: Logs an event when a new Azure Automation Runbook is created or an existing one is updated. +mitre_components: +- Scheduled Job Modification +- Scheduled Job Creation source: mscs:azure:audit sourcetype: mscs:azure:audit separator: operationName.localizedValue +separator_value: Create or Update an Azure Automation Runbook supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml index 35fccd817e..584e44aaff 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml @@ -3,11 +3,15 @@ id: 575faeb2-09d0-4849-b1f6-eae241f26ff2 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Azure Audit Create or Update an Azure Automation - webhook +description: Logs an event when a webhook is created or updated in Azure Automation. +mitre_components: +- Scheduled Job Modification +- Cloud Service Modification +- Scheduled Job Metadata source: mscs:azure:audit sourcetype: mscs:azure:audit separator: operationName.localizedValue +separator_value: Create or Update an Azure Automation webhook supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 diff --git a/data_sources/bro.yml b/data_sources/bro.yml deleted file mode 100644 index 72d2cd5415..0000000000 --- a/data_sources/bro.yml +++ /dev/null @@ -1,9 +0,0 @@ -name: Bro -id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2 -version: 1 -date: '2024-07-18' -author: Patrick Bareiss, Splunk -description: Data source object for Bro -source: bro:http:json -sourcetype: bro:http:json -supported_TA: [] diff --git a/data_sources/bro_conn.yml b/data_sources/bro_conn.yml new file mode 100644 index 0000000000..d4ed14b382 --- /dev/null +++ b/data_sources/bro_conn.yml @@ -0,0 +1,15 @@ +name: Bro conn +id: c5a7e93b-2172-45a7-a7e9-3b217255a7f5 +version: 1 +date: '2025-20-01' +author: Jacob Delgado, SnapAttack +description: Logs network connection metadata captured by Zeek (formerly Bro), including details such as source and destination IPs, ports, connection state, and protocol. +mitre_components: +- Network Connection Creation +- Network Traffic Flow +- Response Metadata +- Application Log Content +source: bro:conn:json +sourcetype: bro:conn:json +supported_TA: [] + diff --git a/data_sources/bro_dns.yml b/data_sources/bro_dns.yml new file mode 100644 index 0000000000..2b7cf87568 --- /dev/null +++ b/data_sources/bro_dns.yml @@ -0,0 +1,15 @@ +name: Bro dns +id: a4576cbf-06cc-4ed0-976c-bf06ccaed011 +version: 1 +date: '2025-20-01' +author: Jacob Delgado, SnapAttack +description: Logs DNS queries and responses captured by Zeek (formerly Bro), including details such as queried domains, resolved IPs, query types, and response codes. +mitre_components: +- Active DNS +- Passive DNS +- Network Traffic Content +- Network Traffic Flow +- Response Metadata +source: bro:dns:json +sourcetype: bro:dns:json +supported_TA: [] diff --git a/data_sources/bro_files.yml b/data_sources/bro_files.yml new file mode 100644 index 0000000000..b8b0f83dc8 --- /dev/null +++ b/data_sources/bro_files.yml @@ -0,0 +1,15 @@ +name: Bro files +id: f72d34d0-3495-4826-ad34-d03495782633 +version: 1 +date: '2025-20-01' +author: Jacob Delgado, SnapAttack +description: Logs metadata about files transferred over the network captured by Zeek (formerly Bro), including details such as file names, hashes, MIME types, and transfer protocols. +mitre_components: +- File Metadata +- Network Traffic Content +- Network Traffic Flow +- Response Metadata +- Application Log Content +source: bro:files:json +sourcetype: bro:files:json +supported_TA: [] diff --git a/data_sources/bro_http.yml b/data_sources/bro_http.yml new file mode 100644 index 0000000000..f0e879954e --- /dev/null +++ b/data_sources/bro_http.yml @@ -0,0 +1,15 @@ +name: Bro http +id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2 +version: 2 +date: '2024-07-18' +author: Patrick Bareiss, Splunk +description: Logs HTTP traffic analyzed by Zeek (formerly Bro), including details such as request methods, URLs, user agents, response codes, and headers. +mitre_components: +- Network Traffic Content +- Network Traffic Flow +- Response Content +- Response Metadata +- Application Log Content +source: bro:http:json +sourcetype: bro:http:json +supported_TA: [] diff --git a/data_sources/bro_loaded_scripts.yml b/data_sources/bro_loaded_scripts.yml new file mode 100644 index 0000000000..e6f2764604 --- /dev/null +++ b/data_sources/bro_loaded_scripts.yml @@ -0,0 +1,14 @@ +name: Bro loaded_scripts +id: 81e08a21-a735-42b1-a08a-21a73582b1bf +version: 1 +date: '2025-20-01' +author: Jacob Delgado, SnapAttack +description: Logs details about the scripts loaded by Zeek (formerly Bro) during initialization, including script names and paths. +mitre_components: +- Application Log Content +- Configuration Modification +- Script Execution +- OS API Execution +source: bro:loaded_scripts:json +sourcetype: bro:loaded_scripts:json +supported_TA: [] diff --git a/data_sources/bro_ntp.yml b/data_sources/bro_ntp.yml new file mode 100644 index 0000000000..15ea709585 --- /dev/null +++ b/data_sources/bro_ntp.yml @@ -0,0 +1,14 @@ +name: Bro ntp +id: 3f64a544-47a4-4958-a4a5-4447a47958df +version: 1 +date: '2025-20-01' +author: Jacob Delgado, SnapAttack +description: Logs Network Time Protocol (NTP) activity captured by Zeek (formerly Bro), including details such as NTP requests, responses, and server metadata. +mitre_components: +- Network Traffic Flow +- Network Traffic Content +- Response Metadata +- Application Log Content +source: bro:ntp:json +sourcetype: bro:ntp:json +supported_TA: [] diff --git a/data_sources/bro_ocsp.yml b/data_sources/bro_ocsp.yml new file mode 100644 index 0000000000..c0da63d49e --- /dev/null +++ b/data_sources/bro_ocsp.yml @@ -0,0 +1,15 @@ +name: Bro ocsp +id: d20909ab-70be-409a-8909-ab70be609af1 +version: 1 +date: '2025-20-01' +author: Jacob Delgado, SnapAttack +description: Logs Online Certificate Status Protocol (OCSP) activity captured by Zeek (formerly Bro), including details such as certificate validation requests and responses. +mitre_components: +- Certificate Registration +- Network Traffic Flow +- Network Traffic Content +- Response Metadata +- Application Log Content +source: bro:ocsp:json +sourcetype: bro:ocsp:json +supported_TA: [] \ No newline at end of file diff --git a/data_sources/bro_ssl.yml b/data_sources/bro_ssl.yml new file mode 100644 index 0000000000..2616ce8186 --- /dev/null +++ b/data_sources/bro_ssl.yml @@ -0,0 +1,15 @@ +name: Bro ssl +id: 22c637eb-f62e-41f0-8637-ebf62e11f0a8 +version: 1 +date: '2025-20-01' +author: Jacob Delgado, SnapAttack +description: Logs SSL/TLS handshake and session details captured by Zeek (formerly Bro), including certificates, cipher suites, and session information. +mitre_components: +- Certificate Registration +- Network Traffic Flow +- Network Traffic Content +- Response Metadata +- Application Log Content +source: bro:ssl:json +sourcetype: bro:ssl:json +supported_TA: [] \ No newline at end of file diff --git a/data_sources/bro_weird.yml b/data_sources/bro_weird.yml new file mode 100644 index 0000000000..346236e53d --- /dev/null +++ b/data_sources/bro_weird.yml @@ -0,0 +1,15 @@ +name: Bro weird +id: e03762c5-c4b8-44e3-b762-c5c4b8e4e3b6 +version: 1 +date: '2025-20-01' +author: Jacob Delgado, SnapAttack +description: Logs anomalous or unexpected network behaviors identified by Zeek (formerly Bro), including protocol violations and unusual traffic patterns. +mitre_components: +- Network Traffic Flow +- Network Traffic Content +- Response Metadata +- Application Log Content +- Host Status +source: bro:weird:json +sourcetype: bro:weird:json +supported_TA: [] diff --git a/data_sources/bro_x509.yml b/data_sources/bro_x509.yml new file mode 100644 index 0000000000..8c41ee6ac1 --- /dev/null +++ b/data_sources/bro_x509.yml @@ -0,0 +1,15 @@ +name: Bro x509 +id: e8792367-64b0-47e9-b923-6764b0f7e936 +version: 1 +date: '2025-20-01' +author: Jacob Delgado, SnapAttack +description: Logs details about X.509 certificates observed in network traffic captured by Zeek (formerly Bro), including certificate fields, validity periods, and issuers. +mitre_components: +- Certificate Registration +- Network Traffic Content +- Response Metadata +- Application Log Content +- Host Status +source: bro:x509:json +sourcetype: bro:x509:json +supported_TA: [] \ No newline at end of file diff --git a/data_sources/circleci.yml b/data_sources/circleci.yml index 9dfcb06b20..6cf9ff1092 100644 --- a/data_sources/circleci.yml +++ b/data_sources/circleci.yml @@ -3,7 +3,13 @@ id: 34ad06fc-a296-4ab5-8315-2f07714948e3 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for CircleCI +description: Logs activities related to CI/CD pipelines executed in CircleCI, including job execution, workflow progress, and configuration changes. +mitre_components: +- Scheduled Job Execution +- Scheduled Job Metadata +- Application Log Content +- Configuration Modification +- Host Status source: circleci sourcetype: circleci supported_TA: diff --git a/data_sources/crowdstrike_processrollup2.yml b/data_sources/crowdstrike_processrollup2.yml index 83b05821b9..e9074afdd5 100644 --- a/data_sources/crowdstrike_processrollup2.yml +++ b/data_sources/crowdstrike_processrollup2.yml @@ -3,10 +3,17 @@ id: cbb06880-9dd9-4542-ac60-bd6e5d3c3e4e version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for CrowdStrike ProcessRollup2 +description: Logs process-related activities captured by CrowdStrike, including process creation, termination, and metadata such as hashes, parent processes, and command-line arguments. +mitre_components: +- Process Creation +- Process Termination +- Process Metadata +- Command Execution +- OS API Execution source: crowdstrike sourcetype: crowdstrike:events:sensor separator: event_simpleName +separator_value: ProcessRollup2 supported_TA: - name: Splunk Add-on for CrowdStrike FDR url: https://splunkbase.splunk.com/app/5579 diff --git a/data_sources/crushftp.yml b/data_sources/crushftp.yml index 7c3f19a528..04a5b0827c 100644 --- a/data_sources/crushftp.yml +++ b/data_sources/crushftp.yml @@ -3,7 +3,13 @@ id: 8a42ace5-e4c8-4653-80cf-1b8e7e6024ef version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for CrushFTP +description: Logs activities related to file transfers and user interactions in CrushFTP, including file uploads, downloads, user authentication, and session details. +mitre_components: +- File Access +- File Metadata +- User Account Authentication +- Logon Session Metadata +- Network Traffic Content source: crushftp sourcetype: crushftp:sessionlogs supported_TA: [] diff --git a/data_sources/g_suite_drive.yml b/data_sources/g_suite_drive.yml index 0b3b02e79e..a07ee5cd8c 100644 --- a/data_sources/g_suite_drive.yml +++ b/data_sources/g_suite_drive.yml @@ -3,7 +3,13 @@ id: 5f79120f-a235-4468-bd0d-55203758ac22 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for G Suite Drive +description: Logs activities related to Google Drive in G Suite, including file creation, modification, sharing, and access details. +mitre_components: +- File Access +- File Creation +- File Modification +- Cloud Storage Access +- Cloud Storage Metadata source: http:gsuite sourcetype: gsuite:drive:json supported_TA: diff --git a/data_sources/g_suite_gmail.yml b/data_sources/g_suite_gmail.yml index 7f628c7174..0a6ddc9596 100644 --- a/data_sources/g_suite_gmail.yml +++ b/data_sources/g_suite_gmail.yml @@ -3,7 +3,12 @@ id: 706c3978-41de-406b-b6e0-75bd01e12a5d version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for G Suite Gmail +description: Logs Gmail activities in G Suite, including email sending, receiving, and access details, as well as potential security-related events. +mitre_components: +- Application Log Content +- User Account Metadata +- Email Metadata +- Cloud Service Metadata source: http:gsuite sourcetype: gsuite:gmail:bigquery supported_TA: diff --git a/data_sources/github.yml b/data_sources/github.yml index 2c5c88084d..e9125f7f07 100644 --- a/data_sources/github.yml +++ b/data_sources/github.yml @@ -3,7 +3,13 @@ id: 88aa4632-3c3e-43f6-a00a-998d71f558e3 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for GitHub +description: Logs activities on GitHub repositories, including push events, pull requests, issue creation, and user authentication events. +mitre_components: +- User Account Authentication +- Configuration Modification +- Application Log Content +- User Account Metadata +- Scheduled Job Metadata source: github sourcetype: aws:firehose:json supported_TA: diff --git a/data_sources/google_workspace_login_failure.yml b/data_sources/google_workspace_login_failure.yml index 11f79d2ad5..4f49e2a565 100644 --- a/data_sources/google_workspace_login_failure.yml +++ b/data_sources/google_workspace_login_failure.yml @@ -3,10 +3,16 @@ id: cabec7cf-4008-4899-b47e-39c34a9a1255 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Google Workspace login_failure +description: Logs failed login attempts to Google Workspace accounts, including details about the user, IP address, and reason for failure. +mitre_components: +- User Account Authentication +- Logon Session Metadata +- User Account Metadata +- Application Log Content source: gws:reports:admin sourcetype: gws:reports:admin separator: event.name +separator_value: login_failure supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 diff --git a/data_sources/google_workspace_login_success.yml b/data_sources/google_workspace_login_success.yml index 4a2bd0308c..723b1b2724 100644 --- a/data_sources/google_workspace_login_success.yml +++ b/data_sources/google_workspace_login_success.yml @@ -3,10 +3,16 @@ id: bffe8013-9cdf-4fe6-9c1b-6784391a4951 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Google Workspace login_success +description: Logs successful login attempts to Google Workspace accounts, including details about the user, IP address, and session metadata. +mitre_components: +- User Account Authentication +- Logon Session Creation +- User Account Metadata +- Logon Session Metadata source: gws:reports:admin sourcetype: gws:reports:admin separator: event.name +separator_value: login_success supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 diff --git a/data_sources/ivanti_vtm_audit.yml b/data_sources/ivanti_vtm_audit.yml index 0bdb54223a..a10ae34f02 100644 --- a/data_sources/ivanti_vtm_audit.yml +++ b/data_sources/ivanti_vtm_audit.yml @@ -3,7 +3,13 @@ id: b04be6e5-2002-4a49-8722-52285635b8f5 version: 1 date: '2024-08-19' author: Michael Haag, Splunk -description: Data source object for Ivanti Virtual Traffic Manager (vTM) +description: Logs administrative and operational activities in Ivanti Virtual Traffic Manager (VTM), including configuration changes, user actions, and system events. +mitre_components: +- Configuration Modification +- Application Log Content +- User Account Metadata +- Host Status +- Service Modification source: ivanti_vtm sourcetype: ivanti_vtm_audit supported_TA: [] diff --git a/data_sources/kubernetes_audit.yml b/data_sources/kubernetes_audit.yml index 9ca3815448..9035f6c381 100644 --- a/data_sources/kubernetes_audit.yml +++ b/data_sources/kubernetes_audit.yml @@ -3,7 +3,14 @@ id: 6c25181a-0c07-4aaf-90e6-77ab1f0e6699 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Kubernetes Audit +description: Logs activities within a Kubernetes cluster, including API server requests, resource access, configuration changes, and user authentication events. +mitre_components: +- Pod Metadata +- Pod Modification +- Cluster Metadata +- User Account Authentication +- Configuration Modification +- Application Log Content source: kubernetes sourcetype: _json supported_TA: [] diff --git a/data_sources/kubernetes_falco.yml b/data_sources/kubernetes_falco.yml index 568d4be771..6b21e39781 100644 --- a/data_sources/kubernetes_falco.yml +++ b/data_sources/kubernetes_falco.yml @@ -3,7 +3,14 @@ id: 23c0eeed-840a-4711-a41b-6819c1ffbba5 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Kubernetes Falco +description: Logs suspicious or anomalous activities within a Kubernetes environment detected by Falco, including system calls, file access, and network activity. +mitre_components: +- File Access +- Network Traffic Content +- Process Creation +- Process Modification +- Application Log Content +- Host Status source: kubernetes sourcetype: kube:container:falco supported_TA: [] diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml index c1d4736a2e..1b6bb6ba17 100644 --- a/data_sources/linux_auditd_add_user.yml +++ b/data_sources/linux_auditd_add_user.yml @@ -3,9 +3,16 @@ id: 30f79353-e1d2-4585-8735-1e0359559f3f version: 1 date: '2024-08-08' author: Teoderick Contreras, Splunk -description: Data source object for Linux Auditd Add User Type +description: Logs activities related to the addition of a new user account on a Linux system, including details about the username, UID, and the process initiating the action. +mitre_components: +- User Account Creation +- User Account Metadata +- OS API Execution +- Application Log Content source: /var/log/audit/audit.log sourcetype: linux:audit +separator: type +separator_value: ADD_USER configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml index 0752725a0f..f70b98a8f9 100644 --- a/data_sources/linux_auditd_execve.yml +++ b/data_sources/linux_auditd_execve.yml @@ -3,9 +3,17 @@ id: 9ef6364d-cc67-480e-8448-3306829a6a24 version: 1 date: '2024-08-08' author: Teoderick Contreras, Splunk -description: Data source object for Linux Auditd Execve Type +description: Logs the execution of processes on a Linux system, including details about the executed command, arguments, and the initiating process. +mitre_components: +- Command Execution +- Process Creation +- Process Metadata +- OS API Execution +- Application Log Content source: /var/log/audit/audit.log sourcetype: linux:audit +separator: type +separator_value: EXECVE configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml index 03703ad47b..3dd0c9d22a 100644 --- a/data_sources/linux_auditd_path.yml +++ b/data_sources/linux_auditd_path.yml @@ -3,9 +3,17 @@ id: 3d86125c-0496-4a5a-aae3-0d355a4f3d7d version: 1 date: '2024-08-08' author: Teoderick Contreras, Splunk -description: Data source object for Linux Auditd Path Type +description: Logs file system access events on a Linux system, including details about file paths, permissions, and associated processes. +mitre_components: +- File Access +- File Metadata +- Process Metadata +- OS API Execution +- Application Log Content source: /var/log/audit/audit.log sourcetype: linux:audit +separator: type +separator_value: PATH configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml index 4831ba4585..e0038b6a94 100644 --- a/data_sources/linux_auditd_proctitle.yml +++ b/data_sources/linux_auditd_proctitle.yml @@ -3,7 +3,14 @@ id: 5a25984a-2789-400a-858b-d75c923e06b1 version: 1 date: '2024-08-08' author: Teoderick Contreras, Splunk -description: Data source object for Linux Auditd Proctitle Type +description: Logs the full command-line arguments of a process execution on a Linux system, providing visibility into the executed command and its parameters. +mitre_components: +- Command Execution +- Process Metadata +- OS API Execution +- Application Log Content +separator: type +separator_value: PROCTITLE source: /var/log/audit/audit.log sourcetype: linux:audit configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml index 151da0bdca..3c4f41bcbf 100644 --- a/data_sources/linux_auditd_service_stop.yml +++ b/data_sources/linux_auditd_service_stop.yml @@ -3,7 +3,14 @@ id: 0643483c-bc62-455c-8d6e-1630e5f0e00d version: 1 date: '2024-08-08' author: Teoderick Contreras, Splunk -description: Data source object for Linux Auditd Service Stop Type +description: Logs events related to the stoppage of a service on a Linux system, including details about the service name, the process initiating the stop, and associated timestamps. +mitre_components: +- Service Modification +- Service Metadata +- OS API Execution +- Application Log Content +separator: type +separator_value: SERVICE_STOP source: /var/log/audit/audit.log sourcetype: linux:audit configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml index 73a300e2be..46f043e357 100644 --- a/data_sources/linux_auditd_syscall.yml +++ b/data_sources/linux_auditd_syscall.yml @@ -3,9 +3,16 @@ id: 4dff7047-0d43-4096-bb3f-b756c889bbad version: 1 date: '2024-08-08' author: Teoderick Contreras, Splunk -description: Data source object for Linux Auditd Syscall Type +description: Logs system calls made by processes on a Linux system, including details about the syscall number, arguments, return values, and associated process metadata. +mitre_components: +- OS API Execution +- Process Metadata +- Application Log Content +- Host Status source: /var/log/audit/audit.log sourcetype: linux:audit +separator: type +separator_value: syscall configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index cd08575aa2..1f1c1917e3 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -3,7 +3,13 @@ id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Linux Secure +description: Logs authentication and authorization events on a Linux system, including login attempts, SSH connections, and privilege escalation activities. +mitre_components: +- User Account Authentication +- Logon Session Creation +- Logon Session Metadata +- User Account Metadata +- Application Log Content source: /var/log/secure sourcetype: linux_secure supported_TA: [] diff --git a/data_sources/ms365_defender_incident_alerts.yml b/data_sources/ms365_defender_incident_alerts.yml index 3fd9ba4555..d8114c0151 100644 --- a/data_sources/ms365_defender_incident_alerts.yml +++ b/data_sources/ms365_defender_incident_alerts.yml @@ -3,7 +3,13 @@ id: 12345678-90ab-cdef-1234-567890abcdef version: 1 date: '2024-07-18' author: Bhavin Patel, Splunk -description: Data source object for MS365 Defender Incident Alerts +description: Logs security incidents and correlated alerts in Microsoft 365 Defender, including details about affected assets, threat types, and remediation steps. +mitre_components: +- Host Status +- User Account Metadata +- Application Log Content +- Malware Metadata +- Active Directory Object Access source: ms365_defender_incident_alerts sourcetype: ms365:defender:incident:alerts supported_TA: diff --git a/data_sources/ms_defender_atp_alerts.yml b/data_sources/ms_defender_atp_alerts.yml index 92d4452143..09026a67d5 100644 --- a/data_sources/ms_defender_atp_alerts.yml +++ b/data_sources/ms_defender_atp_alerts.yml @@ -3,7 +3,13 @@ id: 38f034ed-1598-46c8-95e8-14edf01fdf5d version: 1 date: '2024-10-30' author: Bryan Pluta, Bhavin Patel, Splunk -description: Data source object for Microsoft Defender ATP Alerts +description: Logs security alerts generated by Microsoft Defender for Endpoint, including information about detected threats, impacted devices, and recommended actions. +mitre_components: +- Host Status +- Malware Metadata +- Process Metadata +- User Account Metadata +- Application Log Content source: ms_defender_atp_alerts sourcetype: ms:defender:atp:alerts supported_TA: diff --git a/data_sources/nginx_access.yml b/data_sources/nginx_access.yml index 87238e5c67..052bfc81e4 100644 --- a/data_sources/nginx_access.yml +++ b/data_sources/nginx_access.yml @@ -3,7 +3,13 @@ id: c716a418-eab3-4df5-9dff-5420174e3068 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Nginx Access +description: Logs HTTP/S access events on an Nginx server, including details such as client IP, request method, URI, response status, and user agent. +mitre_components: +- Network Traffic Content +- Network Traffic Flow +- Response Metadata +- Application Log Content +- User Account Metadata source: /var/log/nginx/access.log sourcetype: nginx:plus:kv supported_TA: [] diff --git a/data_sources/o365.yml b/data_sources/o365.yml index 8102ea7c9f..efbfc3ee05 100644 --- a/data_sources/o365.yml +++ b/data_sources/o365.yml @@ -3,7 +3,13 @@ id: b32de97d-0074-4cca-853c-db22c392b6c0 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365. +description: Logs management activities in Microsoft 365, including administrative actions, user activities, and configuration changes across various services. +mitre_components: +- User Account Metadata +- Cloud Service Modification +- Application Log Content +- Configuration Modification +- Active Directory Object Modification source: o365 sourcetype: o365:management:activity separator: Operation diff --git a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml index 89ececa0d0..4c64614e57 100644 --- a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml +++ b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml @@ -3,10 +3,16 @@ id: ce1d7849-a1d2-47fd-b6eb-d7ef854a860c version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Add app role assignment grant to user. +description: Logs the assignment of an application role grant to a user in Microsoft 365, including details about the role, user, and application involved. +mitre_components: +- User Account Modification +- Group Modification +- Cloud Service Modification +- Cloud Service Metadata source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Add app role assignment grant to user. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml index 365604ba84..1549f8b091 100644 --- a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml +++ b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml @@ -3,10 +3,16 @@ id: 785ba57a-ba7b-474e-97c8-9474e6e00b3a version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Add app role assignment to service principal. +description: Logs the assignment of an application role to a service principal in Microsoft 365, including details about the role, service principal, and application involved. +mitre_components: +- Cloud Service Modification +- Cloud Service Metadata +- User Account Metadata +- Group Modification source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Add app role assignment to service principal. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_add_mailboxpermission.yml b/data_sources/o365_add_mailboxpermission.yml index c4869abc7a..e98765f07b 100644 --- a/data_sources/o365_add_mailboxpermission.yml +++ b/data_sources/o365_add_mailboxpermission.yml @@ -3,10 +3,16 @@ id: 9c0babdb-bb15-449e-abba-0a9cdb3fc061 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Add-MailboxPermission +description: Logs the addition of mailbox permissions in Microsoft 365, including details about the mailbox, granted permissions, and the user or administrator performing the action. +mitre_components: +- User Account Modification +- User Account Metadata +- Active Directory Object Modification +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Add-MailboxPermission supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_add_member_to_role_.yml b/data_sources/o365_add_member_to_role_.yml index c2403e0b25..3fc466dba1 100644 --- a/data_sources/o365_add_member_to_role_.yml +++ b/data_sources/o365_add_member_to_role_.yml @@ -3,10 +3,16 @@ id: 8b949f7c-4b5d-404f-9694-d7403c4ec096 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Add member to role. +description: Logs the addition of a member to a role in Microsoft 365, including details about the role, the added member, and the user or administrator performing the action. +mitre_components: +- Group Modification +- Group Metadata +- User Account Metadata +- Cloud Service Modification source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Add member to role. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_add_owner_to_application_.yml b/data_sources/o365_add_owner_to_application_.yml index fdeccc791b..71caf3f806 100644 --- a/data_sources/o365_add_owner_to_application_.yml +++ b/data_sources/o365_add_owner_to_application_.yml @@ -3,10 +3,16 @@ id: da012cbf-af6e-40ee-a1ba-32a5f8da8f8a version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Add owner to application. +description: Logs the addition of an owner to an application in Microsoft 365, including details about the application, the new owner, and the user or administrator performing the action. +mitre_components: +- User Account Modification +- Group Modification +- Cloud Service Modification +- Cloud Service Metadata source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Add owner to application. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_add_service_principal_.yml b/data_sources/o365_add_service_principal_.yml index ae338dcc71..8511ac4c76 100644 --- a/data_sources/o365_add_service_principal_.yml +++ b/data_sources/o365_add_service_principal_.yml @@ -3,10 +3,16 @@ id: 9c1ef9f5-bc30-4a47-a1bd-cb34484ee778 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Add service principal. +description: Logs the addition of a new service principal in Microsoft 365, including details about the associated application and the action initiator. +mitre_components: +- Cloud Service Creation +- Cloud Service Metadata +- User Account Metadata +- Active Directory Object Creation source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Add service principal. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_change_user_license_.yml b/data_sources/o365_change_user_license_.yml index 17222c9261..2cceff2f8a 100644 --- a/data_sources/o365_change_user_license_.yml +++ b/data_sources/o365_change_user_license_.yml @@ -3,10 +3,16 @@ id: 1029a20d-3d0d-4fb9-b5e2-22ac5380b20a version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Change user license. +description: Logs changes to user licenses in Microsoft 365, including additions, removals, or updates to service plans associated with a user account. +mitre_components: +- User Account Modification +- User Account Metadata +- Cloud Service Modification +- Configuration Modification source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Change user license. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_consent_to_application_.yml b/data_sources/o365_consent_to_application_.yml index 4b96c68d96..a5df3bc9f2 100644 --- a/data_sources/o365_consent_to_application_.yml +++ b/data_sources/o365_consent_to_application_.yml @@ -3,10 +3,16 @@ id: 0a15a464-ef51-4614-9a07-a216eb9817db version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Consent to application. +description: Logs user or administrator consent to an application's permissions in Microsoft 365, including details about the application, granted permissions, and the consenting user or process. +mitre_components: +- User Account Modification +- Cloud Service Modification +- Cloud Service Metadata +- Configuration Modification source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Consent to application. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_disable_strong_authentication_.yml b/data_sources/o365_disable_strong_authentication_.yml index 53f37fa0ab..ea3fb70491 100644 --- a/data_sources/o365_disable_strong_authentication_.yml +++ b/data_sources/o365_disable_strong_authentication_.yml @@ -3,10 +3,16 @@ id: 235381c4-382a-4183-b818-a51c3ce12187 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Disable Strong Authentication. +description: Logs the disabling of strong authentication (e.g., multi-factor authentication) for a user or group in Microsoft 365, including details about the affected accounts and the action initiator. +mitre_components: +- User Account Modification +- Group Modification +- Configuration Modification +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Disable Strong Authentication. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_mailitemsaccessed.yml b/data_sources/o365_mailitemsaccessed.yml index d2bad265dc..bc03fd713a 100644 --- a/data_sources/o365_mailitemsaccessed.yml +++ b/data_sources/o365_mailitemsaccessed.yml @@ -3,10 +3,16 @@ id: 3d5188eb-341a-4b46-9caa-aade4047d027 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 MailItemsAccessed +description: Logs access to mailbox items in Microsoft 365, including details about the user accessing the items, the accessed content, and the method of access. +mitre_components: +- File Access +- User Account Metadata +- Application Log Content +- Active Directory Object Access source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: MailItemsAccessed supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_modifyfolderpermissions.yml b/data_sources/o365_modifyfolderpermissions.yml index bf6d9f1855..76c4e10d20 100644 --- a/data_sources/o365_modifyfolderpermissions.yml +++ b/data_sources/o365_modifyfolderpermissions.yml @@ -3,10 +3,16 @@ id: 0a8c1080-68c2-46d7-8324-2e7d97bb6e2f version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 ModifyFolderPermissions +description: Logs modifications to folder permissions in Microsoft 365, including updates to access levels, user assignments, and sharing settings. +mitre_components: +- User Account Modification +- File Access +- Active Directory Object Modification +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: ModifyFolderPermissions supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_set_company_information_.yml b/data_sources/o365_set_company_information_.yml index d40cca2fcb..5fab124138 100644 --- a/data_sources/o365_set_company_information_.yml +++ b/data_sources/o365_set_company_information_.yml @@ -3,10 +3,16 @@ id: 06c6d576-f032-41e3-b15d-80a434ce13d8 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Set Company Information. +description: Logs updates to organizational settings and company information in Microsoft 365, including changes to contact details, branding, and configuration policies. +mitre_components: +- Cloud Service Modification +- Configuration Modification +- Cloud Service Metadata +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Set Company Information. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_set_mailbox.yml b/data_sources/o365_set_mailbox.yml index 30ebad4b33..6849ce100a 100644 --- a/data_sources/o365_set_mailbox.yml +++ b/data_sources/o365_set_mailbox.yml @@ -3,10 +3,16 @@ id: db798c5c-928c-4972-bb42-e5f90e35865f version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Set-Mailbox +description: Logs changes to mailbox properties in Microsoft 365, including updates to permissions, storage quotas, and configuration settings. +mitre_components: +- User Account Modification +- Active Directory Object Modification +- User Account Metadata +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Set-Mailbox supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_update_application_.yml b/data_sources/o365_update_application_.yml index f78faf1948..155f1353ca 100644 --- a/data_sources/o365_update_application_.yml +++ b/data_sources/o365_update_application_.yml @@ -3,10 +3,16 @@ id: 62159133-911b-4c63-9e30-a6a8c89195ca version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Update application. +description: Logs updates made to applications in Microsoft 365, including changes to configurations, permissions, and role assignments. +mitre_components: +- Cloud Service Modification +- Configuration Modification +- Cloud Service Metadata +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Update application. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_update_authorization_policy_.yml b/data_sources/o365_update_authorization_policy_.yml index b53bce2417..2438a25b16 100644 --- a/data_sources/o365_update_authorization_policy_.yml +++ b/data_sources/o365_update_authorization_policy_.yml @@ -3,10 +3,16 @@ id: d40e6a20-4d64-404c-8351-2caae8228d34 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Update authorization policy. +description: Logs changes to authorization policies in Microsoft 365, including updates to access controls, permissions, and security settings. +mitre_components: +- Cloud Service Modification +- Configuration Modification +- User Account Metadata +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Update authorization policy. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_update_user_.yml b/data_sources/o365_update_user_.yml index 5497544e68..308a4ac7a4 100644 --- a/data_sources/o365_update_user_.yml +++ b/data_sources/o365_update_user_.yml @@ -3,10 +3,16 @@ id: a05fd01e-34d9-4233-9089-11272416b531 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 Update user. +description: Logs updates to user account properties in Microsoft 365, including changes to roles, permissions, and profile information. +mitre_components: +- User Account Modification +- User Account Metadata +- Active Directory Object Modification +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: Update user. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_userloggedin.yml b/data_sources/o365_userloggedin.yml index 540450b496..3296cb188a 100644 --- a/data_sources/o365_userloggedin.yml +++ b/data_sources/o365_userloggedin.yml @@ -3,10 +3,16 @@ id: ed29c8c4-4053-419c-b133-16abf2a1c4c9 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 UserLoggedIn +description: Logs successful login events by users in Microsoft 365, including details about the user account, IP address, and session metadata. +mitre_components: +- User Account Authentication +- Logon Session Creation +- User Account Metadata +- Logon Session Metadata source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: UserLoggedIn supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/o365_userloginfailed.yml b/data_sources/o365_userloginfailed.yml index b03d5032ae..dfea247775 100644 --- a/data_sources/o365_userloginfailed.yml +++ b/data_sources/o365_userloginfailed.yml @@ -3,10 +3,16 @@ id: 6099b33d-d581-43ed-8401-911862590361 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for O365 UserLoginFailed +description: Logs failed login attempts by users in Microsoft 365, including details about the user account, IP address, and reason for failure. +mitre_components: +- User Account Authentication +- Logon Session Metadata +- User Account Metadata +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation +separator_value: UserLoginFailed supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 diff --git a/data_sources/okta.yml b/data_sources/okta.yml index 816d155e23..27417c8961 100644 --- a/data_sources/okta.yml +++ b/data_sources/okta.yml @@ -3,7 +3,13 @@ id: ec26febe-e760-4981-bbee-72e107c7b9d2 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Okta +description: Logs authentication and administrative activities captured by Okta, including user login attempts, session management, and configuration changes. +mitre_components: +- User Account Authentication +- Logon Session Creation +- User Account Metadata +- Configuration Modification +- Application Log Content source: Okta sourcetype: OktaIM2:log supported_TA: diff --git a/data_sources/osquery.yml b/data_sources/osquery.yml index 7244b5e8ce..bd8cb58790 100644 --- a/data_sources/osquery.yml +++ b/data_sources/osquery.yml @@ -3,7 +3,13 @@ id: 7ec4d7c8-c1d0-423a-9169-261f6adb74c0 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for osquery +description: Logs system queries performed using osquery, including details about processes, file access, network activity, and system configurations. +mitre_components: +- Process Metadata +- File Access +- Network Traffic Content +- Host Status +- Application Log Content source: osquery sourcetype: osquery:results supported_TA: [] diff --git a/data_sources/palo_alto_network_threat.yml b/data_sources/palo_alto_network_threat.yml index 37d07f372d..d9c2937be9 100644 --- a/data_sources/palo_alto_network_threat.yml +++ b/data_sources/palo_alto_network_threat.yml @@ -3,7 +3,13 @@ id: 375c2b0e-d216-41ad-9406-200464595209 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Palo Alto Network Threat +description: Logs detected threats identified by Palo Alto Networks devices, including details about malware, intrusion attempts, and malicious network activity. +mitre_components: +- Malware Metadata +- Network Traffic Content +- Network Traffic Flow +- Application Log Content +- Host Status source: pan:threat sourcetype: pan:threat supported_TA: diff --git a/data_sources/palo_alto_network_traffic.yml b/data_sources/palo_alto_network_traffic.yml index 7f42b934b2..02afe2d863 100644 --- a/data_sources/palo_alto_network_traffic.yml +++ b/data_sources/palo_alto_network_traffic.yml @@ -3,7 +3,13 @@ id: 182a83bc-c31a-4817-8c7a-263744cec52a version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Palo Alto Network Traffic +description: Logs network traffic events captured by Palo Alto Networks devices, including details about sessions, protocols, and source and destination IPs. +mitre_components: +- Network Traffic Content +- Network Traffic Flow +- Network Connection Creation +- Response Metadata +- Application Log Content source: screenconnect_palo_traffic sourcetype: pan:traffic supported_TA: diff --git a/data_sources/pingid.yml b/data_sources/pingid.yml index 1342a8c5d5..2b77686143 100644 --- a/data_sources/pingid.yml +++ b/data_sources/pingid.yml @@ -3,7 +3,13 @@ id: 17890675-61c1-40bd-a88e-6a8e9e246b43 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for PingID +description: Logs authentication and multi-factor authentication (MFA) events managed by PingID, including user logins, device enrollments, and MFA challenges. +mitre_components: +- User Account Authentication +- Logon Session Metadata +- User Account Metadata +- Application Log Content +- Host Status source: XmlWinEventLog:Security sourcetype: XmlWinEventLog supported_TA: [] diff --git a/data_sources/powershell_installed_iis_modules.yml b/data_sources/powershell_installed_iis_modules.yml index a27822830a..cf0b592d7b 100644 --- a/data_sources/powershell_installed_iis_modules.yml +++ b/data_sources/powershell_installed_iis_modules.yml @@ -3,7 +3,12 @@ id: 4f2ccf42-3503-4417-a684-bfccf7f0d7b4 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Powershell Installed IIS Modules +description: Logs the list of installed IIS modules retrieved using PowerShell, including details about their names and statuses. +mitre_components: +- Service Metadata +- Configuration Modification +- OS API Execution +- Application Log Content source: powershell://AppCmdModules sourcetype: Pwsh:InstalledIISModules supported_TA: [] diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index 8333b3c4b2..b5aba9d7f7 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -3,9 +3,17 @@ id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Powershell Script Block Logging 4104 +description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution. +mitre_components: +- Script Execution +- Command Execution +- Process Metadata +- OS API Execution +- Application Log Content source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational sourcetype: xmlwineventlog +separator: EventID +separator_value: 4104 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/powershell_sip_inventory.yml b/data_sources/powershell_sip_inventory.yml index dc02c04217..3d87d08359 100644 --- a/data_sources/powershell_sip_inventory.yml +++ b/data_sources/powershell_sip_inventory.yml @@ -3,7 +3,12 @@ id: 5ef5cb5d-1fa8-4567-b48f-27317662cd73 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Powershell SIP Inventory +description: Logs the inventory of System Integrity Policies (SIP) on a system retrieved via PowerShell, including details about policy configurations and statuses. +mitre_components: +- Configuration Modification +- Host Status +- Application Log Content +- OS API Execution source: powershell://SubjectInterfacePackage sourcetype: PwSh:SubjectInterfacePackage supported_TA: [] diff --git a/data_sources/splunk.yml b/data_sources/splunk.yml index 59728f1060..fdd3c93db4 100644 --- a/data_sources/splunk.yml +++ b/data_sources/splunk.yml @@ -3,7 +3,13 @@ id: d8a2c791-460b-4756-a8e5-ecade77b21e3 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Splunk +description: Logs user interface access events for Splunk, including details about user actions, accessed resources, and authentication information. +mitre_components: +- User Account Authentication +- User Account Metadata +- Application Log Content +- Configuration Modification +- Logon Session Metadata source: splunkd_ui_access.log sourcetype: splunkd_ui_access supported_TA: [] diff --git a/data_sources/splunk_stream_http.yml b/data_sources/splunk_stream_http.yml index 29db818262..7db141fc5f 100644 --- a/data_sources/splunk_stream_http.yml +++ b/data_sources/splunk_stream_http.yml @@ -3,7 +3,13 @@ id: b0070a33-92ed-49e5-8f38-576cdf300710 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Splunk Stream HTTP +description: Logs HTTP traffic captured by Splunk Stream, including details such as request methods, URLs, headers, response codes, and client-server interactions. +mitre_components: +- Network Traffic Content +- Network Traffic Flow +- Response Content +- Response Metadata +- Application Log Content source: stream:http sourcetype: stream:http supported_TA: diff --git a/data_sources/splunk_stream_ip.yml b/data_sources/splunk_stream_ip.yml index d722002f17..9460dfccac 100644 --- a/data_sources/splunk_stream_ip.yml +++ b/data_sources/splunk_stream_ip.yml @@ -3,7 +3,13 @@ id: c96f5906-f601-4f32-a26c-482535159bc2 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Splunk Stream IP +description: Logs IP traffic captured by Splunk Stream, including details about source and destination IPs, protocols, and packet metadata. +mitre_components: +- Network Traffic Content +- Network Traffic Flow +- Network Connection Creation +- Response Metadata +- Application Log Content source: stream:ip sourcetype: stream:ip supported_TA: diff --git a/data_sources/splunk_stream_tcp.yml b/data_sources/splunk_stream_tcp.yml index 685c0f6931..e1488a0873 100644 --- a/data_sources/splunk_stream_tcp.yml +++ b/data_sources/splunk_stream_tcp.yml @@ -3,7 +3,13 @@ id: 4b1233d1-f80a-4da1-ab27-a5b10ea8a4ce version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Splunk Stream TCP +description: Logs TCP traffic captured by Splunk Stream, including details about source and destination IPs, ports, connection states, and packet-level metadata. +mitre_components: +- Network Traffic Content +- Network Traffic Flow +- Network Connection Creation +- Response Metadata +- Application Log Content source: stream:tcp sourcetype: stream:tcp supported_TA: diff --git a/data_sources/suricata.yml b/data_sources/suricata.yml index 6ad1b8e80c..389920b743 100644 --- a/data_sources/suricata.yml +++ b/data_sources/suricata.yml @@ -3,7 +3,13 @@ id: 64b245d4-a4d1-4865-a718-c83d3b939f2e version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Suricata +description: Logs network traffic and security events detected by Suricata, including details about connections, protocol metadata, and potential threats. +mitre_components: +- Network Traffic Content +- Network Traffic Flow +- Network Connection Creation +- Malware Metadata +- Application Log Content source: suricata sourcetype: suricata supported_TA: [] diff --git a/data_sources/sysmon_eventid_1.yml b/data_sources/sysmon_eventid_1.yml index 80284e88ac..9af0398f6a 100644 --- a/data_sources/sysmon_eventid_1.yml +++ b/data_sources/sysmon_eventid_1.yml @@ -3,10 +3,16 @@ id: b375f4d1-d7ca-4bc0-9103-294825c0af17 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 1 +description: Logs the creation of a new process, including details such as process ID, parent process, command line arguments, and hashes of the executable. +mitre_components: +- Process Creation +- Process Metadata +- Command Execution +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 1 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_10.yml b/data_sources/sysmon_eventid_10.yml index be7121e719..80713f8dc3 100644 --- a/data_sources/sysmon_eventid_10.yml +++ b/data_sources/sysmon_eventid_10.yml @@ -3,10 +3,16 @@ id: 659cd5a8-148a-4c59-ade1-05f41ac1b096 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 10 +description: Logs events where one process accesses another process, typically for memory reads or injections, including details about the source and target processes. +mitre_components: +- Process Access +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 10 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_11.yml b/data_sources/sysmon_eventid_11.yml index e206bee06f..ecf23fc755 100644 --- a/data_sources/sysmon_eventid_11.yml +++ b/data_sources/sysmon_eventid_11.yml @@ -3,10 +3,17 @@ id: f3db9179-f4f5-416d-bc03-39f4d4ff699e version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 11 +description: Logs the creation of a new file, including details about the file path, hash information, and associated process metadata. +mitre_components: +- File Creation +- File Metadata +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 11 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_12.yml b/data_sources/sysmon_eventid_12.yml index 232ca47a23..665a69a98e 100644 --- a/data_sources/sysmon_eventid_12.yml +++ b/data_sources/sysmon_eventid_12.yml @@ -3,10 +3,16 @@ id: 3ef28798-8eaa-4fd2-b074-6f36d08a1b33 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 12 +description: Logs the creation of a new registry key, including details about the key name, registry path, and associated process metadata. +mitre_components: +- Windows Registry Key Creation +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 12 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_13.yml b/data_sources/sysmon_eventid_13.yml index ff0aa0690b..d7ed659f74 100644 --- a/data_sources/sysmon_eventid_13.yml +++ b/data_sources/sysmon_eventid_13.yml @@ -3,10 +3,16 @@ id: 19cd00ee-f65f-48ca-bb08-64aac28638ce version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 13 +description: Logs changes to a registry key, including details about the modified key, value, and associated process. +mitre_components: +- Windows Registry Key Modification +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 13 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_15.yml b/data_sources/sysmon_eventid_15.yml index 335042f192..8ffed5fe5c 100644 --- a/data_sources/sysmon_eventid_15.yml +++ b/data_sources/sysmon_eventid_15.yml @@ -3,10 +3,17 @@ id: 95785e02-93b4-47e2-81f1-be326295348e version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 15 +description: Logs the creation of a new file stream, including details about the file stream's hash, path, and associated process metadata. +mitre_components: +- File Creation +- File Metadata +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 15 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_17.yml b/data_sources/sysmon_eventid_17.yml index b1125bf4d3..221feadee2 100644 --- a/data_sources/sysmon_eventid_17.yml +++ b/data_sources/sysmon_eventid_17.yml @@ -3,10 +3,13 @@ id: 08924246-c8e8-4c95-a9fc-633c43cc82df version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 17 +description: Sysmon EventID 17 logs details about the detection of a named pipe. +mitre_components: +- Named Pipe Metadata source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 17 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_18.yml b/data_sources/sysmon_eventid_18.yml index a1204b64f7..d776df79ee 100644 --- a/data_sources/sysmon_eventid_18.yml +++ b/data_sources/sysmon_eventid_18.yml @@ -3,10 +3,16 @@ id: 37eb3554-214e-4e66-af10-c3ffc5b8ca82 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 18 +description: Logs the connection to a named pipe, including details about the pipe name, source and destination processes, and communication direction. +mitre_components: +- Named Pipe Metadata +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 18 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_20.yml b/data_sources/sysmon_eventid_20.yml index dfcc795a12..07720a1a9e 100644 --- a/data_sources/sysmon_eventid_20.yml +++ b/data_sources/sysmon_eventid_20.yml @@ -3,7 +3,12 @@ id: aeee5374-3203-4286-b744-a8cc4ad1cd7e version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 20 +description: Logs WMI (Windows Management Instrumentation) consumer activity, including details about the WMI event consumer, associated process, and event data. +mitre_components: +- WMI Creation +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID diff --git a/data_sources/sysmon_eventid_21.yml b/data_sources/sysmon_eventid_21.yml index 89de93b9dc..4fb0386039 100644 --- a/data_sources/sysmon_eventid_21.yml +++ b/data_sources/sysmon_eventid_21.yml @@ -3,10 +3,16 @@ id: 304384bc-715e-4958-988b-a8051a91349a version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 21 +description: Logs activity related to the association of a WMI event consumer with a filter, including details about the consumer, filter, and associated process. +mitre_components: +- WMI Creation +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 21 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_22.yml b/data_sources/sysmon_eventid_22.yml index eee550143e..5ed15373d4 100644 --- a/data_sources/sysmon_eventid_22.yml +++ b/data_sources/sysmon_eventid_22.yml @@ -3,10 +3,17 @@ id: 911538b2-eba7-4d3e-85e8-d82d380c37bf version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 22 +description: Logs DNS query events, including details about the queried domain, source IP, query type, and response data. +mitre_components: +- Passive DNS +- Active DNS +- Network Traffic Content +- Network Traffic Flow +- Application Log Content source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 22 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_23.yml b/data_sources/sysmon_eventid_23.yml index ee91eb49d2..dfcd344c24 100644 --- a/data_sources/sysmon_eventid_23.yml +++ b/data_sources/sysmon_eventid_23.yml @@ -3,10 +3,17 @@ id: 5ea2721d-f60c-4f48-a047-47d514e327c3 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 23 +description: Logs the deletion of a file, including details about the file path, associated process, and the time of deletion. +mitre_components: +- File Deletion +- File Metadata +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 23 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_3.yml b/data_sources/sysmon_eventid_3.yml index 4a92e3fcd3..36d5299c6b 100644 --- a/data_sources/sysmon_eventid_3.yml +++ b/data_sources/sysmon_eventid_3.yml @@ -3,10 +3,17 @@ id: 01d84dff-4e26-422c-9389-6a579ee6e75b version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 3 +description: Logs details of network connections initiated by processes, including source and destination IPs, ports, protocols, and the associated process metadata. +mitre_components: +- Network Connection Creation +- Network Traffic Flow +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 3 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_5.yml b/data_sources/sysmon_eventid_5.yml index 2e8f6f0ab7..06cf9d15a3 100644 --- a/data_sources/sysmon_eventid_5.yml +++ b/data_sources/sysmon_eventid_5.yml @@ -3,10 +3,16 @@ id: 556471bf-44fa-44e6-97e2-eb25416aeb6d version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 5 +description: Logs the termination of a process, including details about the process name, process ID, parent process, and associated metadata. +mitre_components: +- Process Termination +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 5 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_6.yml b/data_sources/sysmon_eventid_6.yml index 33345ac58b..9cf7db46b6 100644 --- a/data_sources/sysmon_eventid_6.yml +++ b/data_sources/sysmon_eventid_6.yml @@ -3,10 +3,16 @@ id: eadc297a-c20c-45a1-8fac-74ad54019767 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 6 +description: Logs the loading of a driver into the kernel or user mode, including details about the driver name, file path, and associated process metadata. +mitre_components: +- Driver Load +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 6 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_7.yml b/data_sources/sysmon_eventid_7.yml index 2efd35e16d..24d4800817 100644 --- a/data_sources/sysmon_eventid_7.yml +++ b/data_sources/sysmon_eventid_7.yml @@ -3,10 +3,17 @@ id: 45512fa5-4d55-4088-9d51-f4dedc16fdff version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 7 +description: Logs the loading of an image (module) into a process, including details about the image name, file path, and hash information. +mitre_components: +- Module Load +- Process Metadata +- File Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 7 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_8.yml b/data_sources/sysmon_eventid_8.yml index 5fc772500d..ff4dd0f046 100644 --- a/data_sources/sysmon_eventid_8.yml +++ b/data_sources/sysmon_eventid_8.yml @@ -3,10 +3,16 @@ id: df7a786c-ade0-48f0-8596-26f10d169f7d version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 8 +description: Logs the creation of a new thread in a process, including details about the thread ID, start address, and source process. +mitre_components: +- Process Modification +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 8 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_9.yml b/data_sources/sysmon_eventid_9.yml index b93f6051cb..8d3731938b 100644 --- a/data_sources/sysmon_eventid_9.yml +++ b/data_sources/sysmon_eventid_9.yml @@ -3,10 +3,17 @@ id: ae4a6a24-9b8c-4386-a7ac-677d7ad5bf09 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon EventID 9 +description: Logs the access of raw disk data by a process, including details about the disk name, process ID, and process metadata. +mitre_components: +- Drive Access +- File Metadata +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID +separator_value: 9 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_for_linux_eventid_1.yml b/data_sources/sysmon_for_linux_eventid_1.yml index 9ee369f5b8..ac395956a2 100644 --- a/data_sources/sysmon_for_linux_eventid_1.yml +++ b/data_sources/sysmon_for_linux_eventid_1.yml @@ -3,10 +3,17 @@ id: 93643652-30fe-4941-a1f7-6454f2948660 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon for Linux EventID 1 +description: Logs process creation events on Linux systems, including details about the process name, process ID, command line arguments, and parent process ID. +mitre_components: +- Process Creation +- Command Execution +- Process Metadata +- OS API Execution +- Application Log Content source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux separator: EventID +separator_value: 1 supported_TA: - name: Splunk Add-on for Sysmon for Linux url: https://splunkbase.splunk.com/app/6652 diff --git a/data_sources/sysmon_for_linux_eventid_11.yml b/data_sources/sysmon_for_linux_eventid_11.yml index 8276870f8a..96020a1d91 100644 --- a/data_sources/sysmon_for_linux_eventid_11.yml +++ b/data_sources/sysmon_for_linux_eventid_11.yml @@ -3,7 +3,13 @@ id: 14672fed-235a-411f-8062-ace9696fb2af version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Sysmon for Linux EventID 11 +description: Logs the creation of a new file on a Linux system, including details about the file path, file type, and associated process. +mitre_components: +- File Creation +- File Metadata +- Process Metadata +- OS API Execution +- Application Log Content source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux separator: EventID diff --git a/data_sources/windows_active_directory_admon.yml b/data_sources/windows_active_directory_admon.yml index cfeb4c831e..7e660bb3e7 100644 --- a/data_sources/windows_active_directory_admon.yml +++ b/data_sources/windows_active_directory_admon.yml @@ -3,7 +3,13 @@ id: 22bbf4e4-d313-43c1-98ee-808b8775519d version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Active Directory Admon +description: Logs administrative actions within Active Directory, including user and group modifications, permission changes, and policy updates. +mitre_components: +- Active Directory Object Modification +- Group Modification +- User Account Modification +- Configuration Modification +- Application Log Content source: ActiveDirectory sourcetype: ActiveDirectory supported_TA: diff --git a/data_sources/windows_defender_alerts.yml b/data_sources/windows_defender_alerts.yml index 83a470bf4b..7a4de96d5d 100644 --- a/data_sources/windows_defender_alerts.yml +++ b/data_sources/windows_defender_alerts.yml @@ -3,7 +3,13 @@ id: 91738e9e-d112-41c9-b91b-e5868d8993d7 version: 1 date: '2024-09-24' author: Gowthamaraj Rajendran -description: Data source object for Windows Defender alerts +description: Logs security alerts generated by Windows Defender, including details about detected threats, impacted files, and recommended actions for remediation. +mitre_components: +- Malware Metadata +- File Access +- Process Metadata +- Application Log Content +- Host Status source: eventhub://windowsdefenderlogs sourcetype: mscs:azure:eventhub:defender:advancedhunting separator: AlertId diff --git a/data_sources/windows_event_log_application_2282.yml b/data_sources/windows_event_log_application_2282.yml index eb6fc6d136..af675f03ca 100644 --- a/data_sources/windows_event_log_application_2282.yml +++ b/data_sources/windows_event_log_application_2282.yml @@ -3,7 +3,12 @@ id: 4490537e-5e0c-46f7-9209-f56f852aa237 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Application 2282 +description: Logs an event in IIS when a module DLL fails to load due to a configuration issue, including details about the module and error message. +mitre_components: +- Service Modification +- Configuration Modification +- Application Log Content +- Service Metadata source: XmlWinEventLog:Application sourcetype: XmlWinEventLog separator: EventCode diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index 87b847e9bc..9ec681c407 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -3,10 +3,16 @@ id: 3911945d-9222-408d-b851-9b1bce4c2d24 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Application 3000 +description: Logs the termination of a process, including details about the process, its termination code, and timestamp. +mitre_components: +- Process Termination +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Application sourcetype: XmlWinEventLog separator: EventCode +separator_value: 3000 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index b604bbe548..0ac0455e60 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -3,10 +3,17 @@ id: 821de0a6-c5b4-491b-a27e-187552792817 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log CAPI2 70 +description: This event log records events related to cryptographic operations, including the deletion and export of certificates. +mitre_components: +- Certificate Registration +- Process Metadata +- Application Log Content +- OS API Execution +- Host Status source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational sourcetype: xmlwineventlog separator: EventCode +separator_value: 70 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml index 376d347618..5d677ef6c5 100644 --- a/data_sources/windows_event_log_capi2_81.yml +++ b/data_sources/windows_event_log_capi2_81.yml @@ -3,10 +3,17 @@ id: 463ff898-8135-4c0e-811e-f8629dfc5027 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log CAPI2 81 +description: Logs an error when attempting to verify the digital signature of a file, including details about the file path, signature failure, and the process involved. +mitre_components: +- File Access +- File Metadata +- Malware Metadata +- Application Log Content +- Process Metadata source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational sourcetype: xmlwineventlog separator: EventCode +separator_value: 81 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml index aecc0bf864..0399196d64 100644 --- a/data_sources/windows_event_log_certificateservicesclient_1007.yml +++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml @@ -3,10 +3,17 @@ id: c51444e3-479d-4c4a-b111-e8276a3acf39 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log CertificateServicesClient 1007 +description: Logs the export of a certificate from the local certificate store, including details about the certificate thumbprint, subject names, and the process involved. +mitre_components: +- Certificate Registration +- Certificate Metadata +- Process Metadata +- Application Log Content +- User Account Metadata source: XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational sourcetype: XmlWinEventLog separator: EventCode +separator_value: 1007 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml index e06fcfddca..4ff6962a3c 100644 --- a/data_sources/windows_event_log_defender_1121.yml +++ b/data_sources/windows_event_log_defender_1121.yml @@ -3,10 +3,15 @@ id: 84a254c5-7900-4b52-a324-a176adb7c11d version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Defender 1121 +description: Logs an event when a Windows Defender attack surface reduction rule fires in block mode. +mitre_components: +- Application Log Content +- Host Status +- Process Creation source: WinEventLog:Microsoft-Windows-Windows Defender/Operational sourcetype: xmlwineventlog separator: EventCode +separator_value: 1121 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml index 669bbb0047..bc1fe7c3eb 100644 --- a/data_sources/windows_event_log_defender_1122.yml +++ b/data_sources/windows_event_log_defender_1122.yml @@ -3,10 +3,15 @@ id: 4a2d0499-f489-4557-82f4-f357025cf3e7 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Defender 1122 +description: Logs an event when a process attempts to load a DLL that is blocked by an attack surface reduction rule. +mitre_components: +- Application Log Content +- Process Creation +- Module Load source: WinEventLog:Microsoft-Windows-Windows Defender/Operational sourcetype: xmlwineventlog separator: EventCode +separator_value: 1122 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml index 1227f6efa2..d2572d00c0 100644 --- a/data_sources/windows_event_log_defender_1129.yml +++ b/data_sources/windows_event_log_defender_1129.yml @@ -3,10 +3,15 @@ id: 0572e119-a48a-4c70-bc58-90e453edacd2 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Defender 1129 +description: Logs an event when a user overrides a security policy set by an Attack Surface Reduction rule in Microsoft Defender. +mitre_components: +- User Account Authentication +- Security Policy Modification +- Application Log Content source: WinEventLog:Microsoft-Windows-Windows Defender/Operational sourcetype: xmlwineventlog separator: EventCode +separator_value: 1129 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_defender_5007.yml b/data_sources/windows_event_log_defender_5007.yml index 598ccc1740..80df5e2faa 100644 --- a/data_sources/windows_event_log_defender_5007.yml +++ b/data_sources/windows_event_log_defender_5007.yml @@ -3,7 +3,10 @@ id: 27f18792-8d95-4871-8853-874b7faf023f version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Defender 5007 +description: Logs an event when Windows Defender antimalware settings are modified. +mitre_components: +- Service Modification +- Service Metadata source: WinEventLog:Microsoft-Windows-Windows Defender/Operational sourcetype: xmlwineventlog separator: EventCode diff --git a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml index d17981dc1f..22e591d7a7 100644 --- a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml +++ b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml @@ -3,7 +3,10 @@ id: 2490537e-5e0c-46f7-9209-f56f852aa217 version: 1 date: '2024-11-21' author: Michael Haag, Splunk -description: Data source object for Windows Event Microsoft Windows TerminalServices RDPClient 1024 +description: Logs an event when a Remote Desktop Protocol (RDP) client successfully connects to a remote host. +mitre_components: +- Network Connection Creation +- Logon Session Creation source: WinEventLog:Microsoft-Windows-TerminalServices-RDPClient/Operational sourcetype: WinEventLog separator: EventCode diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index 66896969fe..507a925e5d 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -3,10 +3,14 @@ id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Printservice 316 +description: Logs an event when printer drivers are installed or updated on the system. +mitre_components: +- Driver Load +- Driver Metadata source: WinEventLog:Microsoft-Windows-PrintService/Admin sourcetype: WinEventLog separator: EventCode +separator_value: 316 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index bc9a09f66d..ef717b2d20 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -3,10 +3,15 @@ id: e3a26785-4389-4830-8d7b-3dad4252719e version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Printservice 808 +description: Logs an event when the print spooler service fails to load a printer plug-in module. +mitre_components: +- Module Load +- Application Log Content +- Service Metadata source: WinEventLog:Microsoft-Windows-PrintService/Admin sourcetype: WinEventLog separator: EventCode +separator_value: 808 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index 1081028aa2..14c3a6bc1a 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -3,10 +3,15 @@ id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log RemoteConnectionManager 1149 +description: Logs an event when a Remote Desktop Service session is initialized. +mitre_components: +- Network Connection Creation +- Logon Session Creation +- Logon Session Metadata source: WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational sourcetype: wineventlog separator: EventCode +separator_value: 1149 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index 1e2404f690..41e0c3fced 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -3,10 +3,14 @@ id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 1100 +description: Logs an event when the event logging service has shut down. +mitre_components: +- Host Status +- System Configuration Changes source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 1100 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index 0646f5ad48..50bcf53f6b 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -3,10 +3,15 @@ id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 1102 +description: Logs an event when the audit log is cleared. +mitre_components: +- User Account Modification +- Logon Session Metadata +- File Deletion source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 1102 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index 4f02eeb290..0faba24352 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -3,10 +3,15 @@ id: 08682968-0366-4882-9559-fe4fe018a846 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4624 +description: Logs an event when an account successfully logs on to a system. +mitre_components: +- Logon Session Creation +- User Account Authentication +- Logon Session Metadata source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4624 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml index 3928d3b9d6..5f58a8d248 100644 --- a/data_sources/windows_event_log_security_4625.yml +++ b/data_sources/windows_event_log_security_4625.yml @@ -3,10 +3,14 @@ id: 365a02c2-7d18-4baf-b76e-d90c20bbe6ed version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4625 +description: Logs an event when an account fails to log on to a system. +mitre_components: +- User Account Authentication +- Logon Session Metadata source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4625 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml index dbb7cc5c55..d91715f957 100644 --- a/data_sources/windows_event_log_security_4627.yml +++ b/data_sources/windows_event_log_security_4627.yml @@ -3,10 +3,15 @@ id: e35c7b9a-b451-4084-95a5-43b7f8965cac version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4627 +description: Logs an event when a successful account logon occurs and displays the list of groups the logged-on account belongs to. +mitre_components: +- Logon Session Creation +- Group Metadata +- User Account Authentication source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4627 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml index 26445ed64d..ade1d81ce9 100644 --- a/data_sources/windows_event_log_security_4648.yml +++ b/data_sources/windows_event_log_security_4648.yml @@ -3,10 +3,14 @@ id: 6a367f8b-1ee0-463d-94a7-029757c6cd02 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4648 +description: Logged when an account logon is attempted by a process by explicitly specifying the credentials of that account +mitre_components: +- User Account Authentication +- Logon Session Creation source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4648 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml index 1970056294..f55185240e 100644 --- a/data_sources/windows_event_log_security_4662.yml +++ b/data_sources/windows_event_log_security_4662.yml @@ -3,10 +3,14 @@ id: f3c2cd64-0b5f-4013-8201-35dc03828ec6 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4662 +description: Logs an event when a user accessed an object within the Active Directory, such as creating, modifying, or deleting it +mitre_components: +- Active Directory Object Access +- Active Directory Object Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4662 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml index 78a84369d9..addcc024d9 100644 --- a/data_sources/windows_event_log_security_4663.yml +++ b/data_sources/windows_event_log_security_4663.yml @@ -3,10 +3,14 @@ id: 5d6dca8c-dad9-494f-a321-ef2b0b92fbf4 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4663 +description: Logs an event when a user or process tried to access a file, directory, registry key, or other system object on the computer +mitre_components: +- File Access +- File Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4663 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index 69d9996108..71facef2ee 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -3,10 +3,14 @@ id: 43f189b6-369d-4a32-a34c-57e0d38d92f1 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4672 +description: Logs an event when a user with administrative privileges logs on to a system. +mitre_components: +- Logon Session Creation +- User Account Authentication source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4672 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml index 8f0a3e3a57..082bce7da0 100644 --- a/data_sources/windows_event_log_security_4688.yml +++ b/data_sources/windows_event_log_security_4688.yml @@ -3,10 +3,14 @@ id: d195eb26-a81c-45ed-aeb3-25792e8a985a version: 2 date: '2024-09-26' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4688 +description: Logs the creation of a new process +mitre_components: +- Process Creation +- Command Execution source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4688 configuration: Enabling Windows event log process command line logging via group policy object https://lantern.splunk.com/Security/Product_Tips/Enterprise_Security/Enabling_Windows_event_log_process_command_line_logging_via_group_policy_object supported_TA: diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml index 0aa1b8ab6a..9f863f1161 100644 --- a/data_sources/windows_event_log_security_4698.yml +++ b/data_sources/windows_event_log_security_4698.yml @@ -3,10 +3,14 @@ id: 32c06703-02d3-47ec-8856-b0dc3045866c version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4698 +description: Logs an event when a new scheduled task is created +mitre_components: +- Scheduled Job Creation +- Scheduled Job Metadata source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4698 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml index a0184e87ef..764795adec 100644 --- a/data_sources/windows_event_log_security_4699.yml +++ b/data_sources/windows_event_log_security_4699.yml @@ -3,10 +3,14 @@ id: 4727dead-d063-4333-9ddd-59823a416aff version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4699 +description: Logs an event when a scheduled task is deleted from the system. +mitre_components: +- Scheduled Job Metadata +- Scheduled Job Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4699 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml index 6d914bbc8c..a776196575 100644 --- a/data_sources/windows_event_log_security_4703.yml +++ b/data_sources/windows_event_log_security_4703.yml @@ -3,10 +3,14 @@ id: e256673b-16e8-4b74-b7aa-9eed6ce67072 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4703 +description: Logs an event when a token right is adjusted on a Windows system. +mitre_components: +- User Account Modification +- Process Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4703 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml index 07f7261f0d..a5305e46f7 100644 --- a/data_sources/windows_event_log_security_4719.yml +++ b/data_sources/windows_event_log_security_4719.yml @@ -3,10 +3,14 @@ id: 954033e6-dd05-4775-a1f2-1f19632f4420 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4719 +description: Logs an event when a system audit policy is modified on a Windows system. +mitre_components: +- Service Modification +- User Account Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4719 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml index bbed05f0b9..390bcae55a 100644 --- a/data_sources/windows_event_log_security_4720.yml +++ b/data_sources/windows_event_log_security_4720.yml @@ -3,10 +3,13 @@ id: 7ef1c9e5-691b-48c2-811b-eba91d2d2f1d version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4720 +description: Logs an event when a new user account is created on a Windows system. +mitre_components: +- User Account Creation source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4720 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml index 1960e64264..2a42ca008c 100644 --- a/data_sources/windows_event_log_security_4724.yml +++ b/data_sources/windows_event_log_security_4724.yml @@ -3,10 +3,13 @@ id: 117fe51f-93f8-4589-8e8b-c6b7b7154c7d version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4724 +description: Logs an event when an attempt is made to reset an account's password, whether successful or not. +mitre_components: +- User Account Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4724 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml index 62a49da0e5..a70b371aa9 100644 --- a/data_sources/windows_event_log_security_4725.yml +++ b/data_sources/windows_event_log_security_4725.yml @@ -3,10 +3,13 @@ id: 31fd887d-0d14-44cc-bb64-80063a9f2968 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4725 +description: Logs an event when a user account has been disabled in Active Directory. +mitre_components: +- User Account Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4725 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml index feb818c007..c6bcdb5ef2 100644 --- a/data_sources/windows_event_log_security_4726.yml +++ b/data_sources/windows_event_log_security_4726.yml @@ -3,10 +3,13 @@ id: 0b56dcd7-0f72-4a05-9226-d6059781737b version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4726 +description: Logs an event when a user account is deleted from Active Directory. +mitre_components: +- User Account Deletion source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4726 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml index 574c3dd7aa..4cf35ee519 100644 --- a/data_sources/windows_event_log_security_4732.yml +++ b/data_sources/windows_event_log_security_4732.yml @@ -3,10 +3,13 @@ id: b0d61c5d-aefe-486a-9152-de45cc10fbb4 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4732 +description: Logs an event when a member is added to a security-enabled local group on a Windows system. +mitre_components: +- Group Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4732 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml index 7ee6af3b45..7298903e0b 100644 --- a/data_sources/windows_event_log_security_4738.yml +++ b/data_sources/windows_event_log_security_4738.yml @@ -3,10 +3,13 @@ id: cb85709b-101e-41a9-bb60-d2108f79dfbd version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4738 +description: Logs an event when a user account's properties, such as permissions or memberships, are modified on a Windows system. +mitre_components: +- User Account Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4738 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml index 4ac66f85a9..3642e4b93e 100644 --- a/data_sources/windows_event_log_security_4739.yml +++ b/data_sources/windows_event_log_security_4739.yml @@ -3,10 +3,14 @@ id: c1e0442a-8a97-405d-baf2-057c5d68cd9a version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4739 +description: Logs an event when a domain policy, such as account or lockout policy, is modified in Active Directory or local security settings. +mitre_components: +- Group Modification +- Active Directory Object Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4739 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml index 2d112fb492..7d4b9f3150 100644 --- a/data_sources/windows_event_log_security_4741.yml +++ b/data_sources/windows_event_log_security_4741.yml @@ -3,10 +3,16 @@ id: ef87257f-e7d1-4856-abae-097b2cfdcdb4 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4741 +description: Logs the creation of a new computer account in Active Directory, including details about the account name, domain, and the user performing the action. +mitre_components: +- Active Directory Object Creation +- User Account Metadata +- Application Log Content +- Configuration Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4741 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4742.yml b/data_sources/windows_event_log_security_4742.yml index 042c75ef93..8668a87cdd 100644 --- a/data_sources/windows_event_log_security_4742.yml +++ b/data_sources/windows_event_log_security_4742.yml @@ -3,7 +3,12 @@ id: ea830adf-5450-489a-bcdc-fb8d2cbe674c version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4742 +description: Logs changes to the properties of a computer account in Active Directory, including details about the modified attributes and the user performing the action. +mitre_components: +- Active Directory Object Modification +- User Account Metadata +- Application Log Content +- Configuration Modification source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml index 474534451e..bee4afe853 100644 --- a/data_sources/windows_event_log_security_4768.yml +++ b/data_sources/windows_event_log_security_4768.yml @@ -3,10 +3,16 @@ id: 4a5fd6ed-66bd-4f34-bc74-51c00c73c298 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4768 +description: Logs Kerberos pre-authentication requests, including details about the user account, authentication type, and client IP address. +mitre_components: +- User Account Authentication +- Active Directory Credential Request +- Logon Session Metadata +- User Account Metadata source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4768 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml index d8694a1dea..ce9343c3c8 100644 --- a/data_sources/windows_event_log_security_4769.yml +++ b/data_sources/windows_event_log_security_4769.yml @@ -3,10 +3,16 @@ id: 358d5520-f40b-4fa2-b799-966c030cb731 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4769 +description: Logs Kerberos service ticket requests, including details about the requesting user, target service, and client IP address. +mitre_components: +- Active Directory Credential Request +- User Account Authentication +- Logon Session Metadata +- User Account Metadata source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4769 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml index f31e4b50fe..b4db6f6ec1 100644 --- a/data_sources/windows_event_log_security_4771.yml +++ b/data_sources/windows_event_log_security_4771.yml @@ -3,10 +3,16 @@ id: 418debbb-adf3-48ec-9efd-59d45f8861e5 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4771 +description: Logs failed Kerberos pre-authentication attempts, including details about the user account, client IP, and failure reason. +mitre_components: +- User Account Authentication +- Logon Session Metadata +- User Account Metadata +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4771 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml index e6ea80b2c5..fb3ebc5cac 100644 --- a/data_sources/windows_event_log_security_4776.yml +++ b/data_sources/windows_event_log_security_4776.yml @@ -3,10 +3,16 @@ id: 1da9092a-c795-4a26-ace8-d43855524e96 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4776 +description: Logs NTLM authentication attempts, including details about the account name, authentication status, and the originating workstation. +mitre_components: +- User Account Authentication +- Logon Session Metadata +- User Account Metadata +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4776 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index b807a5a1d9..453217cdd0 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -3,10 +3,16 @@ id: 9732ffe7-ebce-4557-865c-1725a0f633cb version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4781 +description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action. +mitre_components: +- User Account Modification +- User Account Metadata +- Active Directory Object Modification +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4781 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4794.yml b/data_sources/windows_event_log_security_4794.yml index f3ea14b1c1..bc7d30320b 100644 --- a/data_sources/windows_event_log_security_4794.yml +++ b/data_sources/windows_event_log_security_4794.yml @@ -3,10 +3,16 @@ id: ec7da74f-274a-4bde-aa0e-15c68aca0426 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4794 +description: Logs attempts to set the Directory Services Restore Mode (DSRM) administrator password, including details about the account name and the user performing the action. +mitre_components: +- User Account Modification +- User Account Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4798.yml b/data_sources/windows_event_log_security_4798.yml index 0d64c1b297..ff04d051f0 100644 --- a/data_sources/windows_event_log_security_4798.yml +++ b/data_sources/windows_event_log_security_4798.yml @@ -3,7 +3,12 @@ id: 29e97f72-eb2e-400e-b0c9-81277547e43b version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4798 +description: Logs an enumeration of local group membership on a system, including details about the groups queried and the account performing the action. +mitre_components: +- Group Enumeration +- Group Metadata +- User Account Metadata +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml index 4d978151e4..b44884ed9a 100644 --- a/data_sources/windows_event_log_security_4876.yml +++ b/data_sources/windows_event_log_security_4876.yml @@ -3,10 +3,16 @@ id: 4a78722a-9cd9-44e8-b010-dffad5c7f170 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4876 +description: Logs the result of a cryptographic operation, including details about the key, algorithm used, and whether the operation succeeded or failed. +mitre_components: +- Certificate Registration +- User Account Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4876 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml index 3c82a3eb85..dd50c8c278 100644 --- a/data_sources/windows_event_log_security_4886.yml +++ b/data_sources/windows_event_log_security_4886.yml @@ -3,10 +3,16 @@ id: c5abd97d-b468-451f-bd65-b4f97efa4ecc version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4886 +description: Logs the deletion of a cryptographic key container, including details about the key container name and the user performing the action. +mitre_components: +- Certificate Registration +- User Account Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4886 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml index 39f5cbb7cc..80ac4f9763 100644 --- a/data_sources/windows_event_log_security_4887.yml +++ b/data_sources/windows_event_log_security_4887.yml @@ -3,10 +3,16 @@ id: 994c7b19-a623-4231-9818-f00e453b9a75 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 4887 +description: Logs cryptographic operations performed by a Windows system, including details about the certificate or key used and the operation type. +mitre_components: +- Certificate Registration +- User Account Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 4887 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml index 9e685b1960..f2494cadc9 100644 --- a/data_sources/windows_event_log_security_5136.yml +++ b/data_sources/windows_event_log_security_5136.yml @@ -3,10 +3,16 @@ id: 7ba3737e-231e-455d-824e-cd077749f835 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 5136 +description: Logs modifications made to an Active Directory object, including details about the object name, type, and the changes applied. +mitre_components: +- Active Directory Object Modification +- Active Directory Object Access +- User Account Metadata +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 5136 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index aef4beca13..8787969fa8 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -3,10 +3,16 @@ id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 5137 +description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action. +mitre_components: +- Active Directory Object Creation +- Active Directory Object Modification +- User Account Metadata +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 5137 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index 0687f2ebb5..8d1883d26c 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -3,10 +3,16 @@ id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 5140 +description: Logs access to a network share, including details about the user, share path, and the access type. +mitre_components: +- Network Share Access +- File Access +- User Account Metadata +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 5140 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml index 07f144b980..713a598abe 100644 --- a/data_sources/windows_event_log_security_5141.yml +++ b/data_sources/windows_event_log_security_5141.yml @@ -3,10 +3,16 @@ id: eafb35fa-f034-4be3-8508-d9173a73c0a1 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 5141 +description: Logs the deletion of an Active Directory object, including details about the object name, type, and the user performing the action. +mitre_components: +- Active Directory Object Deletion +- Active Directory Object Modification +- User Account Metadata +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 5141 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index 1d6560e36e..70a22f8d7c 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -3,10 +3,16 @@ id: 0746479b-7b82-4d7e-8811-0b35da00f798 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log Security 5145 +description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions. +mitre_components: +- Network Share Access +- File Access +- User Account Metadata +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode +separator_value: 5145 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml index d930d69759..a2b9a2e197 100644 --- a/data_sources/windows_event_log_system_4720.yml +++ b/data_sources/windows_event_log_system_4720.yml @@ -3,10 +3,16 @@ id: f01d4758-05c8-4ac4-a9a5-33500dd5eb6c version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log System 4720 +description: Logs the creation of a new user account, including details about the account name, associated domain, and the account performing the action. +mitre_components: +- User Account Creation +- User Account Metadata +- Active Directory Object Creation +- Application Log Content source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode +separator_value: 4720 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml index 706432fb4e..a94f1b82e5 100644 --- a/data_sources/windows_event_log_system_4726.yml +++ b/data_sources/windows_event_log_system_4726.yml @@ -3,10 +3,16 @@ id: 05e6b2df-b50e-441b-8ac8-565f2e80d62f version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log System 4726 +description: Logs the deletion of a user account, including details about the account name, associated domain, and the account performing the action. +mitre_components: +- User Account Deletion +- User Account Metadata +- Active Directory Object Modification +- Application Log Content source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode +separator_value: 4726 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml index 906b7cd67d..9d5380f3ca 100644 --- a/data_sources/windows_event_log_system_4728.yml +++ b/data_sources/windows_event_log_system_4728.yml @@ -3,10 +3,16 @@ id: 4549f0ac-3df9-4bfb-bea5-1459690c8040 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log System 4728 +description: Logs the addition of a user to a security-enabled group, including details about the group name, user account, and associated domain. +mitre_components: +- Group Modification +- Group Metadata +- User Account Metadata +- Active Directory Object Modification source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode +separator_value: 4728 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml index 2b5c6845fa..4079da5408 100644 --- a/data_sources/windows_event_log_system_7036.yml +++ b/data_sources/windows_event_log_system_7036.yml @@ -3,10 +3,16 @@ id: a6e9b34f-1507-4fa1-a4ba-684d1b676a34 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log System 7036 +description: Logs state changes of a Windows service, including details about the service name and its new state (e.g., started or stopped). +mitre_components: +- Service Metadata +- OS API Execution +- Application Log Content +- Host Status source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode +separator_value: 7036 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index 9a669d6262..e1d08e67e4 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -3,10 +3,16 @@ id: 91738e9e-d112-41c9-b91b-e5868d8993d9 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log System 7040 +description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type. +mitre_components: +- Service Modification +- Service Metadata +- OS API Execution +- Application Log Content source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode +separator_value: 7040 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index 335efef1a8..b7e8511470 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -3,10 +3,16 @@ id: 614dedc8-8a14-4393-ba9b-6f093cbcd293 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log System 7045 +description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type. +mitre_components: +- Service Creation +- Service Metadata +- OS API Execution +- Process Metadata source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode +separator_value: 7045 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index 979e053f1d..c7af8fd33b 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -3,10 +3,16 @@ id: f8c777f8-e88a-4bba-ae8a-79b250212f23 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows Event Log TaskScheduler 200 +description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations. +mitre_components: +- Scheduled Job Creation +- Scheduled Job Metadata +- Service Creation +- OS API Execution source: WinEventLog:Microsoft-Windows-TaskScheduler/Operational sourcetype: wineventlog separator: EventCode +separator_value: 200 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_iis.yml b/data_sources/windows_iis.yml index a78d2107dd..0aa47abd32 100644 --- a/data_sources/windows_iis.yml +++ b/data_sources/windows_iis.yml @@ -3,7 +3,12 @@ id: 469335b3-b6ad-49e2-bbe6-47e15c1464a7 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows IIS +description: Logs changes to IIS server configuration, including updates to settings, modules, authentication methods, and site bindings. +mitre_components: +- Service Modification +- Cloud Service Modification +- Configuration Modification +- Application Log Content source: IIS:Configuration:Operational sourcetype: IIS:Configuration:Operational separator: EventID diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml index 7657e0c52c..26d05e774f 100644 --- a/data_sources/windows_iis_29.yml +++ b/data_sources/windows_iis_29.yml @@ -3,10 +3,16 @@ id: 1d99ddd7-7fec-4dea-bf4f-1f4906142328 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk -description: Data source object for Windows IIS 29 +description: Logs modifications to IIS server authentication settings, including updates to client certificate requirements and authentication methods. +mitre_components: +- Service Modification +- Configuration Modification +- Certificate Registration +- Application Log Content source: IIS:Configuration:Operational sourcetype: IIS:Configuration:Operational separator: EventID +separator_value: 29 supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 From cbac872e4109835bbe9998d867423347ad653cc3 Mon Sep 17 00:00:00 2001 From: delgado-jacob <29643013+delgado-jacob@users.noreply.github.com> Date: Thu, 23 Jan 2025 09:38:13 -0700 Subject: [PATCH 02/67] Update version and modified date. Fix reference in detection. --- data_sources/asl_aws_cloudtrail.yml | 34 +- data_sources/aws_cloudfront.yml | 183 +- .../aws_cloudtrail_assumerolewithsaml.yml | 198 +- data_sources/aws_cloudtrail_consolelogin.yml | 177 +- data_sources/aws_cloudtrail_copyobject.yml | 187 +- .../aws_cloudtrail_createaccesskey.yml | 175 +- data_sources/aws_cloudtrail_createkey.yml | 211 +- .../aws_cloudtrail_createloginprofile.yml | 173 +- .../aws_cloudtrail_createnetworkaclentry.yml | 205 +- .../aws_cloudtrail_createpolicyversion.yml | 175 +- .../aws_cloudtrail_createsnapshot.yml | 193 +- data_sources/aws_cloudtrail_createtask.yml | 191 +- .../aws_cloudtrail_createvirtualmfadevice.yml | 171 +- .../aws_cloudtrail_deactivatemfadevice.yml | 171 +- ...cloudtrail_deleteaccountpasswordpolicy.yml | 169 +- data_sources/aws_cloudtrail_deletealarms.yml | 239 +-- .../aws_cloudtrail_deletedetector.yml | 165 +- data_sources/aws_cloudtrail_deletegroup.yml | 175 +- data_sources/aws_cloudtrail_deleteipset.yml | 165 +- .../aws_cloudtrail_deleteloggroup.yml | 169 +- .../aws_cloudtrail_deletelogstream.yml | 171 +- .../aws_cloudtrail_deletenetworkaclentry.yml | 183 +- data_sources/aws_cloudtrail_deletepolicy.yml | 171 +- data_sources/aws_cloudtrail_deleterule.yml | 171 +- .../aws_cloudtrail_deletesnapshot.yml | 253 +-- data_sources/aws_cloudtrail_deletetrail.yml | 167 +- .../aws_cloudtrail_deletevirtualmfadevice.yml | 167 +- data_sources/aws_cloudtrail_deletewebacl.yml | 167 +- ...aws_cloudtrail_describeeventaggregates.yml | 159 +- ...s_cloudtrail_describeimagescanfindings.yml | 1831 +++++++++-------- ...ws_cloudtrail_getaccountpasswordpolicy.yml | 165 +- data_sources/aws_cloudtrail_getobject.yml | 183 +- .../aws_cloudtrail_getpassworddata.yml | 185 +- data_sources/aws_cloudtrail_jobcreated.yml | 134 +- .../aws_cloudtrail_modifydbinstance.yml | 283 +-- .../aws_cloudtrail_modifyimageattribute.yml | 173 +- ...aws_cloudtrail_modifysnapshotattribute.yml | 163 +- data_sources/aws_cloudtrail_putbucketacl.yml | 191 +- .../aws_cloudtrail_putbucketlifecycle.yml | 193 +- .../aws_cloudtrail_putbucketreplication.yml | 217 +- .../aws_cloudtrail_putbucketversioning.yml | 199 +- data_sources/aws_cloudtrail_putimage.yml | 179 +- data_sources/aws_cloudtrail_putkeypolicy.yml | 179 +- .../aws_cloudtrail_replacenetworkaclentry.yml | 192 +- ...aws_cloudtrail_setdefaultpolicyversion.yml | 165 +- data_sources/aws_cloudtrail_stoplogging.yml | 155 +- ...cloudtrail_updateaccountpasswordpolicy.yml | 176 +- .../aws_cloudtrail_updateloginprofile.yml | 160 +- .../aws_cloudtrail_updatesamlprovider.yml | 343 +-- data_sources/aws_cloudtrail_updatetrail.yml | 173 +- data_sources/aws_cloudwatchlogs_vpcflow.yml | 124 +- data_sources/aws_security_hub.yml | 227 +- ...p_role_assignment_to_service_principal.yml | 170 +- ...re_active_directory_add_member_to_role.yml | 122 +- ...ive_directory_add_owner_to_application.yml | 132 +- ...active_directory_add_service_principal.yml | 122 +- ...active_directory_add_unverified_domain.yml | 121 +- ...ctive_directory_consent_to_application.yml | 132 +- ...irectory_disable_strong_authentication.yml | 117 +- .../azure_active_directory_enable_account.yml | 116 +- ..._active_directory_invite_external_user.yml | 117 +- ...ve_directory_reset_password_(by_admin).yml | 119 +- ...ve_directory_set_domain_authentication.yml | 119 +- ...zure_active_directory_sign_in_activity.yml | 219 +- ...re_active_directory_update_application.yml | 119 +- ..._directory_update_authorization_policy.yml | 121 +- .../azure_active_directory_update_user.yml | 118 +- ...irectory_user_registered_security_info.yml | 113 +- ..._or_update_an_azure_automation_account.yml | 192 +- ..._or_update_an_azure_automation_runbook.yml | 193 +- ..._or_update_an_azure_automation_webhook.yml | 210 +- data_sources/bro_conn.yml | 15 +- data_sources/bro_dns.yml | 17 +- data_sources/bro_files.yml | 18 +- data_sources/bro_http.yml | 17 +- data_sources/bro_loaded_scripts.yml | 15 +- data_sources/bro_ntp.yml | 15 +- data_sources/bro_ocsp.yml | 19 +- data_sources/bro_ssl.yml | 19 +- data_sources/bro_weird.yml | 17 +- data_sources/bro_x509.yml | 19 +- data_sources/circleci.yml | 127 +- data_sources/crowdstrike_processrollup2.yml | 200 +- data_sources/crushftp.yml | 21 +- data_sources/g_suite_drive.yml | 85 +- data_sources/g_suite_gmail.yml | 161 +- data_sources/github.yml | 401 ++-- .../google_workspace_login_failure.yml | 91 +- .../google_workspace_login_success.yml | 87 +- data_sources/ivanti_vtm_audit.yml | 36 +- data_sources/kubernetes_audit.yml | 111 +- data_sources/kubernetes_falco.yml | 87 +- data_sources/linux_auditd_add_user.yml | 62 +- data_sources/linux_auditd_execve.yml | 34 +- data_sources/linux_auditd_path.yml | 63 +- data_sources/linux_auditd_proctitle.yml | 27 +- data_sources/linux_auditd_service_stop.yml | 58 +- data_sources/linux_auditd_syscall.yml | 106 +- data_sources/linux_secure.yml | 87 +- .../ms365_defender_incident_alerts.yml | 414 ++-- data_sources/ms_defender_atp_alerts.yml | 691 ++++--- data_sources/nginx_access.yml | 135 +- data_sources/o365.yml | 23 +- ...add_app_role_assignment_grant_to_user_.yml | 159 +- ..._role_assignment_to_service_principal_.yml | 158 +- data_sources/o365_add_mailboxpermission.yml | 142 +- data_sources/o365_add_member_to_role_.yml | 163 +- .../o365_add_owner_to_application_.yml | 168 +- data_sources/o365_add_service_principal_.yml | 167 +- data_sources/o365_change_user_license_.yml | 159 +- data_sources/o365_consent_to_application_.yml | 152 +- .../o365_disable_strong_authentication_.yml | 154 +- data_sources/o365_mailitemsaccessed.yml | 145 +- data_sources/o365_modifyfolderpermissions.yml | 181 +- .../o365_set_company_information_.yml | 169 +- data_sources/o365_set_mailbox.yml | 161 +- data_sources/o365_update_application_.yml | 167 +- .../o365_update_authorization_policy_.yml | 151 +- data_sources/o365_update_user_.yml | 165 +- data_sources/o365_userloggedin.yml | 165 +- data_sources/o365_userloginfailed.yml | 183 +- data_sources/okta.yml | 23 +- data_sources/osquery.yml | 123 +- data_sources/palo_alto_network_threat.yml | 62 +- data_sources/palo_alto_network_traffic.yml | 65 +- data_sources/pingid.yml | 71 +- .../powershell_installed_iis_modules.yml | 35 +- .../powershell_script_block_logging_4104.yml | 162 +- data_sources/powershell_sip_inventory.yml | 15 +- data_sources/splunk.yml | 63 +- data_sources/splunk_stream_http.yml | 113 +- data_sources/splunk_stream_ip.yml | 146 +- data_sources/splunk_stream_tcp.yml | 23 +- data_sources/suricata.yml | 109 +- data_sources/sysmon_eventid_1.yml | 333 +-- data_sources/sysmon_eventid_10.yml | 183 +- data_sources/sysmon_eventid_11.yml | 188 +- data_sources/sysmon_eventid_12.yml | 178 +- data_sources/sysmon_eventid_13.yml | 205 +- data_sources/sysmon_eventid_15.yml | 184 +- data_sources/sysmon_eventid_17.yml | 156 +- data_sources/sysmon_eventid_18.yml | 165 +- data_sources/sysmon_eventid_20.yml | 171 +- data_sources/sysmon_eventid_21.yml | 175 +- data_sources/sysmon_eventid_22.yml | 163 +- data_sources/sysmon_eventid_23.yml | 187 +- data_sources/sysmon_eventid_3.yml | 215 +- data_sources/sysmon_eventid_5.yml | 159 +- data_sources/sysmon_eventid_6.yml | 166 +- data_sources/sysmon_eventid_7.yml | 206 +- data_sources/sysmon_eventid_8.yml | 187 +- data_sources/sysmon_eventid_9.yml | 161 +- data_sources/sysmon_for_linux_eventid_1.yml | 205 +- data_sources/sysmon_for_linux_eventid_11.yml | 161 +- .../windows_active_directory_admon.yml | 103 +- data_sources/windows_defender_alerts.yml | 44 +- .../windows_event_log_application_2282.yml | 130 +- .../windows_event_log_application_3000.yml | 115 +- data_sources/windows_event_log_capi2_70.yml | 123 +- data_sources/windows_event_log_capi2_81.yml | 129 +- ...ent_log_certificateservicesclient_1007.yml | 125 +- .../windows_event_log_defender_1121.yml | 132 +- .../windows_event_log_defender_1122.yml | 126 +- .../windows_event_log_defender_1129.yml | 111 +- .../windows_event_log_defender_5007.yml | 101 +- ...indows_terminalservices_rdpclient_1024.yml | 101 +- .../windows_event_log_printservice_316.yml | 102 +- .../windows_event_log_printservice_808.yml | 113 +- ...event_log_remoteconnectionmanager_1149.yml | 103 +- .../windows_event_log_security_1100.yml | 142 +- .../windows_event_log_security_1102.yml | 154 +- .../windows_event_log_security_4624.yml | 227 +- .../windows_event_log_security_4625.yml | 217 +- .../windows_event_log_security_4627.yml | 178 +- .../windows_event_log_security_4648.yml | 204 +- .../windows_event_log_security_4662.yml | 178 +- .../windows_event_log_security_4663.yml | 191 +- .../windows_event_log_security_4672.yml | 158 +- .../windows_event_log_security_4688.yml | 239 +-- .../windows_event_log_security_4698.yml | 158 +- .../windows_event_log_security_4699.yml | 156 +- .../windows_event_log_security_4703.yml | 196 +- .../windows_event_log_security_4719.yml | 167 +- .../windows_event_log_security_4720.yml | 202 +- .../windows_event_log_security_4724.yml | 189 +- .../windows_event_log_security_4725.yml | 186 +- .../windows_event_log_security_4726.yml | 188 +- .../windows_event_log_security_4732.yml | 181 +- .../windows_event_log_security_4738.yml | 229 ++- .../windows_event_log_security_4739.yml | 205 +- .../windows_event_log_security_4741.yml | 231 ++- .../windows_event_log_security_4742.yml | 233 +-- .../windows_event_log_security_4768.yml | 193 +- .../windows_event_log_security_4769.yml | 193 +- .../windows_event_log_security_4771.yml | 181 +- .../windows_event_log_security_4776.yml | 163 +- .../windows_event_log_security_4781.yml | 194 +- .../windows_event_log_security_4794.yml | 178 +- .../windows_event_log_security_4798.yml | 174 +- .../windows_event_log_security_4876.yml | 162 +- .../windows_event_log_security_4886.yml | 146 +- .../windows_event_log_security_4887.yml | 152 +- .../windows_event_log_security_5136.yml | 185 +- .../windows_event_log_security_5137.yml | 178 +- .../windows_event_log_security_5140.yml | 213 +- .../windows_event_log_security_5141.yml | 174 +- .../windows_event_log_security_5145.yml | 253 +-- .../windows_event_log_system_4720.yml | 211 +- .../windows_event_log_system_4726.yml | 191 +- .../windows_event_log_system_4728.yml | 191 +- .../windows_event_log_system_7036.yml | 142 +- .../windows_event_log_system_7040.yml | 147 +- .../windows_event_log_system_7045.yml | 147 +- .../windows_event_log_taskscheduler_200.yml | 140 +- data_sources/windows_iis.yml | 21 +- data_sources/windows_iis_29.yml | 53 +- .../network/detect_outbound_ldap_traffic.yml | 9 +- 217 files changed, 17727 insertions(+), 17073 deletions(-) diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml index 8311be25cc..05767f098b 100644 --- a/data_sources/asl_aws_cloudtrail.yml +++ b/data_sources/asl_aws_cloudtrail.yml @@ -1,26 +1,26 @@ name: ASL AWS CloudTrail id: 1dcf9cfb-0e91-44c6-81b3-61b2574ec898 -version: 1 -date: '2025-01-14' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Represents AWS API dataset data collection from Amazon Security Lake. mitre_components: -- Cloud Service Metadata -- Cloud Service Modification -- Cloud Storage Access -- Instance Creation -- Instance Deletion -- Instance Start -- Instance Stop -- Instance Modification -- Cloud Storage Creation -- Cloud Storage Deletion -- Cloud Service Enumeration -- Cloud Storage Enumeration + - Cloud Service Metadata + - Cloud Service Modification + - Cloud Storage Access + - Instance Creation + - Instance Deletion + - Instance Start + - Instance Stop + - Instance Modification + - Cloud Storage Creation + - Cloud Storage Deletion + - Cloud Service Enumeration + - Cloud Storage Enumeration source: aws_asl sourcetype: aws:asl separator: api.operation supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 diff --git a/data_sources/aws_cloudfront.yml b/data_sources/aws_cloudfront.yml index bc4196951d..b8eb8a416b 100644 --- a/data_sources/aws_cloudfront.yml +++ b/data_sources/aws_cloudfront.yml @@ -1,102 +1,103 @@ name: AWS Cloudfront id: 780086dc-2384-45b6-ade7-56cb00105464 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs requests made to AWS CloudFront distributions, including details on client access, response data, and performance metrics. +description: Logs requests made to AWS CloudFront distributions, including details + on client access, response data, and performance metrics. mitre_components: -- Network Traffic Content -- Network Traffic Flow -- Response Metadata -- Response Content -- Logon Session Metadata -- Cloud Service Metadata + - Network Traffic Content + - Network Traffic Flow + - Response Metadata + - Response Content + - Logon Session Metadata + - Cloud Service Metadata source: aws sourcetype: aws:cloudfront:accesslogs supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- bytes -- bytes_in -- bytes_out -- c_ip -- c_port -- cached -- category -- client_ip -- cs_bytes -- cs_cookie -- cs_host -- cs_method -- cs_protocol -- cs_protocol_version -- cs_referer -- cs_uri_query -- cs_uri_stem -- cs_user_agent -- date -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- duration -- edge_location_name -- eventtype -- fle_encrypted_fields -- fle_status -- host -- http_content_type -- http_method -- http_user_agent -- http_user_agent_length -- index -- linecount -- punct -- response_time -- sc_bytes -- sc_content_len -- sc_content_type -- sc_range_end -- sc_range_start -- sc_status -- source -- sourcetype -- splunk_server -- src -- src_ip -- src_port -- ssl_cipher -- ssl_protocol -- status -- tag -- tag::eventtype -- time -- time_taken -- time_to_first_byte -- timeendpos -- timestartpos -- uri_path -- url -- url_domain -- url_length -- vendor_product -- x_edge_detail_result_type -- x_edge_location -- x_edge_request_id -- x_edge_response_result_type -- x_edge_result_type -- x_forwarded_for -- x_host_header + - _time + - action + - app + - bytes + - bytes_in + - bytes_out + - c_ip + - c_port + - cached + - category + - client_ip + - cs_bytes + - cs_cookie + - cs_host + - cs_method + - cs_protocol + - cs_protocol_version + - cs_referer + - cs_uri_query + - cs_uri_stem + - cs_user_agent + - date + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - duration + - edge_location_name + - eventtype + - fle_encrypted_fields + - fle_status + - host + - http_content_type + - http_method + - http_user_agent + - http_user_agent_length + - index + - linecount + - punct + - response_time + - sc_bytes + - sc_content_len + - sc_content_type + - sc_range_end + - sc_range_start + - sc_status + - source + - sourcetype + - splunk_server + - src + - src_ip + - src_port + - ssl_cipher + - ssl_protocol + - status + - tag + - tag::eventtype + - time + - time_taken + - time_to_first_byte + - timeendpos + - timestartpos + - uri_path + - url + - url_domain + - url_length + - vendor_product + - x_edge_detail_result_type + - x_edge_location + - x_edge_request_id + - x_edge_response_result_type + - x_edge_result_type + - x_forwarded_for + - x_host_header example_log: "2023-11-07\t16:58:21\tIAD55-P5\t921\t44.192.78.55\tGET\td3u5aue66f5ui4.cloudfront.net\t\ /plugins/servlet/com.jsos.shell/ShellServlet\t200\t-\tSlackbot-LinkExpanding%201.0%20(+https://api.slack.com/robots)\t\ -\t-\tLambdaGeneratedResponse\tsGwvFCkFU4qlMxatCoJRgW87P7Ee8bKQor3U6lRt6I6jaFvLC7vcPA==\t\ diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml index acd5a6247f..c9823cd2d7 100644 --- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml +++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml @@ -1,114 +1,114 @@ name: AWS CloudTrail AssumeRoleWithSAML id: 1e28f2a6-2db9-405f-b298-18734a293f77 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs attempts to assume roles via SAML authentication in AWS, including details of identity provider and role mapping. mitre_components: -- User Account Authentication -- Logon Session Creation -- User Account Metadata -- Cloud Service Metadata -- Instance Modification + - User Account Authentication + - Logon Session Creation + - User Account Metadata + - Cloud Service Metadata + - Instance Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: AssumeRoleWithSAML supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.durationSeconds -- requestParameters.principalArn -- requestParameters.roleArn -- requestParameters.roleSessionName -- requestParameters.sAMLAssertionID -- resources{}.ARN -- resources{}.accountId -- resources{}.type -- responseElements.assumedRoleUser.arn -- responseElements.assumedRoleUser.assumedRoleId -- responseElements.audience -- responseElements.credentials.accessKeyId -- responseElements.credentials.expiration -- responseElements.credentials.sessionToken -- responseElements.issuer -- responseElements.nameQualifier -- responseElements.subject -- responseElements.subjectType -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- src_user -- src_user_id -- src_user_type -- start_time -- status -- tag -- tag::action -- tag::eventtype -- temp_access_key -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.identityProvider -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- user_agent -- user_arn -- user_id -- user_name -- user_role -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.durationSeconds + - requestParameters.principalArn + - requestParameters.roleArn + - requestParameters.roleSessionName + - requestParameters.sAMLAssertionID + - resources{}.ARN + - resources{}.accountId + - resources{}.type + - responseElements.assumedRoleUser.arn + - responseElements.assumedRoleUser.assumedRoleId + - responseElements.audience + - responseElements.credentials.accessKeyId + - responseElements.credentials.expiration + - responseElements.credentials.sessionToken + - responseElements.issuer + - responseElements.nameQualifier + - responseElements.subject + - responseElements.subjectType + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - src_user + - src_user_id + - src_user_type + - start_time + - status + - tag + - tag::action + - tag::eventtype + - temp_access_key + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.identityProvider + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - user_agent + - user_arn + - user_id + - user_name + - user_role + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "principalId": "ZRu9MRAjiG9tvi1QBNfdI664G5A=:rodsoto@rodsoto.onmicrosoft.com", "userName": "rodsoto@rodsoto.onmicrosoft.com", "identityProvider": "ZRu9MRAjiG9tvi1QBNfdI664G5A="}, "eventTime": "2021-01-22T03:44:16Z", diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml index 934d502f32..0d05cff28d 100644 --- a/data_sources/aws_cloudtrail_consolelogin.yml +++ b/data_sources/aws_cloudtrail_consolelogin.yml @@ -1,101 +1,102 @@ name: AWS CloudTrail ConsoleLogin id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs attempts to sign in to the AWS Management Console, including successful and failed login events. +description: Logs attempts to sign in to the AWS Management Console, including successful + and failed login events. mitre_components: -- User Account Authentication -- Logon Session Creation -- User Account Metadata -- Logon Session Metadata -- Cloud Service Metadata + - User Account Authentication + - Logon Session Creation + - User Account Metadata + - Logon Session Metadata + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: ConsoleLogin supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- additionalEventData.LoginTo -- additionalEventData.MFAUsed -- additionalEventData.MobileVersion -- app -- authentication_method -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- desc -- dest -- dvc -- errorCode -- errorMessage -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- reason -- recipientAccountId -- region -- requestParameters -- responseElements.ConsoleLogin -- result -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::action -- tag::eventtype -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.type -- userIdentity.userName -- user_access_key -- user_agent -- user_group_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - additionalEventData.LoginTo + - additionalEventData.MFAUsed + - additionalEventData.MobileVersion + - app + - authentication_method + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - desc + - dest + - dvc + - errorCode + - errorMessage + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - reason + - recipientAccountId + - region + - requestParameters + - responseElements.ConsoleLogin + - result + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::action + - tag::eventtype + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.type + - userIdentity.userName + - user_access_key + - user_agent + - user_group_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "accountId": "140429656527", "accessKeyId": "", "userName": "HIDDEN_DUE_TO_SECURITY_REASONS"}, "eventTime": "2022-10-19T20:33:38Z", "eventSource": "signin.amazonaws.com", "eventName": diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml index 72a9c6af4b..9edd40bb4d 100644 --- a/data_sources/aws_cloudtrail_copyobject.yml +++ b/data_sources/aws_cloudtrail_copyobject.yml @@ -1,106 +1,107 @@ name: AWS CloudTrail CopyObject id: 965083f4-64a8-403f-99cc-252e1a6bd3b6 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs operations that copy objects within or between AWS S3 buckets, including details of source and destination. +description: Logs operations that copy objects within or between AWS S3 buckets, including + details of source and destination. mitre_components: -- Cloud Storage Access -- Cloud Storage Modification -- Cloud Storage Metadata -- Instance Modification + - Cloud Storage Access + - Cloud Storage Modification + - Cloud Storage Metadata + - Instance Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_values: CopyObject supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- additionalEventData.AuthenticationMethod -- additionalEventData.CipherSuite -- additionalEventData.SSEApplied -- additionalEventData.SignatureVersion -- additionalEventData.bytesTransferredIn -- additionalEventData.bytesTransferredOut -- additionalEventData.x-amz-id-2 -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.Host -- requestParameters.bucketName -- requestParameters.key -- requestParameters.x-amz-copy-source -- requestParameters.x-amz-server-side-encryption -- requestParameters.x-amz-server-side-encryption-aws-kms-key-id -- resources{}.ARN -- resources{}.accountId -- resources{}.type -- responseElements.x-amz-server-side-encryption -- responseElements.x-amz-server-side-encryption-aws-kms-key-id -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - additionalEventData.AuthenticationMethod + - additionalEventData.CipherSuite + - additionalEventData.SSEApplied + - additionalEventData.SignatureVersion + - additionalEventData.bytesTransferredIn + - additionalEventData.bytesTransferredOut + - additionalEventData.x-amz-id-2 + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.Host + - requestParameters.bucketName + - requestParameters.key + - requestParameters.x-amz-copy-source + - requestParameters.x-amz-server-side-encryption + - requestParameters.x-amz-server-side-encryption-aws-kms-key-id + - resources{}.ARN + - resources{}.accountId + - resources{}.type + - responseElements.x-amz-server-side-encryption + - responseElements.x-amz-server-side-encryption-aws-kms-key-id + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"}, diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml index 6e95f8ab0f..d72354f779 100644 --- a/data_sources/aws_cloudtrail_createaccesskey.yml +++ b/data_sources/aws_cloudtrail_createaccesskey.yml @@ -1,100 +1,101 @@ name: AWS CloudTrail CreateAccessKey id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of new AWS access keys, including details of the associated user and permissions. +description: Logs the creation of new AWS access keys, including details of the associated + user and permissions. mitre_components: -- User Account Creation -- User Account Metadata -- Cloud Service Modification -- Cloud Service Metadata + - User Account Creation + - User Account Metadata + - Cloud Service Modification + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateAccessKey supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.userName -- responseElements.accessKey.accessKeyId -- responseElements.accessKey.createDate -- responseElements.accessKey.status -- responseElements.accessKey.userName -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- src_user_name -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.userName + - responseElements.accessKey.accessKeyId + - responseElements.accessKey.createDate + - responseElements.accessKey.status + - responseElements.accessKey.userName + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - src_user_name + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121521347698:user/bhavin_cli", "accountId": "121521347698", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml index 655ce8762f..293ecba3cd 100644 --- a/data_sources/aws_cloudtrail_createkey.yml +++ b/data_sources/aws_cloudtrail_createkey.yml @@ -1,118 +1,119 @@ name: AWS CloudTrail CreateKey id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of new AWS KMS keys, including details of key properties and associated metadata. +description: Logs the creation of new AWS KMS keys, including details of key properties + and associated metadata. mitre_components: -- Cloud Service Creation -- Cloud Service Metadata -- Instance Creation -- Volume Metadata + - Cloud Service Creation + - Cloud Service Metadata + - Instance Creation + - Volume Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateKey supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.bypassPolicyLockoutSafetyCheck -- requestParameters.customerMasterKeySpec -- requestParameters.description -- requestParameters.keyUsage -- requestParameters.origin -- requestParameters.policy -- resources{}.ARN -- resources{}.accountId -- resources{}.type -- responseElements.keyMetadata.aWSAccountId -- responseElements.keyMetadata.arn -- responseElements.keyMetadata.creationDate -- responseElements.keyMetadata.customerMasterKeySpec -- responseElements.keyMetadata.description -- responseElements.keyMetadata.enabled -- responseElements.keyMetadata.encryptionAlgorithms{} -- responseElements.keyMetadata.keyId -- responseElements.keyMetadata.keyManager -- responseElements.keyMetadata.keyState -- responseElements.keyMetadata.keyUsage -- responseElements.keyMetadata.origin -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.bypassPolicyLockoutSafetyCheck + - requestParameters.customerMasterKeySpec + - requestParameters.description + - requestParameters.keyUsage + - requestParameters.origin + - requestParameters.policy + - resources{}.ARN + - resources{}.accountId + - resources{}.type + - responseElements.keyMetadata.aWSAccountId + - responseElements.keyMetadata.arn + - responseElements.keyMetadata.creationDate + - responseElements.keyMetadata.customerMasterKeySpec + - responseElements.keyMetadata.description + - responseElements.keyMetadata.enabled + - responseElements.keyMetadata.encryptionAlgorithms{} + - responseElements.keyMetadata.keyId + - responseElements.keyMetadata.keyManager + - responseElements.keyMetadata.keyState + - responseElements.keyMetadata.keyUsage + - responseElements.keyMetadata.origin + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext": diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml index 7c272ab23f..df6b04e40d 100644 --- a/data_sources/aws_cloudtrail_createloginprofile.yml +++ b/data_sources/aws_cloudtrail_createloginprofile.yml @@ -1,99 +1,100 @@ name: AWS CloudTrail CreateLoginProfile id: 0024fdb1-0d62-4449-970a-746952cf80b6 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of login profiles for IAM users, including associated metadata and authentication settings. +description: Logs the creation of login profiles for IAM users, including associated + metadata and authentication settings. mitre_components: -- User Account Creation -- User Account Metadata -- Logon Session Metadata -- Cloud Service Metadata + - User Account Creation + - User Account Metadata + - Logon Session Metadata + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateLoginProfile supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.passwordResetRequired -- requestParameters.userName -- responseElements.loginProfile.createDate -- responseElements.loginProfile.passwordResetRequired -- responseElements.loginProfile.userName -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.passwordResetRequired + - requestParameters.userName + - responseElements.loginProfile.createDate + - responseElements.loginProfile.passwordResetRequired + - responseElements.loginProfile.userName + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml index 65830e0d0c..993b03197a 100644 --- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml @@ -1,115 +1,116 @@ name: AWS CloudTrail CreateNetworkAclEntry id: 45934028-10ec-4ab5-a7b1-a6349b833e67 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of new entries in a network ACL, including rules to allow or deny specific network traffic. +description: Logs the creation of new entries in a network ACL, including rules to + allow or deny specific network traffic. mitre_components: -- Firewall Rule Modification -- Network Connection Creation -- Cloud Service Modification -- Cloud Service Metadata + - Firewall Rule Modification + - Network Connection Creation + - Cloud Service Modification + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateNetworkAclEntry supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- direction -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object -- object_category -- object_id -- product -- protocol -- protocol_code -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.aclProtocol -- requestParameters.cidrBlock -- requestParameters.egress -- requestParameters.networkAclId -- requestParameters.ruleAction -- requestParameters.ruleNumber -- responseElements._return -- responseElements.requestId -- rule_action -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- src_ip_range -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - direction + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object + - object_category + - object_id + - product + - protocol + - protocol_code + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.aclProtocol + - requestParameters.cidrBlock + - requestParameters.egress + - requestParameters.networkAclId + - requestParameters.ruleAction + - requestParameters.ruleNumber + - responseElements._return + - responseElements.requestId + - rule_action + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - src_ip_range + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext": diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml index cc6b2d03f0..2973c651b0 100644 --- a/data_sources/aws_cloudtrail_createpolicyversion.yml +++ b/data_sources/aws_cloudtrail_createpolicyversion.yml @@ -1,100 +1,101 @@ name: AWS CloudTrail CreatePolicyVersion id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of new versions of IAM policies, including changes to permissions and attached roles or resources. +description: Logs the creation of new versions of IAM policies, including changes + to permissions and attached roles or resources. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata -- User Account Metadata -- Group Modification + - Cloud Service Modification + - Cloud Service Metadata + - User Account Metadata + - Group Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreatePolicyVersion supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.policyArn -- requestParameters.policyDocument -- requestParameters.setAsDefault -- responseElements.policyVersion.createDate -- responseElements.policyVersion.isDefaultVersion -- responseElements.policyVersion.versionId -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.policyArn + - requestParameters.policyDocument + - requestParameters.setAsDefault + - responseElements.policyVersion.createDate + - responseElements.policyVersion.isDefaultVersion + - responseElements.policyVersion.versionId + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLNMCDVJZAY", "arn": "arn:aws:iam::111111111111:user/rhino_escalate", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLHSQZPZFZ", "userName": diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml index db7c828449..ae5c392552 100644 --- a/data_sources/aws_cloudtrail_createsnapshot.yml +++ b/data_sources/aws_cloudtrail_createsnapshot.yml @@ -1,109 +1,110 @@ name: AWS CloudTrail CreateSnapshot id: 514135a2-f4b2-4d32-8f31-d87824887f9f -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon EBS volume, including details about the snapshot ID and resource type. +description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon + EBS volume, including details about the snapshot ID and resource type. mitre_components: -- Snapshot Creation -- Snapshot Metadata -- Volume Metadata -- Cloud Service Metadata + - Snapshot Creation + - Snapshot Metadata + - Volume Metadata + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateSnapshot supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.tagSpecificationSet.items{}.resourceType -- requestParameters.tagSpecificationSet.items{}.tags{}.key -- requestParameters.tagSpecificationSet.items{}.tags{}.value -- requestParameters.volumeId -- responseElements.encrypted -- responseElements.ownerId -- responseElements.requestId -- responseElements.snapshotId -- responseElements.startTime -- responseElements.status -- responseElements.tagSet.items{}.key -- responseElements.tagSet.items{}.value -- responseElements.volumeId -- responseElements.volumeSize -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.tagSpecificationSet.items{}.resourceType + - requestParameters.tagSpecificationSet.items{}.tags{}.key + - requestParameters.tagSpecificationSet.items{}.tags{}.value + - requestParameters.volumeId + - responseElements.encrypted + - responseElements.ownerId + - responseElements.requestId + - responseElements.snapshotId + - responseElements.startTime + - responseElements.status + - responseElements.tagSet.items{}.key + - responseElements.tagSet.items{}.value + - responseElements.volumeId + - responseElements.volumeSize + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml index ee7394b6e4..7808c2b9cc 100644 --- a/data_sources/aws_cloudtrail_createtask.yml +++ b/data_sources/aws_cloudtrail_createtask.yml @@ -1,108 +1,109 @@ name: AWS CloudTrail CreateTask id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of a new task in AWS services, such as ECS, including details about the task definition and resource allocation. +description: Logs the creation of a new task in AWS services, such as ECS, including + details about the task definition and resource allocation. mitre_components: -- Scheduled Job Creation -- Scheduled Job Metadata -- Cloud Service Metadata -- Instance Creation + - Scheduled Job Creation + - Scheduled Job Metadata + - Cloud Service Metadata + - Instance Creation source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_name: CreateTask supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.cloudWatchLogGroupArn -- requestParameters.destinationLocationArn -- requestParameters.options.logLevel -- requestParameters.options.verifyMode -- requestParameters.schedule.scheduleExpression -- requestParameters.sourceLocationArn -- responseElements.taskArn -- sessionCredentialFromConsole -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.cloudWatchLogGroupArn + - requestParameters.destinationLocationArn + - requestParameters.options.logLevel + - requestParameters.options.verifyMode + - requestParameters.schedule.scheduleExpression + - requestParameters.sourceLocationArn + - responseElements.taskArn + - sessionCredentialFromConsole + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WQQQQQ:abc@acme.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/abc@acme.com", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLOB2GM111", "sessionContext": diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml index ba978e3343..7b6b181672 100644 --- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml @@ -1,98 +1,99 @@ name: AWS CloudTrail CreateVirtualMFADevice id: 13e6e952-0dad-4190-865c-fb5911725f7a -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of a new virtual multi-factor authentication (MFA) device, including details about the associated user and configuration. +description: Logs the creation of a new virtual multi-factor authentication (MFA) + device, including details about the associated user and configuration. mitre_components: -- User Account Creation -- User Account Metadata -- Cloud Service Creation -- Cloud Service Metadata + - User Account Creation + - User Account Metadata + - Cloud Service Creation + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateVirtualMFADevice supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.path -- requestParameters.virtualMFADeviceName -- responseElements.virtualMFADevice.serialNumber -- sessionCredentialFromConsole -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.path + - requestParameters.virtualMFADeviceName + - responseElements.virtualMFADevice.serialNumber + - sessionCredentialFromConsole + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527", "accessKeyId": "ASIASBMSCQHH2YXNXJBU", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml index a62bdde87c..e53018b544 100644 --- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml +++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml @@ -1,98 +1,99 @@ name: AWS CloudTrail DeactivateMFADevice id: 7397a10b-1150-4de9-8062-a96454ae53b2 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the deactivation of a multi-factor authentication (MFA) device, including details about the associated user and the device. +description: Logs the deactivation of a multi-factor authentication (MFA) device, + including details about the associated user and the device. mitre_components: -- User Account Modification -- User Account Metadata -- Cloud Service Modification -- Cloud Service Metadata + - User Account Modification + - User Account Metadata + - Cloud Service Modification + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeactivateMFADevice supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.serialNumber -- requestParameters.userName -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.serialNumber + - requestParameters.userName + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111", "accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml index 631ac8d253..9d10c7443a 100644 --- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml @@ -1,97 +1,98 @@ name: AWS CloudTrail DeleteAccountPasswordPolicy id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the deletion of an account-level password policy in AWS, including details about the account and policy being removed. +description: Logs the deletion of an account-level password policy in AWS, including + details about the account and policy being removed. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata + - Cloud Service Modification + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteAccountPasswordPolicy supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- desc -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters -- responseElements -- sessionCredentialFromConsole -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - desc + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters + - responseElements + - sessionCredentialFromConsole + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111", "accessKeyId": "ASIASBMSCQHHWMDJXSE6", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml index 2fdf221e51..7babfa595c 100644 --- a/data_sources/aws_cloudtrail_deletealarms.yml +++ b/data_sources/aws_cloudtrail_deletealarms.yml @@ -1,132 +1,133 @@ name: AWS CloudTrail DeleteAlarms id: b0730ac8-0992-4de8-b000-2c7d0fc7a61f -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Bhavin Patel, Splunk -description: Logs the deletion of CloudWatch alarms, including details about the alarm names and associated monitoring configurations. +description: Logs the deletion of CloudWatch alarms, including details about the alarm + names and associated monitoring configurations. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata -- Application Log Content -- Host Status + - Cloud Service Modification + - Cloud Service Metadata + - Application Log Content + - Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteAlarms supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- authentication_method -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- desc -- dest -- dest_ip_range -- dest_port_range -- direction -- dvc -- errorCode -- errorMessage -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- image_id -- index -- instance_type -- linecount -- managementEvent -- msg -- object -- object_attrs -- object_category -- object_id -- product -- protocol -- protocol_code -- punct -- readOnly -- reason -- recipientAccountId -- region -- requestID -- requestParameters.alarmNames{} -- responseElements -- result -- result_id -- rule_action -- sessionCredentialFromConsole -- signature -- source -- sourceIPAddress -- splunk_server -- splunk_server_group -- src -- src_ip -- src_ip_range -- src_port_range -- src_user -- src_user_id -- src_user_name -- src_user_role -- src_user_type -- start_time -- status -- tag -- tag::action -- tag::eventtype -- tag::object_category -- temp_access_key -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.invokedBy -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_role -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - authentication_method + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - desc + - dest + - dest_ip_range + - dest_port_range + - direction + - dvc + - errorCode + - errorMessage + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - image_id + - index + - instance_type + - linecount + - managementEvent + - msg + - object + - object_attrs + - object_category + - object_id + - product + - protocol + - protocol_code + - punct + - readOnly + - reason + - recipientAccountId + - region + - requestID + - requestParameters.alarmNames{} + - responseElements + - result + - result_id + - rule_action + - sessionCredentialFromConsole + - signature + - source + - sourceIPAddress + - splunk_server + - splunk_server_group + - src + - src_ip + - src_ip_range + - src_port_range + - src_user + - src_user_id + - src_user_name + - src_user_role + - src_user_type + - start_time + - status + - tag + - tag::action + - tag::eventtype + - tag::object_category + - temp_access_key + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.invokedBy + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_role + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLKZK7JIDWN:AutoScaling-ManageAlarms", "arn": "arn:aws:sts::111111111111:assumed-role/AWSServiceRoleForApplicationAutoScaling_DynamoDBTable/AutoScaling-ManageAlarms", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLJ7ZZZZZZZ", "sessionContext": diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml index f467d9348d..f20cba230e 100644 --- a/data_sources/aws_cloudtrail_deletedetector.yml +++ b/data_sources/aws_cloudtrail_deletedetector.yml @@ -1,95 +1,96 @@ name: AWS CloudTrail DeleteDetector id: 5d8bd475-c8bc-4447-b27f-efa508728b90 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the deletion of an Amazon GuardDuty detector, including details about the detector ID and associated configurations. +description: Logs the deletion of an Amazon GuardDuty detector, including details + about the detector ID and associated configurations. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata -- Host Status -- Application Log Content + - Cloud Service Modification + - Cloud Service Metadata + - Host Status + - Application Log Content source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteDetector supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.detectorId -- responseElements.__type -- responseElements.message -- result_id -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.detectorId + - responseElements.__type + - responseElements.message + - result_id + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml index a683fd2697..e2bd256da6 100644 --- a/data_sources/aws_cloudtrail_deletegroup.yml +++ b/data_sources/aws_cloudtrail_deletegroup.yml @@ -1,100 +1,101 @@ name: AWS CloudTrail DeleteGroup id: c95308a4-a943-42ca-b112-f90a05c21bd3 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the deletion of an IAM group in AWS, including details about the group name and its associated policies or members. +description: Logs the deletion of an IAM group in AWS, including details about the + group name and its associated policies or members. mitre_components: -- Group Modification -- Group Metadata -- User Account Metadata -- Cloud Service Modification + - Group Modification + - Group Metadata + - User Account Metadata + - Cloud Service Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteGroup supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- errorMessage -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- reason -- recipientAccountId -- region -- requestID -- requestParameters.groupName -- responseElements -- result -- result_id -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - errorMessage + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - reason + - recipientAccountId + - region + - requestID + - requestParameters.groupName + - responseElements + - result + - result_id + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121522247101:user/bhavin_cli", "accountId": "121522247101", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml index 4c8770dcb2..ce670c3006 100644 --- a/data_sources/aws_cloudtrail_deleteipset.yml +++ b/data_sources/aws_cloudtrail_deleteipset.yml @@ -1,95 +1,96 @@ name: AWS CloudTrail DeleteIPSet id: ebdeeb63-77a0-4808-a6fe-549956731377 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details about the IP set ID and its associated configurations. +description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details + about the IP set ID and its associated configurations. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata -- Firewall Rule Modification + - Cloud Service Modification + - Cloud Service Metadata + - Firewall Rule Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteIPSet supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.detectorId -- requestParameters.ipSetId -- responseElements.__type -- responseElements.message -- result_id -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.detectorId + - requestParameters.ipSetId + - responseElements.__type + - responseElements.message + - result_id + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml index 04895c5bab..3aafeff30a 100644 --- a/data_sources/aws_cloudtrail_deleteloggroup.yml +++ b/data_sources/aws_cloudtrail_deleteloggroup.yml @@ -1,97 +1,98 @@ name: AWS CloudTrail DeleteLogGroup id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the deletion of a CloudWatch log group, including details about the log group name and associated resources. +description: Logs the deletion of a CloudWatch log group, including details about + the log group name and associated resources. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata -- Application Log Content -- Host Status + - Cloud Service Modification + - Cloud Service Metadata + - Application Log Content + - Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteLogGroup supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- apiVersion -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.logGroupName -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - apiVersion + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.logGroupName + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml index 998218f3d2..7f4805833e 100644 --- a/data_sources/aws_cloudtrail_deletelogstream.yml +++ b/data_sources/aws_cloudtrail_deletelogstream.yml @@ -1,98 +1,99 @@ name: AWS CloudTrail DeleteLogStream id: 6f8bb808-89f8-465e-a34d-229df2f46402 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the deletion of a log stream within a CloudWatch log group, including details about the stream name and associated log group. +description: Logs the deletion of a log stream within a CloudWatch log group, including + details about the stream name and associated log group. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata -- Application Log Content -- Host Status + - Cloud Service Modification + - Cloud Service Metadata + - Application Log Content + - Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteLogStream supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- apiVersion -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.logGroupName -- requestParameters.logStreamName -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - apiVersion + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.logGroupName + - requestParameters.logStreamName + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml index ce7ac268b0..deca786012 100644 --- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml @@ -1,104 +1,105 @@ name: AWS CloudTrail DeleteNetworkAclEntry id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the deletion of a network ACL entry in AWS, including details about the rule number and associated network ACL. +description: Logs the deletion of a network ACL entry in AWS, including details about + the rule number and associated network ACL. mitre_components: -- Firewall Rule Modification -- Cloud Service Modification -- Cloud Service Metadata + - Firewall Rule Modification + - Cloud Service Modification + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteNetworkAclEntry supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- direction -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.egress -- requestParameters.networkAclId -- requestParameters.ruleNumber -- responseElements._return -- responseElements.requestId -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - direction + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.egress + - requestParameters.networkAclId + - requestParameters.ruleNumber + - responseElements._return + - responseElements.requestId + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext": diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml index fd3dbe18c2..62fa46bbd0 100644 --- a/data_sources/aws_cloudtrail_deletepolicy.yml +++ b/data_sources/aws_cloudtrail_deletepolicy.yml @@ -1,98 +1,99 @@ name: AWS CloudTrail DeletePolicy id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the deletion of an IAM policy in AWS, including details about the policy name and its associated roles or users. +description: Logs the deletion of an IAM policy in AWS, including details about the + policy name and its associated roles or users. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata + - Cloud Service Modification + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeletePolicy supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- errorMessage -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- reason -- recipientAccountId -- region -- requestID -- requestParameters.policyArn -- responseElements -- result -- result_id -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - errorMessage + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - reason + - recipientAccountId + - region + - requestID + - requestParameters.policyArn + - responseElements + - result + - result_id + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::151521547504:user/bhavin_cli", "accountId": "151521547504", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml index b5bf81865b..b5f3c819fa 100644 --- a/data_sources/aws_cloudtrail_deleterule.yml +++ b/data_sources/aws_cloudtrail_deleterule.yml @@ -1,98 +1,99 @@ name: AWS CloudTrail DeleteRule id: b5760623-f3ca-492d-a372-d5c2b3567dfc -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the deletion of an event rule in AWS EventBridge, including details about the rule name and its associated targets or schedules. +description: Logs the deletion of an event rule in AWS EventBridge, including details + about the rule name and its associated targets or schedules. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata -- Scheduled Job Modification -- Application Log Content + - Cloud Service Modification + - Cloud Service Metadata + - Scheduled Job Modification + - Application Log Content source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteRule supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- apiVersion -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.changeToken -- requestParameters.ruleId -- responseElements.changeToken -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - apiVersion + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.changeToken + - requestParameters.ruleId + - responseElements.changeToken + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml index dc157cb6bd..62a075237d 100644 --- a/data_sources/aws_cloudtrail_deletesnapshot.yml +++ b/data_sources/aws_cloudtrail_deletesnapshot.yml @@ -1,139 +1,140 @@ name: AWS CloudTrail DeleteSnapshot id: b0731ac8-0992-4de8-b000-2c7d0fc2a61f -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Bhavin Patel, Splunk -description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS snapshot, including details about the snapshot ID and associated resource. +description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS + snapshot, including details about the snapshot ID and associated resource. mitre_components: -- Snapshot Deletion -- Snapshot Metadata -- Cloud Service Modification -- Cloud Service Metadata + - Snapshot Deletion + - Snapshot Metadata + - Cloud Service Modification + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteSnapshot supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- authentication_method -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- desc -- dest -- dest_ip_range -- dest_port_range -- direction -- dvc -- errorCode -- errorMessage -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- image_id -- index -- instance_type -- linecount -- managementEvent -- msg -- object -- object_attrs -- object_category -- object_id -- product -- protocol -- protocol_code -- punct -- readOnly -- reason -- recipientAccountId -- region -- requestID -- requestParameters.force -- requestParameters.snapshotId -- responseElements -- responseElements._return -- responseElements.requestId -- result -- result_id -- rule_action -- sessionCredentialFromConsole -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- splunk_server_group -- src -- src_ip -- src_ip_range -- src_port_range -- src_user -- src_user_id -- src_user_name -- src_user_role -- src_user_type -- start_time -- status -- tag -- tag::action -- tag::eventtype -- tag::object_category -- temp_access_key -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_role -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - authentication_method + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - desc + - dest + - dest_ip_range + - dest_port_range + - direction + - dvc + - errorCode + - errorMessage + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - image_id + - index + - instance_type + - linecount + - managementEvent + - msg + - object + - object_attrs + - object_category + - object_id + - product + - protocol + - protocol_code + - punct + - readOnly + - reason + - recipientAccountId + - region + - requestID + - requestParameters.force + - requestParameters.snapshotId + - responseElements + - responseElements._return + - responseElements.requestId + - result + - result_id + - rule_action + - sessionCredentialFromConsole + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - splunk_server_group + - src + - src_ip + - src_ip_range + - src_port_range + - src_user + - src_user_id + - src_user_name + - src_user_role + - src_user_type + - start_time + - status + - tag + - tag::action + - tag::eventtype + - tag::object_category + - temp_access_key + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_role + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.09", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WPXXXX:daftpunk@splunk.com", "arn": "arn:aws:sts::11111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/daftpunk@splunk.com", "accountId": "11111111111111", "accessKeyId": "AAAAAAAAAAAAAAAAAA", "sessionContext": diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml index 50d8ba5c17..2d077d3400 100644 --- a/data_sources/aws_cloudtrail_deletetrail.yml +++ b/data_sources/aws_cloudtrail_deletetrail.yml @@ -1,96 +1,97 @@ name: AWS CloudTrail DeleteTrail id: a5af09ff-07b6-4df6-92a0-2146bfe402c8 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the deletion of an AWS CloudTrail trail, including details about the trail name and its associated logging configurations. +description: Logs the deletion of an AWS CloudTrail trail, including details about + the trail name and its associated logging configurations. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata -- Application Log Content -- Host Status + - Cloud Service Modification + - Cloud Service Metadata + - Application Log Content + - Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteTrail supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.name -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.name + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml index 64de0ba5eb..ba7bd9f0b0 100644 --- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml @@ -1,96 +1,97 @@ name: AWS CloudTrail DeleteVirtualMFADevice id: 84a08d6b-3d59-4260-8cab-84278ada262f -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a virtual Multi-Factor Authentication (MFA) device is deleted in AWS CloudTrail. +description: Logs an event when a virtual Multi-Factor Authentication (MFA) device + is deleted in AWS CloudTrail. mitre_components: -- User Account Authentication -- User Account Deletion + - User Account Authentication + - User Account Deletion source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteVirtualMFADevice supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.serialNumber -- responseElements -- sessionCredentialFromConsole -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.serialNumber + - responseElements + - sessionCredentialFromConsole + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111", "accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml index 8d9c4b1cb9..dad7353b3b 100644 --- a/data_sources/aws_cloudtrail_deletewebacl.yml +++ b/data_sources/aws_cloudtrail_deletewebacl.yml @@ -1,96 +1,97 @@ name: AWS CloudTrail DeleteWebACL id: 90da5f08-7961-4c29-8de8-01364982aadf -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS CloudTrail. +description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS + CloudTrail. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata + - Cloud Service Modification + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteWebACL supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- apiVersion -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.changeToken -- requestParameters.webACLId -- responseElements.changeToken -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - apiVersion + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.changeToken + - requestParameters.webACLId + - responseElements.changeToken + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml index 68042cdaa6..51c3b5464a 100644 --- a/data_sources/aws_cloudtrail_describeeventaggregates.yml +++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml @@ -1,92 +1,93 @@ name: AWS CloudTrail DescribeEventAggregates id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when aggregate details about AWS events are queried, often for analysis. +description: Logs an event when aggregate details about AWS events are queried, often + for analysis. mitre_components: -- Cloud Service Enumeration -- Cloud Service Metadata + - Cloud Service Enumeration + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DescribeEventAggregates supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.aggregateField -- requestParameters.filter.eventStatusCodes{} -- requestParameters.filter.startTimes{}.from -- responseElements -- sessionCredentialFromConsole -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.aggregateField + - requestParameters.filter.eventStatusCodes{} + - requestParameters.filter.startTimes{}.from + - responseElements + - sessionCredentialFromConsole + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527", "accessKeyId": "ASIASBMSCQHHQQ6LB24V", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml index d29dc3e798..fab3a5b39f 100644 --- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml +++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml @@ -1,900 +1,985 @@ name: AWS CloudTrail DescribeImageScanFindings id: 688ea789-9ba2-4970-90a2-17e541e273c9 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when findings from an image vulnerability scan are described using the DescribeImageScanFindings operation in AWS CloudTrail. +description: Logs an event when findings from an image vulnerability scan are described + using the DescribeImageScanFindings operation in AWS CloudTrail. mitre_components: -- Image Metadata -- Image Modification -- Malware Metadata + - Image Metadata + - Image Modification + - Malware Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DescribeImageScanFindings supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.imageId.imageDigest -- requestParameters.maxResults -- requestParameters.repositoryName -- responseElements.imageId.imageDigest -- responseElements.imageScanFindings.findingSeverityCounts.HIGH -- responseElements.imageScanFindings.findingSeverityCounts.INFORMATIONAL -- responseElements.imageScanFindings.findingSeverityCounts.LOW -- responseElements.imageScanFindings.findingSeverityCounts.MEDIUM -- responseElements.imageScanFindings.findingSeverityCounts.UNDEFINED -- responseElements.imageScanFindings.findings{}.attributes{}.key -- responseElements.imageScanFindings.findings{}.attributes{}.value -- responseElements.imageScanFindings.findings{}.description -- responseElements.imageScanFindings.findings{}.name -- responseElements.imageScanFindings.findings{}.severity -- responseElements.imageScanFindings.findings{}.uri -- responseElements.imageScanFindings.imageScanCompletedAt -- responseElements.imageScanFindings.vulnerabilitySourceUpdatedAt -- responseElements.imageScanStatus.description -- responseElements.imageScanStatus.status -- responseElements.registryId -- responseElements.repositoryName -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region -example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": - "AAAAAAAAAAAAAAAAAAAAA:test@test.com", "arn": "arn:aws:sts::111111111111:assumed-role/role_name/test@test.com", - "accountId": "111111111111", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "sessionContext": - {"sessionIssuer": {"type": "Role", "principalId": "AKIAIOSFODNN7EXAMPLE", "arn": - "arn:aws:iam::111111111111:role/aws-reserved/test/region/group", "accountId": "111111111111", - "userName": "test"}, "webIdFederationData": {}, "attributes": {"creationDate": "2021-08-11T09:42:53Z", - "mfaAuthenticated": "false"}}}, "eventTime": "2021-08-11T11:52:27Z", "eventSource": - "ecr.amazonaws.com", "eventName": "DescribeImageScanFindings", "awsRegion": "eu-central-1", - "sourceIPAddress": "154.16.165.133", "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.imageId.imageDigest + - requestParameters.maxResults + - requestParameters.repositoryName + - responseElements.imageId.imageDigest + - responseElements.imageScanFindings.findingSeverityCounts.HIGH + - responseElements.imageScanFindings.findingSeverityCounts.INFORMATIONAL + - responseElements.imageScanFindings.findingSeverityCounts.LOW + - responseElements.imageScanFindings.findingSeverityCounts.MEDIUM + - responseElements.imageScanFindings.findingSeverityCounts.UNDEFINED + - responseElements.imageScanFindings.findings{}.attributes{}.key + - responseElements.imageScanFindings.findings{}.attributes{}.value + - responseElements.imageScanFindings.findings{}.description + - responseElements.imageScanFindings.findings{}.name + - responseElements.imageScanFindings.findings{}.severity + - responseElements.imageScanFindings.findings{}.uri + - responseElements.imageScanFindings.imageScanCompletedAt + - responseElements.imageScanFindings.vulnerabilitySourceUpdatedAt + - responseElements.imageScanStatus.description + - responseElements.imageScanStatus.status + - responseElements.registryId + - responseElements.repositoryName + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region +example_log: "{\"eventVersion\": \"1.08\", \"userIdentity\": {\"type\": \"AssumedRole\"\ + , \"principalId\": \"AAAAAAAAAAAAAAAAAAAAA:test@test.com\", \"arn\": \"arn:aws:sts::111111111111:assumed-role/role_name/test@test.com\"\ + , \"accountId\": \"111111111111\", \"accessKeyId\": \"AKIAIOSFODNN7EXAMPLE\", \"\ + sessionContext\": {\"sessionIssuer\": {\"type\": \"Role\", \"principalId\": \"AKIAIOSFODNN7EXAMPLE\"\ + , \"arn\": \"arn:aws:iam::111111111111:role/aws-reserved/test/region/group\", \"\ + accountId\": \"111111111111\", \"userName\": \"test\"}, \"webIdFederationData\" + : {}, \"attributes\": {\"creationDate\": \"2021-08-11T09:42:53Z\", \"mfaAuthenticated\"\ + : \"false\"}}}, \"eventTime\": \"2021-08-11T11:52:27Z\", \"eventSource\": \"ecr.amazonaws.com\"\ + , \"eventName\": \"DescribeImageScanFindings\", \"awsRegion\": \"eu-central-1\" + , \"sourceIPAddress\": \"154.16.165.133\", \"userAgent\": \"aws-internal/3 aws-sdk-java/1.11.1030 Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08 - java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy", "requestParameters": - {"repositoryName": "devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"}, - "maxResults": 1000}, "responseElements": {"registryId": "111111111111", "repositoryName": - "devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"}, - "imageScanStatus": {"status": "COMPLETE", "description": "The scan was completed - successfully."}, "imageScanFindings": {"imageScanCompletedAt": "Aug 11, 2021, 11:30:16 - AM", "vulnerabilitySourceUpdatedAt": "Aug 11, 2021, 1:17:52 AM", "findings": [{"name": - "CVE-2019-25013", "description": "The iconv feature in the GNU C Library (aka glibc - or libc6) through 2.32, when processing invalid multi-byte input sequences in the - EUC-KR encoding, may have a buffer over-read.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-25013", - "severity": "HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"}, - {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"}, - {"key": "CVSS2_SCORE", "value": "7.1"}]}, {"name": "CVE-2021-33574", "description": - "The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 - has a use-after-free. It may use the notification thread attributes object (passed - through its struct sigevent parameter) after it has been freed by the caller, leading - to a denial of service (application crash) or possibly unspecified other impact.", - "uri": "https://security-tracker.debian.org/tracker/CVE-2021-33574", "severity": - "HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name", - "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-12886", "description": - "stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c - in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate - instruction sequences when targeting ARM targets that spill the address of the stack - protector guard, which allows an attacker to bypass the protection of -fstack-protector, - -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit - against stack overflow by controlling what the stack canary is compared against.", - "uri": "https://security-tracker.debian.org/tracker/CVE-2018-12886", "severity": - "MEDIUM", "attributes": [{"key": "package_version", "value": "8.3.0-6"}, {"key": - "package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-1751", "description": - "An out-of-bounds write vulnerability was found in glibc before 2.31 when handling - signal trampolines on PowerPC. Specifically, the backtrace function did not properly - check the array bounds when storing the frame address, resulting in a denial of - service or potential code execution. The highest threat from this vulnerability - is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1751", - "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"}, - {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:C"}, - {"key": "CVSS2_SCORE", "value": "5.9"}]}, {"name": "CVE-2021-3326", "description": - "The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, - when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an - assertion in the code path and aborts the program, potentially resulting in a denial - of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3326", - "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"}, - {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-35942", "description": - "The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or - read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, - crafted pattern, potentially resulting in a denial of service or disclosure of information. - This occurs because atoi was used but strtoul should have been used to ensure correct - calculations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-35942", - "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"}, - {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "6.4"}]}, {"name": "CVE-2019-12904", "description": - "In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload - side-channel attack because physical addresses are available to other processes. - (The C implementation is used on platforms where an assembly-language implementation - is unavailable.)", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12904", - "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"}, - {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value": - "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": - "CVE-2017-6363", "description": "** DISPUTED ** In the GD Graphics Library (aka - LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. - NOTE: the vendor says \"In my opinion this issue should not have a CVE, since the - GD and GD2 formats are documented to be ''obsolete, and should only be used for - development and testing purposes.''\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-6363", - "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"}, - {"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-12290", "description": - "GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 - Section 4.2 when converting A-labels to U-labels. This makes it possible in some - circumstances for one domain to impersonate another. By creating a malicious domain - that matches a target domain except for the inclusion of certain punycoded Unicode - characters (that would be discarded when converted first to a Unicode label and - then back to an ASCII label), arbitrary domains can be impersonated.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12290", - "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.0.5-1+deb10u1"}, - {"key": "package_name", "value": "libidn2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, - {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13115", "description": - "In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange + java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy\", \"requestParameters\"\ + : {\"repositoryName\": \"devsecops/cat_dog_client\", \"imageId\": {\"imageDigest\"\ + : \"sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6\"}, + \"maxResults\": 1000}, \"responseElements\": {\"registryId\": \"111111111111\", + \"repositoryName\": \"devsecops/cat_dog_client\", \"imageId\": {\"imageDigest\" + : \"sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6\"}, + \"imageScanStatus\": {\"status\": \"COMPLETE\", \"description\": \"The scan was + completed successfully.\"}, \"imageScanFindings\": {\"imageScanCompletedAt\": \"\ + Aug 11, 2021, 11:30:16 AM\", \"vulnerabilitySourceUpdatedAt\": \"Aug 11, 2021, 1:17:52 + AM\", \"findings\": [{\"name\": \"CVE-2019-25013\", \"description\": \"The iconv + feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing + invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-25013\", \"severity\"\ + : \"HIGH\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\ + }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ + , \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:C\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ + : \"7.1\"}]}, {\"name\": \"CVE-2021-33574\", \"description\": \"The mq_notify function + in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It + may use the notification thread attributes object (passed through its struct sigevent + parameter) after it has been freed by the caller, leading to a denial of service + (application crash) or possibly unspecified other impact.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-33574\"\ + , \"severity\": \"HIGH\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-12886\", \"description\": \"stack_protect_prologue + in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection + (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences + when targeting ARM targets that spill the address of the stack protector guard, + which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, + -fstack-protector-strong, and -fstack-protector-explicit against stack overflow + by controlling what the stack canary is compared against.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-12886\"\ + , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"8.3.0-6\"}, {\"key\": \"package_name\", \"value\": \"gcc-8\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-1751\", \"description\": \"An out-of-bounds + write vulnerability was found in glibc before 2.31 when handling signal trampolines + on PowerPC. Specifically, the backtrace function did not properly check the array + bounds when storing the frame address, resulting in a denial of service or potential + code execution. The highest threat from this vulnerability is to system availability.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-1751\", \"severity\"\ + : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\ + }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ + , \"value\": \"AV:L/AC:M/Au:N/C:P/I:P/A:C\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ + : \"5.9\"}]}, {\"name\": \"CVE-2021-3326\", \"description\": \"The iconv function + in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid + input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path + and aborts the program, potentially resulting in a denial of service.\", \"uri\"\ + : \"https://security-tracker.debian.org/tracker/CVE-2021-3326\", \"severity\": \"\ + MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\ + }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ + , \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ + : \"5\"}]}, {\"name\": \"CVE-2021-35942\", \"description\": \"The wordexp function + in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory + in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, + potentially resulting in a denial of service or disclosure of information. This + occurs because atoi was used but strtoul should have been used to ensure correct + calculations.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-35942\"\ + , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"6.4\"}]}, {\"name\": \"CVE-2019-12904\", \"description\": \"In Libgcrypt + 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel + attack because physical addresses are available to other processes. (The C implementation + is used on platforms where an assembly-language implementation is unavailable.)\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-12904\", \"severity\"\ + : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.4-5+deb10u1\"\ + }, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"}, {\"key\": \"CVSS2_VECTOR\"\ + , \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ + : \"4.3\"}]}, {\"name\": \"CVE-2017-6363\", \"description\": \"** DISPUTED ** In + the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer + over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says \\\"In my opinion this + issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, + and should only be used for development and testing purposes.'\\\"\", \"uri\": \"\ + https://security-tracker.debian.org/tracker/CVE-2017-6363\", \"severity\": \"MEDIUM\"\ + , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"}, {\"\ + key\": \"package_name\", \"value\": \"libgd2\"}, {\"key\": \"CVSS2_VECTOR\", \"\ + value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\": + \"5.8\"}]}, {\"name\": \"CVE-2019-12290\", \"description\": \"GNU libidn2 before + 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when + converting A-labels to U-labels. This makes it possible in some circumstances for + one domain to impersonate another. By creating a malicious domain that matches a + target domain except for the inclusion of certain punycoded Unicode characters (that + would be discarded when converted first to a Unicode label and then back to an ASCII + label), arbitrary domains can be impersonated.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-12290\"\ + , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.0.5-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libidn2\"}, {\"\ + key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"\ + CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-13115\", \"description\"\ + : \"In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server. This is related to an _libssh2_check_length - mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.", - "uri": "https://security-tracker.debian.org/tracker/CVE-2019-13115", "severity": - "MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"}, {"key": - "package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2016-9318", "description": - "libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, - does not offer a flag directly indicating that the current document may be read - but other files may not be opened, which makes it easier for remote attackers to - conduct XML External Entity (XXE) attacks via a crafted document.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9318", - "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"}, - {"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, - {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2017-16932", "description": - "parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter - entities.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16932", - "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"}, - {"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-36309", "description": - "ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe - characters in an argument when using the API to mutate a URI, or a request or response - header.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-36309", "severity": - "MEDIUM", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"}, - {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, - {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-14155", "description": - "libpcre in PCRE before 8.44 allows an integer overflow via a large number after - a (?C substring.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-14155", - "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2:8.39-12"}, - {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-3843", "description": - "It was discovered that a systemd service that uses DynamicUser property can create - a SUID/SGID binary that would be allowed to run as the transient service UID/GID - even after the service is terminated. A local attacker may use this flaw to access - resources that will be owned by a potentially different service in the future, when - the UID/GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3843", - "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"}, - {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2019-3844", "description": - "It was discovered that a systemd service that uses DynamicUser property can get - new privileges through the execution of SUID binaries, which would allow to create - binaries owned by the service transient group with the setgid bit set. A local attacker - may use this flaw to access resources that will be owned by a potentially different - service in the future, when the GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3844", - "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"}, - {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2016-2781", "description": - "chroot in GNU coreutils, when used with --userspec, allows local users to escape - to the parent session via a crafted TIOCSTI ioctl call, which pushes characters - to the terminal''s input buffer.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-2781", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "8.30-3"}, - {"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR", "value": - "AV:L/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": - "CVE-2021-22898", "description": "curl 7.7 through 7.76.1 suffers from an information - disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in - libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw - in the option parser for sending NEW_ENV variables, libcurl could be made to pass - on uninitialized data from a stack based buffer to the server, resulting in potentially - revealing sensitive internal information to the server using a clear-text network - protocol.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22898", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"}, - {"key": "package_name", "value": "curl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:N/A:N"}, - {"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name": "CVE-2019-15847", "description": - "The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize - multiple calls of the __builtin_darn intrinsic into a single call, thus reducing - the entropy of the random number generator. This occurred because a volatile operation - was not specified. For example, within a single execution of a program, the output - of every __builtin_darn() call may be the same.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-15847", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "8.3.0-6"}, - {"key": "package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, - {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-1752", "description": - "A use-after-free vulnerability introduced in glibc upstream version 2.14 was found - in the way the tilde expansion was carried out. Directory paths containing an initial - tilde followed by a valid username were affected by this issue. A local attacker - could exploit this flaw by creating a specially crafted path that, when processed - by the glob function, would potentially lead to arbitrary code execution. This was - fixed in version 2.32.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1752", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, - {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:H/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "3.7"}]}, {"name": "CVE-2020-6096", "description": - "An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation - of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU - glibc implementation) with a negative value for the ''num'' parameter results in - a signed comparison vulnerability. If an attacker underflows the ''num'' parameter - to memcpy(), this vulnerability could lead to undefined behavior such as writing - to out-of-bounds memory and potentially remote code execution. Furthermore, this - memcpy() implementation allows for program execution to continue in scenarios where - a segmentation fault or crash should have occurred. The dangers occur in that subsequent - execution and iterations of this code will be executed with this corrupted data.", - "uri": "https://security-tracker.debian.org/tracker/CVE-2020-6096", "severity": - "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name", - "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-10029", "description": - "The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer - during range reduction if an input to an 80-bit long double function contains a - non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to - sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.", - "uri": "https://security-tracker.debian.org/tracker/CVE-2020-10029", "severity": - "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name", - "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2020-27618", "description": - "The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, - when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, - IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead - to an infinite loop in applications, resulting in a denial of service, a different - vulnerability from CVE-2016-10228.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-27618", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, - {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2016-10228", "description": - "The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when - invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) - along with the -c option, enters an infinite loop when processing invalid multi-byte - input sequences, leading to a denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-10228", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, - {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-19126", "description": - "On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to - ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution - after a security transition, allowing local attackers to restrict the possible mapping - addresses for loaded libraries and thus bypass ASLR for a setuid program.", "uri": - "https://security-tracker.debian.org/tracker/CVE-2019-19126", "severity": "LOW", - "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name", - "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:N/A:N"}, - {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-27645", "description": - "The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) - 2.29 through 2.33, when processing a request for netgroup lookup, may crash due - to a double-free, potentially resulting in degraded service or Denial of Service - on the local system. This is related to netgroupcache.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-27645", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, - {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2019-14855", "description": - "A flaw was found in the way certificate signatures could be forged using collisions - found in the SHA-1 algorithm. An attacker could use this weakness to create forged - certificate signatures. This issue affects GnuPG versions before 2.2.18.", "uri": - "https://security-tracker.debian.org/tracker/CVE-2019-14855", "severity": "LOW", - "attributes": [{"key": "package_version", "value": "2.2.12-1+deb10u1"}, {"key": - "package_name", "value": "gnupg2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, - {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13627", "description": - "It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic + mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-13115\", \"severity\"\ + : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.0-2.1\"\ + }, {\"key\": \"package_name\", \"value\": \"libssh2\"}, {\"key\": \"CVSS2_VECTOR\"\ + , \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ + : \"5.8\"}]}, {\"name\": \"CVE-2016-9318\", \"description\": \"libxml2 2.9.4 and + earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer + a flag directly indicating that the current document may be read but other files + may not be opened, which makes it easier for remote attackers to conduct XML External + Entity (XXE) attacks via a crafted document.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-9318\"\ + , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.9.4+dfsg1-7+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"libxml2\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-16932\", \"description\"\ + : \"parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter + entities.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16932\"\ + , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.9.4+dfsg1-7+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"libxml2\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2020-36309\", \"description\"\ + : \"ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows + unsafe characters in an argument when using the API to mutate a URI, or a request + or response header.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-36309\"\ + , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"}, {\"key\"\ + : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"5\"}]}, {\"name\": \"CVE-2020-14155\", \"description\": \"libpcre + in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-14155\", \"severity\"\ + : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2:8.39-12\"\ + }, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"CVSS2_VECTOR\"\ + , \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ + : \"5\"}]}, {\"name\": \"CVE-2019-3843\", \"description\": \"It was discovered that + a systemd service that uses DynamicUser property can create a SUID/SGID binary that + would be allowed to run as the transient service UID/GID even after the service + is terminated. A local attacker may use this flaw to access resources that will + be owned by a potentially different service in the future, when the UID/GID will + be recycled.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-3843\"\ + , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\ + : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"4.6\"}]}, {\"name\": \"CVE-2019-3844\", \"description\": \"It was + discovered that a systemd service that uses DynamicUser property can get new privileges + through the execution of SUID binaries, which would allow to create binaries owned + by the service transient group with the setgid bit set. A local attacker may use + this flaw to access resources that will be owned by a potentially different service + in the future, when the GID will be recycled.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-3844\"\ + , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\ + : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"4.6\"}]}, {\"name\": \"CVE-2016-2781\", \"description\": \"chroot + in GNU coreutils, when used with --userspec, allows local users to escape to the + parent session via a crafted TIOCSTI ioctl call, which pushes characters to the + terminal's input buffer.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-2781\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"8.30-3\"}, {\"key\": \"package_name\", \"value\": \"coreutils\"}, {\"key\": + \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-22898\", \"description\": \"curl + 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command + line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content + pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV + variables, libcurl could be made to pass on uninitialized data from a stack based + buffer to the server, resulting in potentially revealing sensitive internal information + to the server using a clear-text network protocol.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22898\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"}, {\"key\"\ + : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:H/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"2.6\"}]}, {\"name\": \"CVE-2019-15847\", \"description\": \"The POWER9 + backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple + calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy + of the random number generator. This occurred because a volatile operation was not + specified. For example, within a single execution of a program, the output of every + __builtin_darn() call may be the same.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-15847\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"8.3.0-6\"}, {\"key\": \"package_name\", \"value\": \"gcc-8\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"5\"}]}, {\"name\": \"CVE-2020-1752\", \"description\": \"A use-after-free + vulnerability introduced in glibc upstream version 2.14 was found in the way the + tilde expansion was carried out. Directory paths containing an initial tilde followed + by a valid username were affected by this issue. A local attacker could exploit + this flaw by creating a specially crafted path that, when processed by the glob + function, would potentially lead to arbitrary code execution. This was fixed in + version 2.32.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-1752\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"3.7\"}]}, {\"name\": \"CVE-2020-6096\", \"description\": \"An exploitable + signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU + glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) + with a negative value for the 'num' parameter results in a signed comparison vulnerability. + If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could + lead to undefined behavior such as writing to out-of-bounds memory and potentially + remote code execution. Furthermore, this memcpy() implementation allows for program + execution to continue in scenarios where a segmentation fault or crash should have + occurred. The dangers occur in that subsequent execution and iterations of this + code will be executed with this corrupted data.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-6096\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-10029\", \"description\": \"The GNU + C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during + range reduction if an input to an 80-bit long double function contains a non-canonical + bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. + This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-10029\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2020-27618\", \"description\": \"The iconv + function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing + invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 + encodings, fails to advance the input state, which could lead to an infinite loop + in applications, resulting in a denial of service, a different vulnerability from + CVE-2016-10228.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-27618\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2016-10228\", \"description\": \"The iconv + program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked + with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with + the -c option, enters an infinite loop when processing invalid multi-byte input + sequences, leading to a denial of service.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-10228\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2019-19126\", \"description\": \"On the + x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the + LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security + transition, allowing local attackers to restrict the possible mapping addresses + for loaded libraries and thus bypass ASLR for a setuid program.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-19126\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-27645\", \"description\": \"The nameserver + caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, + when processing a request for netgroup lookup, may crash due to a double-free, potentially + resulting in degraded service or Denial of Service on the local system. This is + related to netgroupcache.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-27645\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"1.9\"}]}, {\"name\": \"CVE-2019-14855\", \"description\": \"A flaw + was found in the way certificate signatures could be forged using collisions found + in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate + signatures. This issue affects GnuPG versions before 2.2.18.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-14855\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.2.12-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"gnupg2\"}, {\"\ + key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"\ + CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-13627\", \"description\"\ + : \"It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions - fixed: 1.8.5-2 and 1.6.3-2+deb8u7.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-13627", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"}, - {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value": - "AV:L/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name": - "CVE-2018-14553", "description": "gdImageClone in gd.c in libgd 2.1.0-rc2 through - 2.2.5 has a NULL pointer dereference allowing attackers to crash an application - via a specific function call sequence. Only affects PHP when linked with an external - libgd (not bundled).", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14553", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"}, - {"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-36086", "description": - "The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission - (called from cil_reset_classperms_set and cil_reset_classperms_list).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36086", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"}, - {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36085", "description": - "The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms - (called from __verify_map_perm_classperms and hashtab_map).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36085", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"}, - {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36087", "description": - "The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any - (called indirectly from cil_check_neverallow). This occurs because there is sometimes - a lack of checks for invalid statements in an optional block.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36087", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"}, - {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36084", "description": - "The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms - (called from __cil_verify_classpermission and __cil_pre_verify_helper).", "uri": - "https://security-tracker.debian.org/tracker/CVE-2021-36084", "severity": "LOW", - "attributes": [{"key": "package_version", "value": "2.8-1"}, {"key": "package_name", - "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2019-17498", "description": - "In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c - has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary - (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be - able to disclose sensitive information or cause a denial of service condition on - the client system when a user connects to the server.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17498", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"}, - {"key": "package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-17543", "description": - "LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), + fixed: 1.8.5-2 and 1.6.3-2+deb8u7.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-13627\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"1.8.4-5+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"}, + {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:P/I:P/A:N\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"2.6\"}]}, {\"name\": \"CVE-2018-14553\", \"description\"\ + : \"gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference + allowing attackers to crash an application via a specific function call sequence. + Only affects PHP when linked with an external libgd (not bundled).\", \"uri\": \"\ + https://security-tracker.debian.org/tracker/CVE-2018-14553\", \"severity\": \"LOW\"\ + , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"}, {\"\ + key\": \"package_name\", \"value\": \"libgd2\"}, {\"key\": \"CVSS2_VECTOR\", \"\ + value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\": + \"5\"}]}, {\"name\": \"CVE-2021-36086\", \"description\": \"The CIL compiler in + SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set + and cil_reset_classperms_list).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36086\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36085\", \"description\": \"The CIL + compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called + from __verify_map_perm_classperms and hashtab_map).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36085\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36087\", \"description\": \"The CIL + compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called + indirectly from cil_check_neverallow). This occurs because there is sometimes a + lack of checks for invalid statements in an optional block.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36087\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36084\", \"description\": \"The CIL + compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called + from __cil_verify_classpermission and __cil_pre_verify_helper).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36084\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2019-17498\", \"description\": \"In libssh2 + v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer + overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) + offset for a subsequent memory read. A crafted SSH server may be able to disclose + sensitive information or cause a denial of service condition on the client system + when a user connects to the server.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-17498\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"1.8.0-2.1\"}, {\"key\": \"package_name\", \"value\": \"libssh2\"}, {\"key\" + : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"5.8\"}]}, {\"name\": \"CVE-2019-17543\", \"description\": \"LZ4 before + 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue - can also lead to data corruption.) NOTE: the vendor states \"only a few specific - / uncommon usages of the API are at risk.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17543", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.3-1+deb10u1"}, - {"key": "package_name", "value": "lz4"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2013-0337", "description": - "The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable - permissions for the (1) access.log and (2) error.log files, which allows local users - to obtain sensitive information by reading the files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0337", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"}, - {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-7169", "description": - "An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and - allows an unprivileged user to be placed in a user namespace where setgroups(2) - is permitted. This allows an attacker to remove themselves from a supplementary - group, which may allow access to certain filesystem paths if the administrator has - used \"group blacklisting\" (e.g., chmod g-rwx) to restrict access to paths. This - flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups - knob) to prevent this sort of privilege escalation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-7169", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "1:4.5-1.1"}, - {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, - {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-37600", "description": - "An integer overflow in util-linux through 2.37.1 can potentially cause a buffer - overflow if an attacker were able to use system resources in a way that leads to - a large number in the /proc/sysvipc/sem file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-37600", - "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.33.1-0.1"}, - {"key": "package_name", "value": "util-linux"}, {"key": "CVSS2_VECTOR", "value": - "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": - "CVE-2011-3374", "description": "It was found that apt-key in apt, all versions, - do not correctly validate gpg keys with the master keyring, leading to a potential - man-in-the-middle attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3374", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1.8.2.3"}, {"key": "package_name", "value": "apt"}, {"key": "CVSS2_VECTOR", "value": - "AV:N/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": - "CVE-2019-18276", "description": "An issue was discovered in disable_priv_mode in - shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective - UID not equal to its real UID, it will drop privileges by setting its effective - UID to its real UID. However, it does so incorrectly. On Linux and other systems - that support \"saved UID\" functionality, the saved UID is not dropped. An attacker - with command execution in the shell can use \"enable -f\" for runtime loading of - a new builtin, which can be a shared object that calls setuid() and therefore regains - privileges. However, binaries running with an effective UID of 0 are unaffected.", - "uri": "https://security-tracker.debian.org/tracker/CVE-2019-18276", "severity": - "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "5.0-4"}, {"key": - "package_name", "value": "bash"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:C/I:C/A:C"}, - {"key": "CVSS2_SCORE", "value": "7.2"}]}, {"name": "CVE-2017-18018", "description": - "In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent - replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options, - which allows local users to modify the ownership of arbitrary files by leveraging - a race condition.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-18018", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "8.30-3"}, {"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR", - "value": "AV:L/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "1.9"}]}, - {"name": "CVE-2021-22923", "description": "When curl is instructed to get content - using the metalink feature, and a user name and password are used to download the - metalink XML file, those same credentials are then subsequently passed on to each - of the servers from which curl will download or try to download the contents from. - Often contrary to the user''s expectations and intentions and without telling the - user it happened.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22923", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-22922", - "description": "When curl is instructed to download content using the metalink feature, - thecontents is verified against a hash provided in the metalink XML file.The metalink - XML file points out to the client how to get the same contentfrom a set of different - URLs, potentially hosted by different servers and theclient can then download the - file from one or several of them. In a serial orparallel manner.If one of the servers - hosting the contents has been breached and the contentsof the specific file on that - server is replaced with a modified payload, curlshould detect this when the hash - of the file mismatches after a completeddownload. It should remove the contents - and instead try getting the contentsfrom another URL. This is not done, and instead - such a hash mismatch is onlymentioned in text and the potentially malicious content - is kept in the file ondisk.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22922", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2013-0340", - "description": "expat 2.1.0 and earlier does not properly handle entities expansion - unless an application developer uses the XML_SetEntityDeclHandler function, which - allows remote attackers to cause a denial of service (resource consumption), send - HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, - aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat - already provides the ability to disable external entity expansion, the responsibility - for resolving this issue lies with application developers; according to this argument, - this entry should be REJECTed, and each affected application would need its own - CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0340", "severity": - "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.2.6-2+deb10u1"}, - {"key": "package_name", "value": "expat"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-1010023", "description": - "** DISPUTED ** GNU Libc current is affected by: Re-mapping current loaded library + can also lead to data corruption.) NOTE: the vendor states \\\"only a few specific + / uncommon usages of the API are at risk.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-17543\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"1.8.3-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"lz4\"}, {\"key\"\ + : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2013-0337\", \"description\": \"The default + configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions + for the (1) access.log and (2) error.log files, which allows local users to obtain + sensitive information by reading the files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-0337\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"}, {\"key\"\ + : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-7169\", \"description\": \"An issue + was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an + unprivileged user to be placed in a user namespace where setgroups(2) is permitted. + This allows an attacker to remove themselves from a supplementary group, which may + allow access to certain filesystem paths if the administrator has used \\\"group + blacklisting\\\" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively + reverts a security feature in the kernel (in particular, the /proc/self/setgroups + knob) to prevent this sort of privilege escalation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-7169\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\": + \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"5\"}]}, {\"name\": \"CVE-2021-37600\", \"description\": \"An integer + overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if + an attacker were able to use system resources in a way that leads to a large number + in the /proc/sysvipc/sem file.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-37600\"\ + , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ + : \"2.33.1-0.1\"}, {\"key\": \"package_name\", \"value\": \"util-linux\"}, {\"key\"\ + : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2011-3374\", \"description\": \"It was + found that apt-key in apt, all versions, do not correctly validate gpg keys with + the master keyring, leading to a potential man-in-the-middle attack.\", \"uri\" + : \"https://security-tracker.debian.org/tracker/CVE-2011-3374\", \"severity\": \"\ + INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.2.3\"\ + }, {\"key\": \"package_name\", \"value\": \"apt\"}, {\"key\": \"CVSS2_VECTOR\", + \"value\": \"AV:N/AC:M/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ + : \"4.3\"}]}, {\"name\": \"CVE-2019-18276\", \"description\": \"An issue was discovered + in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if + Bash is run with its effective UID not equal to its real UID, it will drop privileges + by setting its effective UID to its real UID. However, it does so incorrectly. On + Linux and other systems that support \\\"saved UID\\\" functionality, the saved + UID is not dropped. An attacker with command execution in the shell can use \\\"\ + enable -f\\\" for runtime loading of a new builtin, which can be a shared object + that calls setuid() and therefore regains privileges. However, binaries running + with an effective UID of 0 are unaffected.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-18276\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"5.0-4\"}, {\"key\": \"package_name\", \"value\": \"bash\"}, {\"key\"\ + : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"7.2\"}]}, {\"name\": \"CVE-2017-18018\", \"description\": \"In GNU + Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement + of a plain file with a symlink during use of the POSIX \\\"-R -L\\\" options, which + allows local users to modify the ownership of arbitrary files by leveraging a race + condition.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-18018\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"8.30-3\"}, {\"key\": \"package_name\", \"value\": \"coreutils\"}, + {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:P/A:N\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"1.9\"}]}, {\"name\": \"CVE-2021-22923\", \"description\"\ + : \"When curl is instructed to get content using the metalink feature, and a user + name and password are used to download the metalink XML file, those same credentials + are then subsequently passed on to each of the servers from which curl will download + or try to download the contents from. Often contrary to the user's expectations + and intentions and without telling the user it happened.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22923\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"\ + }]}, {\"name\": \"CVE-2021-22922\", \"description\": \"When curl is instructed to + download content using the metalink feature, thecontents is verified against a hash + provided in the metalink XML file.The metalink XML file points out to the client + how to get the same contentfrom a set of different URLs, potentially hosted by different + servers and theclient can then download the file from one or several of them. In + a serial orparallel manner.If one of the servers hosting the contents has been breached + and the contentsof the specific file on that server is replaced with a modified + payload, curlshould detect this when the hash of the file mismatches after a completeddownload. + It should remove the contents and instead try getting the contentsfrom another URL. + This is not done, and instead such a hash mismatch is onlymentioned in text and + the potentially malicious content is kept in the file ondisk.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22922\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"\ + }]}, {\"name\": \"CVE-2013-0340\", \"description\": \"expat 2.1.0 and earlier does + not properly handle entities expansion unless an application developer uses the + XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial + of service (resource consumption), send HTTP requests to intranet servers, or read + arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue.\ + \ NOTE: it could be argued that because expat already provides the ability to disable + external entity expansion, the responsibility for resolving this issue lies with + application developers; according to this argument, this entry should be REJECTed, + and each affected application would need its own CVE.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-0340\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2.2.6-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"expat\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-1010023\", \"description\"\ + : \"** DISPUTED ** GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim - and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this - is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010023", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": - "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": - "CVE-2010-4051", "description": "The regcomp implementation in the GNU C Library - (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent - attackers to cause a denial of service (application crash) via a regular expression - containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, - as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit - for ProFTPD, related to a \"RE_DUP_MAX overflow.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4051", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": - "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": - "CVE-2019-1010022", "description": "** DISPUTED ** GNU Libc current is affected - by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. - The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability - and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments - indicate \"this is being treated as a non-security bug and no real threat.\"", "uri": - "https://security-tracker.debian.org/tracker/CVE-2019-1010022", "severity": "INFORMATIONAL", - "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name", - "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2010-4052", "description": - "Stack consumption vulnerability in the regcomp implementation in the GNU C Library + and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \\\ + \"this is being treated as a non-security bug and no real threat.\\\"\", \"uri\"\ + : \"https://security-tracker.debian.org/tracker/CVE-2019-1010023\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ + , \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ + : \"6.8\"}]}, {\"name\": \"CVE-2010-4051\", \"description\": \"The regcomp implementation + in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, + allows context-dependent attackers to cause a denial of service (application crash) + via a regular expression containing adjacent bounded repetitions that bypass the + intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence + in the proftpd.gnu.c exploit for ProFTPD, related to a \\\"RE_DUP_MAX overflow.\\\ + \"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4051\", \"\ + severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"\ + value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\"\ + : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"5\"}]}, {\"name\": \"CVE-2019-1010022\", \"description\": \"** DISPUTED + ** GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may + bypass stack guard protection. The component is: nptl. The attack vector is: Exploit + stack buffer overflow vulnerability and use this bypass vulnerability to bypass + stack guard. NOTE: Upstream comments indicate \\\"this is being treated as a non-security + bug and no real threat.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-1010022\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\ + key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"\ + CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2010-4052\", \"description\"\ + : \"Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} - sequence in the proftpd.gnu.c exploit for ProFTPD.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4052", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": - "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": - "CVE-2019-1010024", "description": "** DISPUTED ** GNU Libc current is affected - by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread - stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this - is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010024", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": - "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": - "CVE-2010-4756", "description": "The glob implementation in the GNU C Library (aka - glibc or libc6) allows remote authenticated users to cause a denial of service (CPU - and memory consumption) via crafted glob expressions that do not match any pathnames, - as demonstrated by glob expressions in STAT commands to an FTP daemon, a different - vulnerability than CVE-2010-2632.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4756", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": - "AV:N/AC:L/Au:S/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4"}]}, {"name": - "CVE-2019-1010025", "description": "** DISPUTED ** GNU Libc current is affected - by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created - thread. The component is: glibc. NOTE: the vendor''s position is \"ASLR bypass itself - is not a vulnerability.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010025", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": - "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": - "CVE-2018-20796", "description": "In the GNU C Library (aka glibc or libc6) through - 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, - as demonstrated by ''(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+'' in grep.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-20796", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": - "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": - "CVE-2019-9192", "description": "** DISPUTED ** In the GNU C Library (aka glibc - or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled - Recursion, as demonstrated by ''(|)(\\\\1\\\\1)*'' in grep, a different issue than - CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability - because the behavior occurs only with a crafted pattern.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9192", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": - "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": - "CVE-2011-3389", "description": "The SSL protocol, as used in certain configurations - in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, - Opera, and other products, encrypts data by using CBC mode with chained initialization - vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers - via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction - with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection - API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3389", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "3.6.7-4+deb10u7"}, {"key": "package_name", "value": "gnutls28"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, - {"name": "CVE-2021-30535", "description": "Double free in ICU in Google Chrome prior - to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption - via a crafted HTML page.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-30535", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "63.1-6+deb10u1"}, {"key": "package_name", "value": "icu"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, - {"name": "CVE-2017-9937", "description": "In LibTIFF 4.0.8, there is a memory malloc - failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in - a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-9937", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.1-3.1"}, {"key": "package_name", "value": "jbigkit"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, - {"name": "CVE-2018-5709", "description": "An issue was discovered in MIT Kerberos - 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c - that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable - to it, which is for 32-bit data. An attacker can use this vulnerability to affect - other artifacts of the database as we know that a Kerberos database dump file contains - trusted data.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-5709", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, - {"name": "CVE-2021-36222", "description": "ec_verify in kdc/kdc_preauth_ec.c in - the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and - 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference - and daemon crash. This occurs because a return value is not properly managed in - a certain situation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36222", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, - {"name": "CVE-2004-0971", "description": "The krb5-send-pr script in the kerberos5 - (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating - systems, allows local users to overwrite files via a symlink attack on temporary - files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2004-0971", "severity": - "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.17-3+deb10u1"}, - {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:P/A:N"}, - {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2018-6829", "description": - "cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, + sequence in the proftpd.gnu.c exploit for ProFTPD.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4052\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\ + key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\ + CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-1010024\", \"description\"\ + : \"** DISPUTED ** GNU Libc current is affected by: Mitigation bypass. The impact + is: Attacker may bypass ASLR using cache of thread stack and heap. The component + is: glibc. NOTE: Upstream comments indicate \\\"this is being treated as a non-security + bug and no real threat.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-1010024\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\ + key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"\ + CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2010-4756\", \"description\"\ + : \"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote + authenticated users to cause a denial of service (CPU and memory consumption) via + crafted glob expressions that do not match any pathnames, as demonstrated by glob + expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4756\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ + , \"value\": \"AV:N/AC:L/Au:S/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ + : \"4\"}]}, {\"name\": \"CVE-2019-1010025\", \"description\": \"** DISPUTED ** GNU + Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess + the heap addresses of pthread_created thread. The component is: glibc. NOTE: the + vendor's position is \\\"ASLR bypass itself is not a vulnerability.\\\"\", \"uri\"\ + : \"https://security-tracker.debian.org/tracker/CVE-2019-1010025\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ + , \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ + : \"5\"}]}, {\"name\": \"CVE-2018-20796\", \"description\": \"In the GNU C Library + (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c + has Uncontrolled Recursion, as demonstrated by '(\\\\227|)(\\\\\\\\1\\\\\\\\1|t1|\\\ + \\\\\\\\\\2537)+' in grep.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-20796\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\ + key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\ + CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-9192\", \"description\"\ + : \"** DISPUTED ** In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 + in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\\\\\\ + 1\\\\\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software + maintainer disputes that this is a vulnerability because the behavior occurs only + with a crafted pattern.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9192\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\ + key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\ + CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2011-3389\", \"description\"\ + : \"The SSL protocol, as used in certain configurations in Microsoft Windows and + Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, + encrypts data by using CBC mode with chained initialization vectors, which allows + man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary + attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses + (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight + WebClient API, aka a \\\"BEAST\\\" attack.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2011-3389\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"3.6.7-4+deb10u7\"}, {\"key\": \"package_name\", \"value\": \"gnutls28\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2021-30535\", \"description\"\ + : \"Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker + to potentially exploit heap corruption via a crafted HTML page.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-30535\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"63.1-6+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"icu\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2017-9937\", \"description\"\ + : \"In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted + TIFF document can lead to an abort resulting in a remote denial of service attack.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-9937\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"2.1-3.1\"}, {\"key\": \"package_name\", \"value\": \"jbigkit\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-5709\", \"description\": \"An issue + was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \\\ + \"dbentry->n_key_data\\\" in kadmin/dbutil/dump.c that can store 16-bit data but + unknowingly the developer has assigned a \\\"u4\\\" variable to it, which is for + 32-bit data. An attacker can use this vulnerability to affect other artifacts of + the database as we know that a Kerberos database dump file contains trusted data.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-5709\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"}, {\"key\" + : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"5\"}]}, {\"name\": \"CVE-2021-36222\", \"description\": \"ec_verify + in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka + krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a + NULL pointer dereference and daemon crash. This occurs because a return value is + not properly managed in a certain situation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36222\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2004-0971\", \"description\"\ + : \"The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux + 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite + files via a symlink attack on temporary files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2004-0971\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2018-6829\", \"description\"\ + : \"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not - hold for Libgcrypt''s ElGamal implementation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-6829", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1.8.4-5+deb10u1"}, {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, - {"name": "CVE-2018-11813", "description": "libjpeg 9c has a large loop because read_pixel - in rdtarga.c mishandles EOF.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-11813", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key": - "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": - "5"}]}, {"name": "CVE-2020-17541", "description": "Libjpeg-turbo all version have - a stack-based buffer overflow in the \"transform\" component. A remote attacker - can send a malformed jpeg file to the service and cause arbitrary code execution - or denial of service of the target service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-17541", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key": - "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": - "6.8"}]}, {"name": "CVE-2017-15232", "description": "libjpeg-turbo 1.5.2 has a NULL - Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.", "uri": - "https://security-tracker.debian.org/tracker/CVE-2017-15232", "severity": "INFORMATIONAL", - "attributes": [{"key": "package_version", "value": "1:1.5.2-2+deb10u1"}, {"key": - "package_name", "value": "libjpeg-turbo"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2018-14048", "description": - "An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data - in png.c, related to the recommended error handling for png_read_image.", "uri": - "https://security-tracker.debian.org/tracker/CVE-2018-14048", "severity": "INFORMATIONAL", - "attributes": [{"key": "package_version", "value": "1.6.36-6"}, {"key": "package_name", - "value": "libpng1.6"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-6129", "description": - "** DISPUTED ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, - as demonstrated by pngcp. NOTE: a third party has stated \"I don''t think it is - libpng''s job to free this buffer.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-6129", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, - {"name": "CVE-2018-14550", "description": "An issue has been found in third-party - PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow - in the function get_token in pnm2png.c in pnm2png.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14550", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, - {"name": "CVE-2019-9893", "description": "libseccomp before 2.4.0 did not correctly - generate 64-bit syscall argument comparisons using the arithmetic operators (LT, - GT, LE, GE), which might able to lead to bypassing seccomp filters and potential - privilege escalations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9893", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.3.3-4"}, {"key": "package_name", "value": "libseccomp"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]}, - {"name": "CVE-2018-1000654", "description": "GNU Libtasn1-4.13 libtasn1-4.13 version - libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% - when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), - after a long time, the program will be killed. This attack appears to be exploitable - via parsing a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-1000654", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "4.13-3"}, {"key": "package_name", "value": "libtasn1-6"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.1"}]}, - {"name": "CVE-2016-9085", "description": "Multiple integer overflows in libwebp - allows attackers to have unspecified impact via unknown vectors.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9085", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "0.6.1-2+deb10u1"}, {"key": "package_name", "value": "libwebp"}, {"key": "CVSS2_VECTOR", - "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, - {"name": "CVE-2015-9019", "description": "In libxslt 1.1.29 and earlier, the EXSLT - math.random function was not initialized with a random seed during startup, which - could cause usage of this function to produce predictable outputs.", "uri": "https://security-tracker.debian.org/tracker/CVE-2015-9019", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1.1.32-2.2~deb10u1"}, {"key": "package_name", "value": "libxslt"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, - {"name": "CVE-2009-4487", "description": "nginx 0.7.64 writes data to a log file - without sanitizing non-printable characters, which might allow remote attackers - to modify a window''s title, or possibly execute arbitrary commands or overwrite - files, via an HTTP request containing an escape sequence for a terminal emulator.", - "uri": "https://security-tracker.debian.org/tracker/CVE-2009-4487", "severity": - "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"}, - {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-15719", "description": - "libldap in certain third-party OpenLDAP packages has a certificate-validation flaw - when the third-party package is asserting RFC6125 support. It considers CN even - when there is a non-matching subjectAltName (SAN). This is fixed in, for example, - openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-15719", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key": - "CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": - "4"}]}, {"name": "CVE-2015-3276", "description": "The nss_parse_ciphers function - in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword - mode cipher strings, which might cause a weaker than intended cipher to be used - and allow remote attackers to have unspecified impact via unknown vectors.", "uri": - "https://security-tracker.debian.org/tracker/CVE-2015-3276", "severity": "INFORMATIONAL", - "attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"}, {"key": - "package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, - {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2017-14159", "description": - "slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges - to a non-root account, which might allow local users to kill arbitrary processes - by leveraging access to this non-root account for PID file modification before a - root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.", - "uri": "https://security-tracker.debian.org/tracker/CVE-2017-14159", "severity": - "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"}, - {"key": "package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2017-17740", "description": - "contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops - module and the memberof overlay are enabled, attempts to free a buffer that was - allocated on the stack, which allows remote attackers to cause a denial of service - (slapd crash) via a member MODDN operation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17740", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key": - "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": - "5"}]}, {"name": "CVE-2010-0928", "description": "OpenSSL 0.9.8i on the Gaisler - Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation - (FWE) algorithm for certain signature calculations, and does not verify the signature - before providing it to a caller, which makes it easier for physically proximate - attackers to determine the private key via a modified supply voltage for the microprocessor, - related to a \"fault-based attack.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-0928", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1.1.1d-0+deb10u6"}, {"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR", - "value": "AV:L/AC:H/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4"}]}, - {"name": "CVE-2007-6755", "description": "The NIST SP 800-90A default statement - of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm - contains point Q constants with a possible relationship to certain \"skeleton key\" - values, which might allow context-dependent attackers to defeat cryptographic protection - mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary - CVE for Dual_EC_DRBG; future research may provide additional details about point - Q and associated attacks, and could potentially lead to a RECAST or REJECT of this - CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-6755", "severity": - "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.1.1d-0+deb10u6"}, - {"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:N"}, - {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2017-7246", "description": - "Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c + hold for Libgcrypt's ElGamal implementation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-6829\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"1.8.4-5+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2018-11813\", \"description\"\ + : \"libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-11813\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2020-17541\", \"description\"\ + : \"Libjpeg-turbo all version have a stack-based buffer overflow in the \\\"transform\\\ + \" component. A remote attacker can send a malformed jpeg file to the service and + cause arbitrary code execution or denial of service of the target service.\", \"\ + uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-17541\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2017-15232\", \"description\"\ + : \"libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c + via a crafted JPEG file.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-15232\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-14048\", \"description\"\ + : \"An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data + in png.c, related to the recommended error handling for png_read_image.\", \"uri\"\ + : \"https://security-tracker.debian.org/tracker/CVE-2018-14048\", \"severity\": + \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"\ + 1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2019-6129\", \"description\": \"** DISPUTED + ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated + by pngcp. NOTE: a third party has stated \\\"I don't think it is libpng's job to + free this buffer.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-6129\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-14550\", \"description\"\ + : \"An issue has been found in third-party PNM decoding associated with libpng 1.6.35. + It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-14550\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"}, {\"key\": + \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-9893\", \"description\": \"libseccomp + before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using + the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing + seccomp filters and potential privilege escalations.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9893\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2.3.3-4\"}, {\"key\": \"package_name\", \"value\": \"libseccomp\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-1000654\", \"description\"\ + : \"GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains + a DoS, specifically CPU usage will reach 100% when running asn1Paser against the + POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program + will be killed. This attack appears to be exploitable via parsing a crafted file.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-1000654\", \"\ + severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"\ + value\": \"4.13-3\"}, {\"key\": \"package_name\", \"value\": \"libtasn1-6\"}, {\"\ + key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:C\"}, {\"key\": \"\ + CVSS2_SCORE\", \"value\": \"7.1\"}]}, {\"name\": \"CVE-2016-9085\", \"description\"\ + : \"Multiple integer overflows in libwebp allows attackers to have unspecified impact + via unknown vectors.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-9085\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"0.6.1-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libwebp\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2015-9019\", \"description\"\ + : \"In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized + with a random seed during startup, which could cause usage of this function to produce + predictable outputs.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2015-9019\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"1.1.32-2.2~deb10u1\"}, {\"key\": \"package_name\", \"value\": \"\ + libxslt\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"\ + }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2009-4487\" + , \"description\": \"nginx 0.7.64 writes data to a log file without sanitizing non-printable + characters, which might allow remote attackers to modify a window's title, or possibly + execute arbitrary commands or overwrite files, via an HTTP request containing an + escape sequence for a terminal emulator.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2009-4487\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-15719\", \"description\"\ + : \"libldap in certain third-party OpenLDAP packages has a certificate-validation + flaw when the third-party package is asserting RFC6125 support. It considers CN + even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, + openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-15719\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\": + \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:H/Au:N/C:P/I:P/A:N\"\ + }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4\"}]}, {\"name\": \"CVE-2015-3276\" + , \"description\": \"The nss_parse_ciphers function in libraries/libldap/tls_m.c + in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, + which might cause a weaker than intended cipher to be used and allow remote attackers + to have unspecified impact via unknown vectors.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2015-3276\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\": + \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"\ + }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2017-14159\"\ + , \"description\": \"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after + dropping privileges to a non-root account, which might allow local users to kill + arbitrary processes by leveraging access to this non-root account for PID file modification + before a root script executes a \\\"kill `cat /pathname`\\\" command, as demonstrated + by openldap-initscript.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-14159\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\": + \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:N/A:P\"\ + }, {\"key\": \"CVSS2_SCORE\", \"value\": \"1.9\"}]}, {\"name\": \"CVE-2017-17740\"\ + , \"description\": \"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, + when both the nops module and the memberof overlay are enabled, attempts to free + a buffer that was allocated on the stack, which allows remote attackers to cause + a denial of service (slapd crash) via a member MODDN operation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-17740\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\": + \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"\ + }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2010-0928\" + , \"description\": \"OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx + Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain + signature calculations, and does not verify the signature before providing it to + a caller, which makes it easier for physically proximate attackers to determine + the private key via a modified supply voltage for the microprocessor, related to + a \\\"fault-based attack.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-0928\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"1.1.1d-0+deb10u6\"}, {\"key\": \"package_name\", \"value\": \"openssl\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:C/I:N/A:N\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"4\"}]}, {\"name\": \"CVE-2007-6755\", \"description\"\ + : \"The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic + Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a + possible relationship to certain \\\"skeleton key\\\" values, which might allow + context-dependent attackers to defeat cryptographic protection mechanisms by leveraging + knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future + research may provide additional details about point Q and associated attacks, and + could potentially lead to a RECAST or REJECT of this CVE.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2007-6755\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"1.1.1d-0+deb10u6\"}, {\"key\": \"package_name\", \"value\": \"openssl\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:N\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"5.8\"}]}, {\"name\": \"CVE-2017-7246\", \"description\"\ + : \"Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE - of size 268) or possibly have unspecified other impact via a crafted file.", "uri": - "https://security-tracker.debian.org/tracker/CVE-2017-7246", "severity": "INFORMATIONAL", - "attributes": [{"key": "package_version", "value": "2:8.39-12"}, {"key": "package_name", - "value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-20838", "description": - "libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is - disabled, and \\X or \\R has more than one fixed quantifier, a related issue to - CVE-2019-20454.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20838", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, - {"name": "CVE-2017-7245", "description": "Stack-based buffer overflow in the pcre32_copy_substring - function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause - a denial of service (WRITE of size 4) or possibly have unspecified other impact - via a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-7245", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, - {"name": "CVE-2017-16231", "description": "** DISPUTED ** In PCRE 8.41, after compiling, - a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c - because of a self-recursive call. NOTE: third parties dispute the relevance of this - report, noting that there are options that can be used to limit the amount of stack - that is used.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16231", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", - "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, - {"name": "CVE-2017-11164", "description": "In PCRE 8.41, the OP_KETRMAX feature - in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) - when processing a crafted regular expression.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-11164", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:L/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.8"}]}, - {"name": "CVE-2011-4116", "description": "_is_safe in the File::Temp module for - Perl does not properly handle symlinks.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-4116", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "5.28.1-6+deb10u1"}, {"key": "package_name", "value": "perl"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, - {"name": "CVE-2019-19882", "description": "shadow 4.8, in certain circumstances - affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain - root access because setuid programs are misconfigured. Specifically, this affects - shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid, - and without a PAM configuration suitable for use with setuid account management - tools. This combination leads to account management tools (groupadd, groupdel, groupmod, - useradd, userdel, usermod) that can easily be used by unprivileged local users to - escalate privileges to root in multiple ways. This issue became much more relevant - in approximately December 2019 when an unrelated bug was fixed (i.e., the chmod - calls to suidusbins were fixed in the upstream Makefile which is now included in - the release version 4.8).", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-19882", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", - "value": "AV:L/AC:M/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.9"}]}, - {"name": "CVE-2007-5686", "description": "initscripts in rPath Linux 1 sets insecure - permissions for the /var/log/btmp file, which allows local users to obtain sensitive - information regarding authentication attempts. NOTE: because sshd detects the insecure - permissions and does not log certain events, this also prevents sshd from logging - failed authentication attempts by remote attackers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-5686", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", - "value": "AV:L/AC:L/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.9"}]}, - {"name": "CVE-2013-4235", "description": "shadow: TOCTOU (time-of-check time-of-use) - race condition when copying and removing directory trees", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4235", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", - "value": "AV:L/AC:M/Au:N/C:N/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "3.3"}]}, - {"name": "CVE-2020-13529", "description": "An exploitable denial-of-service vulnerability - exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server - running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker - can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.", - "uri": "https://security-tracker.debian.org/tracker/CVE-2020-13529", "severity": - "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"}, - {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:A/AC:M/Au:N/C:N/I:N/A:P"}, - {"key": "CVSS2_SCORE", "value": "2.9"}]}, {"name": "CVE-2013-4392", "description": - "systemd, when updating file permissions, allows local users to change the permissions + of size 268) or possibly have unspecified other impact via a crafted file.\", \"\ + uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-7246\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-20838\", \"description\": \"libpcre + in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, + and \\\\X or \\\\R has more than one fixed quantifier, a related issue to CVE-2019-20454.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-20838\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-7245\", \"description\": \"Stack-based + buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 + in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size + 4) or possibly have unspecified other impact via a crafted file.\", \"uri\": \"\ + https://security-tracker.debian.org/tracker/CVE-2017-7245\", \"severity\": \"INFORMATIONAL\"\ + , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2:8.39-12\"}, {\"\ + key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"CVSS2_VECTOR\", \"value\"\ + : \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\": \"6.8\"\ + }]}, {\"name\": \"CVE-2017-16231\", \"description\": \"** DISPUTED ** In PCRE 8.41, + after compiling, a pcretest load test PoC produces a crash overflow in the function + match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute + the relevance of this report, noting that there are options that can be used to + limit the amount of stack that is used.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16231\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, + {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2017-11164\", \"description\"\ + : \"In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows + stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-11164\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:C\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"7.8\"}]}, {\"name\": \"CVE-2011-4116\", \"description\": \"_is_safe + in the File::Temp module for Perl does not properly handle symlinks.\", \"uri\" + : \"https://security-tracker.debian.org/tracker/CVE-2011-4116\", \"severity\": \"\ + INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"5.28.1-6+deb10u1\"\ + }, {\"key\": \"package_name\", \"value\": \"perl\"}, {\"key\": \"CVSS2_VECTOR\" + , \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ + : \"5\"}]}, {\"name\": \"CVE-2019-19882\", \"description\": \"shadow 4.8, in certain + circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local + users to obtain root access because setuid programs are misconfigured. Specifically, + this affects shadow 4.8 when compiled using --with-libpam but without explicitly + passing --disable-account-tools-setuid, and without a PAM configuration suitable + for use with setuid account management tools. This combination leads to account + management tools (groupadd, groupdel, groupmod, useradd, userdel, usermod) that + can easily be used by unprivileged local users to escalate privileges to root in + multiple ways. This issue became much more relevant in approximately December 2019 + when an unrelated bug was fixed (i.e., the chmod calls to suidusbins were fixed + in the upstream Makefile which is now included in the release version 4.8).\", \"\ + uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-19882\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"6.9\"}]}, {\"name\": \"CVE-2007-5686\", \"description\": \"initscripts + in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows + local users to obtain sensitive information regarding authentication attempts. \ + \ NOTE: because sshd detects the insecure permissions and does not log certain events, + this also prevents sshd from logging failed authentication attempts by remote attackers.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2007-5686\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:C/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"4.9\"}]}, {\"name\": \"CVE-2013-4235\", \"description\": \"shadow: + TOCTOU (time-of-check time-of-use) race condition when copying and removing directory + trees\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-4235\" + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, + {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:P/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"3.3\"}]}, {\"name\": \"CVE-2020-13529\", \"description\"\ + : \"An exploitable denial-of-service vulnerability exists in Systemd 245. A specially + crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be + vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW + and DCHP ACK packets to reconfigure the server.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-13529\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:A/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"2.9\"}]}, {\"name\": \"CVE-2013-4392\", \"description\"\ + : \"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified - files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4392", "severity": - "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"}, - {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:N"}, - {"key": "CVSS2_SCORE", "value": "3.3"}]}, {"name": "CVE-2020-13776", "description": - "systemd through v245 mishandles numerical usernames such as ones composed of decimal - digits or 0x followed by hex digits, as demonstrated by use of root privileges when - privileges of the 0x0 user account were intended. NOTE: this issue exists because - of an incomplete fix for CVE-2017-1000082.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-13776", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", - "value": "AV:L/AC:H/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.2"}]}, - {"name": "CVE-2019-20386", "description": "An issue was discovered in button_open - in login/logind-button.c in systemd before 243. When executing the udevadm trigger - command, a memory leak may occur.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20386", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", - "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, - {"name": "CVE-2019-9923", "description": "pax_decode_header in sparse.c in GNU Tar - before 1.32 had a NULL pointer dereference when parsing certain archives that have - malformed extended headers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9923", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, - {"name": "CVE-2005-2541", "description": "Tar 1.15.1 does not properly warn the - user when extracting setuid or setgid files, which may allow local users or remote - attackers to gain privileges.", "uri": "https://security-tracker.debian.org/tracker/CVE-2005-2541", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:L/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "10"}]}, - {"name": "CVE-2021-20193", "description": "A flaw was found in the src/list.c of - tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input - file to tar to cause uncontrolled consumption of memory. The highest threat from - this vulnerability is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-20193", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR", - "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, - {"name": "CVE-2017-17973", "description": "** DISPUTED ** In LibTIFF 4.0.8, there - is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: - there is a third-party report of inability to reproduce this issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17973", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key": - "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": - "6.8"}]}, {"name": "CVE-2020-35521", "description": "A flaw was found in libtiff. - Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to - an abort, resulting in denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35521", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key": - "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": - "4.3"}]}, {"name": "CVE-2014-8130", "description": "The _TIFFmalloc function in - tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers - to cause a denial of service (divide-by-zero error and application crash) via a - crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, - as demonstrated by tiffdither.", "uri": "https://security-tracker.debian.org/tracker/CVE-2014-8130", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key": - "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": - "4.3"}]}, {"name": "CVE-2017-5563", "description": "LibTIFF version 4.0.7 is vulnerable - to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution - via a crafted bmp image to tools/bmp2tiff.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-5563", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key": - "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": - "6.8"}]}, {"name": "CVE-2020-35522", "description": "In LibTIFF, there is a memory - malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, - resulting in a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35522", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key": - "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": - "4.3"}]}, {"name": "CVE-2017-9117", "description": "In LibTIFF 4.0.7, the program - processes BMP images without verifying that biWidth and biHeight in the bitmap-information - header match the actual input, leading to a heap-based buffer over-read in bmp2tiff.", - "uri": "https://security-tracker.debian.org/tracker/CVE-2017-9117", "severity": - "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "4.1.0+git191117-2~deb10u2"}, - {"key": "package_name", "value": "tiff"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, - {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2017-16232", "description": - "** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow - attackers to cause a denial of service (memory consumption), as demonstrated by - tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce - the issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16232", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key": - "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": - "5"}]}, {"name": "CVE-2018-10126", "description": "LibTIFF 4.0.9 has a NULL pointer - dereference in the jpeg_fdct_16x16 function in jfdctint.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-10126", - "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": - "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key": - "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": - "4.3"}]}, {"name": "CVE-2021-22924", "description": "libcurl keeps previously used - connections in a connection pool for subsequenttransfers to reuse, if one of them - matches the setup.Due to errors in the logic, the config matching function did not - take ''issuercert'' into account and it compared the involved paths *case insensitively*,which - could lead to libcurl reusing wrong connections.File paths are, or can be, case - sensitive on many systems but not all, and caneven vary depending on used file systems.The - comparison also didn''t include the ''issuer cert'' which a transfer can setto qualify - how to verify the server certificate.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22924", - "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"}, - {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-38115", "description": - "read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 - allows remote attackers to cause a denial of service (out-of-bounds read) via a - crafted TGA file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-38115", - "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"}, - {"key": "package_name", "value": "libgd2"}]}, {"name": "CVE-2021-3618", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3618", - "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"}, - {"key": "package_name", "value": "nginx"}]}], "findingSeverityCounts": {"HIGH": - 2, "MEDIUM": 14, "INFORMATIONAL": 63, "LOW": 22, "UNDEFINED": 3}}}, "requestID": - "23c19e2d-c48b-4265-b4eb-853e7b325780", "eventID": "6c94a9b2-36dc-43f8-a6dd-4ec839ded8af", - "readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": - "111111111111", "eventCategory": "Management"}' + files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-4392\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:P/I:P/A:N\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"3.3\"}]}, {\"name\": \"CVE-2020-13776\", \"description\"\ + : \"systemd through v245 mishandles numerical usernames such as ones composed of + decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges + when privileges of the 0x0 user account were intended. NOTE: this issue exists because + of an incomplete fix for CVE-2017-1000082.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-13776\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\ + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:C/I:C/A:C\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"6.2\"}]}, {\"name\": \"CVE-2019-20386\", \"description\"\ + : \"An issue was discovered in button_open in login/logind-button.c in systemd before + 243. When executing the udevadm trigger command, a memory leak may occur.\", \"\ + uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-20386\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\ + : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2019-9923\", \"description\": \"pax_decode_header + in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain + archives that have malformed extended headers.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9923\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"}, + {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2005-2541\", \"description\"\ + : \"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid + files, which may allow local users or remote attackers to gain privileges.\", \"\ + uri\": \"https://security-tracker.debian.org/tracker/CVE-2005-2541\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"10\"}]}, {\"name\": \"CVE-2021-20193\", \"description\": \"A flaw + was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker + who can submit a crafted input file to tar to cause uncontrolled consumption of + memory. The highest threat from this vulnerability is to system availability.\" + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-20193\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"}, {\"key\": \"\ + CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ + , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-17973\", \"description\": \"** DISPUTED + ** In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function + in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this + issue.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-17973\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\ + : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"\ + }, {\"key\": \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-35521\"\ + , \"description\": \"A flaw was found in libtiff. Due to a memory allocation failure + in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of + service.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-35521\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\ + : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"\ + }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2014-8130\"\ + , \"description\": \"The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does + not reject a zero size, which allows remote attackers to cause a denial of service + (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled + by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2014-8130\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\" + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-5563\", \"description\"\ + : \"LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c + resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.\" + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-5563\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\" + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-35522\", \"description\"\ + : \"In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF + document can lead to an abort, resulting in a remote denial of service attack.\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-35522\", \"severity\"\ + : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": + \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\" + }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\ + : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-9117\", \"description\"\ + : \"In LibTIFF 4.0.7, the program processes BMP images without verifying that biWidth + and biHeight in the bitmap-information header match the actual input, leading to + a heap-based buffer over-read in bmp2tiff.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-9117\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\ + : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"\ + }, {\"key\": \"CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2017-16232\"\ + , \"description\": \"** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, + which allow attackers to cause a denial of service (memory consumption), as demonstrated + by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce + the issue.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16232\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\ + : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"\ + }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2018-10126\"\ + , \"description\": \"LibTIFF 4.0.9 has a NULL pointer dereference in the jpeg_fdct_16x16 + function in jfdctint.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-10126\"\ + , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ + , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\ + : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"\ + }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2021-22924\"\ + , \"description\": \"libcurl keeps previously used connections in a connection pool + for subsequenttransfers to reuse, if one of them matches the setup.Due to errors + in the logic, the config matching function did not take 'issuercert' into account + and it compared the involved paths *case insensitively*,which could lead to libcurl + reusing wrong connections.File paths are, or can be, case sensitive on many systems + but not all, and caneven vary depending on used file systems.The comparison also + didn't include the 'issuer cert' which a transfer can setto qualify how to verify + the server certificate.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22924\"\ + , \"severity\": \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"\ + value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\" + }]}, {\"name\": \"CVE-2021-38115\", \"description\": \"read_header_tga in gd_tga.c + in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to + cause a denial of service (out-of-bounds read) via a crafted TGA file.\", \"uri\"\ + : \"https://security-tracker.debian.org/tracker/CVE-2021-38115\", \"severity\": + \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"\ + }, {\"key\": \"package_name\", \"value\": \"libgd2\"}]}, {\"name\": \"CVE-2021-3618\"\ + , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-3618\", \"severity\"\ + : \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.21.1-1~buster\"\ + }, {\"key\": \"package_name\", \"value\": \"nginx\"}]}], \"findingSeverityCounts\"\ + : {\"HIGH\": 2, \"MEDIUM\": 14, \"INFORMATIONAL\": 63, \"LOW\": 22, \"UNDEFINED\"\ + : 3}}}, \"requestID\": \"23c19e2d-c48b-4265-b4eb-853e7b325780\", \"eventID\": \"\ + 6c94a9b2-36dc-43f8-a6dd-4ec839ded8af\", \"readOnly\": true, \"eventType\": \"AwsApiCall\"\ + , \"managementEvent\": true, \"recipientAccountId\": \"111111111111\", \"eventCategory\"\ + : \"Management\"}" diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml index d4abfd2473..56fa1914b9 100644 --- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml @@ -1,95 +1,96 @@ name: AWS CloudTrail GetAccountPasswordPolicy id: 439bdc53-6e4b-4cd7-b326-86c7317fd396 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a request is made to get the account password policy in AWS CloudTrail. +description: Logs an event when a request is made to get the account password policy + in AWS CloudTrail. mitre_components: -- User Account Authentication -- User Account Metadata + - User Account Authentication + - User Account Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: GetAccountPasswordPolicy supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- desc -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - desc + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDASBMSCQHHTH5NDF4GD", "arn": "arn:aws:iam::111111111111:user/strt_fonder", "accountId": "111111111111", "accessKeyId": "AKIASBMSCQHH5A5NJDM5", "userName": "strt_fonder"}, diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml index 3a3c9a6e10..d303eb012c 100644 --- a/data_sources/aws_cloudtrail_getobject.yml +++ b/data_sources/aws_cloudtrail_getobject.yml @@ -1,104 +1,105 @@ name: AWS CloudTrail GetObject id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a request is made to access an object stored in an AWS S3 bucket. +description: Logs an event when a request is made to access an object stored in an + AWS S3 bucket. mitre_components: -- Cloud Storage Access -- Cloud Storage Metadata -- Cloud Storage Enumeration + - Cloud Storage Access + - Cloud Storage Metadata + - Cloud Storage Enumeration source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: GetObject supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- additionalEventData.AuthenticationMethod -- additionalEventData.CipherSuite -- additionalEventData.SignatureVersion -- additionalEventData.bytesTransferredIn -- additionalEventData.bytesTransferredOut -- additionalEventData.x-amz-id-2 -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.Host -- requestParameters.bucketName -- requestParameters.key -- requestParameters.x-amz-request-payer -- resources{}.ARN -- resources{}.accountId -- resources{}.type -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - additionalEventData.AuthenticationMethod + - additionalEventData.CipherSuite + - additionalEventData.SignatureVersion + - additionalEventData.bytesTransferredIn + - additionalEventData.bytesTransferredOut + - additionalEventData.x-amz-id-2 + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.Host + - requestParameters.bucketName + - requestParameters.key + - requestParameters.x-amz-request-payer + - resources{}.ARN + - resources{}.accountId + - resources{}.type + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/console", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": "console"}, "eventTime": diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml index 7b86ddd0fe..6644109837 100644 --- a/data_sources/aws_cloudtrail_getpassworddata.yml +++ b/data_sources/aws_cloudtrail_getpassworddata.yml @@ -1,105 +1,106 @@ name: AWS CloudTrail GetPasswordData id: 6ff2ce99-85b1-4c17-888a-56dbc3570671 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a request is made to retrieve the administrator password of an EC2 instance. +description: Logs an event when a request is made to retrieve the administrator password + of an EC2 instance. mitre_components: -- Instance Metadata -- User Account Authentication + - Instance Metadata + - User Account Authentication source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: GetPasswordData supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- errorMessage -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- reason -- recipientAccountId -- region -- requestID -- requestParameters.instanceId -- responseElements -- result -- result_id -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - errorMessage + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - reason + - recipientAccountId + - region + - requestID + - requestParameters.instanceId + - responseElements + - result + - result_id + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLP5AASA6I5:aws-go-sdk-1660169051746043000", "arn": "arn:aws:sts::111111111111:assumed-role/sample-role-used-by-stratus-for-ec2-password-data/aws-go-sdk-1660169051746043000", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLLY5RQXEF", "sessionContext": diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml index fb86a52163..2278f224a5 100644 --- a/data_sources/aws_cloudtrail_jobcreated.yml +++ b/data_sources/aws_cloudtrail_jobcreated.yml @@ -1,81 +1,81 @@ name: AWS CloudTrail JobCreated id: 6473289b-d097-4c86-a837-3cc5ae408155 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a new job is created in AWS CloudTrail. mitre_components: -- Scheduled Job Creation -- Cloud Service Metadata + - Scheduled Job Creation + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: JobCreated supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- desc -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestParameters -- responseElements -- serviceEventDetails.jobArn -- serviceEventDetails.jobEventId -- serviceEventDetails.jobId -- serviceEventDetails.status -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- userAgent -- userIdentity.accountId -- userIdentity.invokedBy -- user_agent -- user_group_id -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - desc + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestParameters + - responseElements + - serviceEventDetails.jobArn + - serviceEventDetails.jobEventId + - serviceEventDetails.jobId + - serviceEventDetails.status + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - userAgent + - userIdentity.accountId + - userIdentity.invokedBy + - user_agent + - user_group_id + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"accountId": "111111111111", "invokedBy": "s3.amazonaws.com"}, "eventTime": "2023-04-24T23:51:17Z", "eventSource": "s3.amazonaws.com", "eventName": "JobCreated", "awsRegion": "us-west-2", "sourceIPAddress": diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml index df5c25ffe5..99cb79f0b2 100644 --- a/data_sources/aws_cloudtrail_modifydbinstance.yml +++ b/data_sources/aws_cloudtrail_modifydbinstance.yml @@ -1,154 +1,155 @@ name: AWS CloudTrail ModifyDBInstance id: bfa2912d-1a33-4b05-be46-543874d68241 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a modification is made to an AWS database instance, such as parameters or configurations. +description: Logs an event when a modification is made to an AWS database instance, + such as parameters or configurations. mitre_components: -- Instance Modification -- Cloud Service Modification -- Instance Metadata + - Instance Modification + - Cloud Service Modification + - Instance Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: ModifyDBInstance supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.allowMajorVersionUpgrade -- requestParameters.applyImmediately -- requestParameters.dBInstanceIdentifier -- requestParameters.deletionProtection -- requestParameters.masterUserPassword -- responseElements.allocatedStorage -- responseElements.autoMinorVersionUpgrade -- responseElements.availabilityZone -- responseElements.backupRetentionPeriod -- responseElements.backupTarget -- responseElements.cACertificateIdentifier -- responseElements.copyTagsToSnapshot -- responseElements.customerOwnedIpEnabled -- responseElements.dBInstanceArn -- responseElements.dBInstanceClass -- responseElements.dBInstanceIdentifier -- responseElements.dBInstanceStatus -- responseElements.dBParameterGroups{}.dBParameterGroupName -- responseElements.dBParameterGroups{}.parameterApplyStatus -- responseElements.dBSubnetGroup.dBSubnetGroupDescription -- responseElements.dBSubnetGroup.dBSubnetGroupName -- responseElements.dBSubnetGroup.subnetGroupStatus -- responseElements.dBSubnetGroup.subnets{}.subnetAvailabilityZone.name -- responseElements.dBSubnetGroup.subnets{}.subnetIdentifier -- responseElements.dBSubnetGroup.subnets{}.subnetStatus -- responseElements.dBSubnetGroup.vpcId -- responseElements.dbInstancePort -- responseElements.dbiResourceId -- responseElements.deletionProtection -- responseElements.endpoint.address -- responseElements.endpoint.hostedZoneId -- responseElements.endpoint.port -- responseElements.engine -- responseElements.engineVersion -- responseElements.enhancedMonitoringResourceArn -- responseElements.httpEndpointEnabled -- responseElements.iAMDatabaseAuthenticationEnabled -- responseElements.instanceCreateTime -- responseElements.kmsKeyId -- responseElements.latestRestorableTime -- responseElements.licenseModel -- responseElements.masterUsername -- responseElements.monitoringInterval -- responseElements.monitoringRoleArn -- responseElements.multiAZ -- responseElements.networkType -- responseElements.optionGroupMemberships{}.optionGroupName -- responseElements.optionGroupMemberships{}.status -- responseElements.pendingModifiedValues.masterUserPassword -- responseElements.performanceInsightsEnabled -- responseElements.performanceInsightsKMSKeyId -- responseElements.performanceInsightsRetentionPeriod -- responseElements.preferredBackupWindow -- responseElements.preferredMaintenanceWindow -- responseElements.publiclyAccessible -- responseElements.storageEncrypted -- responseElements.storageThroughput -- responseElements.storageType -- responseElements.vpcSecurityGroups{}.status -- responseElements.vpcSecurityGroups{}.vpcSecurityGroupId -- sessionCredentialFromConsole -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.allowMajorVersionUpgrade + - requestParameters.applyImmediately + - requestParameters.dBInstanceIdentifier + - requestParameters.deletionProtection + - requestParameters.masterUserPassword + - responseElements.allocatedStorage + - responseElements.autoMinorVersionUpgrade + - responseElements.availabilityZone + - responseElements.backupRetentionPeriod + - responseElements.backupTarget + - responseElements.cACertificateIdentifier + - responseElements.copyTagsToSnapshot + - responseElements.customerOwnedIpEnabled + - responseElements.dBInstanceArn + - responseElements.dBInstanceClass + - responseElements.dBInstanceIdentifier + - responseElements.dBInstanceStatus + - responseElements.dBParameterGroups{}.dBParameterGroupName + - responseElements.dBParameterGroups{}.parameterApplyStatus + - responseElements.dBSubnetGroup.dBSubnetGroupDescription + - responseElements.dBSubnetGroup.dBSubnetGroupName + - responseElements.dBSubnetGroup.subnetGroupStatus + - responseElements.dBSubnetGroup.subnets{}.subnetAvailabilityZone.name + - responseElements.dBSubnetGroup.subnets{}.subnetIdentifier + - responseElements.dBSubnetGroup.subnets{}.subnetStatus + - responseElements.dBSubnetGroup.vpcId + - responseElements.dbInstancePort + - responseElements.dbiResourceId + - responseElements.deletionProtection + - responseElements.endpoint.address + - responseElements.endpoint.hostedZoneId + - responseElements.endpoint.port + - responseElements.engine + - responseElements.engineVersion + - responseElements.enhancedMonitoringResourceArn + - responseElements.httpEndpointEnabled + - responseElements.iAMDatabaseAuthenticationEnabled + - responseElements.instanceCreateTime + - responseElements.kmsKeyId + - responseElements.latestRestorableTime + - responseElements.licenseModel + - responseElements.masterUsername + - responseElements.monitoringInterval + - responseElements.monitoringRoleArn + - responseElements.multiAZ + - responseElements.networkType + - responseElements.optionGroupMemberships{}.optionGroupName + - responseElements.optionGroupMemberships{}.status + - responseElements.pendingModifiedValues.masterUserPassword + - responseElements.performanceInsightsEnabled + - responseElements.performanceInsightsKMSKeyId + - responseElements.performanceInsightsRetentionPeriod + - responseElements.preferredBackupWindow + - responseElements.preferredMaintenanceWindow + - responseElements.publiclyAccessible + - responseElements.storageEncrypted + - responseElements.storageThroughput + - responseElements.storageType + - responseElements.vpcSecurityGroups{}.status + - responseElements.vpcSecurityGroups{}.vpcSecurityGroupId + - sessionCredentialFromConsole + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WP4HD6:gowthamarajr@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/gowthamarajr@splunk.com", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAKJDBQGB", "sessionContext": diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml index 3d415b44b9..67fd0edb8a 100644 --- a/data_sources/aws_cloudtrail_modifyimageattribute.yml +++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml @@ -1,99 +1,100 @@ name: AWS CloudTrail ModifyImageAttribute id: 667c2115-8082-419e-b541-8150066bda4d -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when the attributes of an Amazon Machine Image (AMI) are modified. +description: Logs an event when the attributes of an Amazon Machine Image (AMI) are + modified. mitre_components: -- Image Modification -- Image Metadata + - Image Modification + - Image Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: ModifyImageAttribute supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.attributeType -- requestParameters.imageId -- requestParameters.launchPermission.add.items{}.userId -- responseElements._return -- responseElements.requestId -- sessionCredentialFromConsole -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.attributeType + - requestParameters.imageId + - requestParameters.launchPermission.add.items{}.userId + - responseElements._return + - responseElements.requestId + - sessionCredentialFromConsole + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WP4HD6:bonobo@bo.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bonobo@bo.com", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLBHIEEEPN", "sessionContext": diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml index 211ccdf1dc..d44c5fa436 100644 --- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml @@ -1,94 +1,95 @@ name: AWS CloudTrail ModifySnapshotAttribute id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when modifications are made to the attributes of a snapshot in AWS CloudTrail. +description: Logs an event when modifications are made to the attributes of a snapshot + in AWS CloudTrail. mitre_components: -- Snapshot Modification + - Snapshot Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: ModifySnapshotAttribute supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.attributeType -- requestParameters.createVolumePermission.add.items{}.userId -- requestParameters.snapshotId -- responseElements._return -- responseElements.requestId -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.attributeType + - requestParameters.createVolumePermission.add.items{}.userId + - requestParameters.snapshotId + - responseElements._return + - responseElements.requestId + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml index 24be91aea5..715cb571cb 100644 --- a/data_sources/aws_cloudtrail_putbucketacl.yml +++ b/data_sources/aws_cloudtrail_putbucketacl.yml @@ -1,108 +1,109 @@ name: AWS CloudTrail PutBucketAcl id: 28fffbfd-d98d-4a42-990b-b04ab47422eb -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when an ACL is set or modified for an S3 bucket in AWS CloudTrail. +description: Logs an event when an ACL is set or modified for an S3 bucket in AWS + CloudTrail. mitre_components: -- Cloud Storage Modification -- Cloud Storage Metadata + - Cloud Storage Modification + - Cloud Storage Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: PutBucketAcl supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- additionalEventData.AuthenticationMethod -- additionalEventData.CipherSuite -- additionalEventData.SignatureVersion -- additionalEventData.bytesTransferredIn -- additionalEventData.bytesTransferredOut -- additionalEventData.x-amz-id-2 -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object -- object_category -- object_id -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.Host -- requestParameters.accessControlList.x-amz-grant-write-acp -- requestParameters.acl -- requestParameters.bucketName -- resources{}.ARN -- resources{}.accountId -- resources{}.type -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- src_user -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - additionalEventData.AuthenticationMethod + - additionalEventData.CipherSuite + - additionalEventData.SignatureVersion + - additionalEventData.bytesTransferredIn + - additionalEventData.bytesTransferredOut + - additionalEventData.x-amz-id-2 + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object + - object_category + - object_id + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.Host + - requestParameters.accessControlList.x-amz-grant-write-acp + - requestParameters.acl + - requestParameters.bucketName + - resources{}.ARN + - resources{}.accountId + - resources{}.type + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - src_user + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"}, diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml index a01d2b76d2..e5108f5812 100644 --- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml +++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml @@ -1,109 +1,110 @@ name: AWS CloudTrail PutBucketLifecycle id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a lifecycle configuration is added to an S3 bucket in AWS CloudTrail. +description: Logs an event when a lifecycle configuration is added to an S3 bucket + in AWS CloudTrail. mitre_components: -- Cloud Storage Modification -- Cloud Storage Metadata + - Cloud Storage Modification + - Cloud Storage Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: PutBucketLifecycle supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- additionalEventData.AuthenticationMethod -- additionalEventData.CipherSuite -- additionalEventData.SignatureVersion -- additionalEventData.bytesTransferredIn -- additionalEventData.bytesTransferredOut -- additionalEventData.x-amz-id-2 -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object -- object_category -- object_id -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.Host -- requestParameters.LifecycleConfiguration.Rule.Expiration.Days -- requestParameters.LifecycleConfiguration.Rule.Filter.Prefix -- requestParameters.LifecycleConfiguration.Rule.ID -- requestParameters.LifecycleConfiguration.Rule.Status -- requestParameters.LifecycleConfiguration.xmlns -- requestParameters.bucketName -- requestParameters.lifecycle -- resources{}.ARN -- resources{}.accountId -- resources{}.type -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - additionalEventData.AuthenticationMethod + - additionalEventData.CipherSuite + - additionalEventData.SignatureVersion + - additionalEventData.bytesTransferredIn + - additionalEventData.bytesTransferredOut + - additionalEventData.x-amz-id-2 + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object + - object_category + - object_id + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.Host + - requestParameters.LifecycleConfiguration.Rule.Expiration.Days + - requestParameters.LifecycleConfiguration.Rule.Filter.Prefix + - requestParameters.LifecycleConfiguration.Rule.ID + - requestParameters.LifecycleConfiguration.Rule.Status + - requestParameters.LifecycleConfiguration.xmlns + - requestParameters.bucketName + - requestParameters.lifecycle + - resources{}.ARN + - resources{}.accountId + - resources{}.type + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml index b16eec7546..779545c3e7 100644 --- a/data_sources/aws_cloudtrail_putbucketreplication.yml +++ b/data_sources/aws_cloudtrail_putbucketreplication.yml @@ -1,121 +1,122 @@ name: AWS CloudTrail PutBucketReplication id: 0e1362eb-e592-419f-8fa5-556d3a122417 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when replication configurations are added or modified for an S3 bucket. +description: Logs an event when replication configurations are added or modified for + an S3 bucket. mitre_components: -- Cloud Storage Modification + - Cloud Storage Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: PutBucketReplication supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- additionalEventData.AuthenticationMethod -- additionalEventData.CipherSuite -- additionalEventData.SignatureVersion -- additionalEventData.bytesTransferredIn -- additionalEventData.bytesTransferredOut -- additionalEventData.x-amz-id-2 -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object -- object_category -- object_id -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.Host -- requestParameters.ReplicationConfiguration.Role -- requestParameters.ReplicationConfiguration.Rule.DeleteMarkerReplication.Status -- requestParameters.ReplicationConfiguration.Rule.Destination.Bucket -- requestParameters.ReplicationConfiguration.Rule.Filter -- requestParameters.ReplicationConfiguration.Rule.ID -- requestParameters.ReplicationConfiguration.Rule.Priority -- requestParameters.ReplicationConfiguration.Rule.Status -- requestParameters.ReplicationConfiguration.xmlns -- requestParameters.bucketName -- requestParameters.replication -- resources{}.ARN -- resources{}.accountId -- resources{}.type -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region -- vpcEndpointId + - _time + - additionalEventData.AuthenticationMethod + - additionalEventData.CipherSuite + - additionalEventData.SignatureVersion + - additionalEventData.bytesTransferredIn + - additionalEventData.bytesTransferredOut + - additionalEventData.x-amz-id-2 + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object + - object_category + - object_id + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.Host + - requestParameters.ReplicationConfiguration.Role + - requestParameters.ReplicationConfiguration.Rule.DeleteMarkerReplication.Status + - requestParameters.ReplicationConfiguration.Rule.Destination.Bucket + - requestParameters.ReplicationConfiguration.Rule.Filter + - requestParameters.ReplicationConfiguration.Rule.ID + - requestParameters.ReplicationConfiguration.Rule.Priority + - requestParameters.ReplicationConfiguration.Rule.Status + - requestParameters.ReplicationConfiguration.xmlns + - requestParameters.bucketName + - requestParameters.replication + - resources{}.ARN + - resources{}.accountId + - resources{}.type + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region + - vpcEndpointId example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WP4H11:bpatel@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bpatel@splunk.com", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLJOVYQHW2", "sessionContext": diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml index 1fcc3c6668..1d727cc4d1 100644 --- a/data_sources/aws_cloudtrail_putbucketversioning.yml +++ b/data_sources/aws_cloudtrail_putbucketversioning.yml @@ -1,112 +1,113 @@ name: AWS CloudTrail PutBucketVersioning id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when the bucket versioning state is modified in an AWS S3 bucket. +description: Logs an event when the bucket versioning state is modified in an AWS + S3 bucket. mitre_components: -- Cloud Storage Modification + - Cloud Storage Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: PutBucketVersioning supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- additionalEventData.AuthenticationMethod -- additionalEventData.CipherSuite -- additionalEventData.SignatureVersion -- additionalEventData.bytesTransferredIn -- additionalEventData.bytesTransferredOut -- additionalEventData.x-amz-id-2 -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object -- object_category -- object_id -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.Host -- requestParameters.VersioningConfiguration.Status -- requestParameters.VersioningConfiguration.xmlns -- requestParameters.bucketName -- requestParameters.versioning -- resources{}.ARN -- resources{}.accountId -- resources{}.type -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region -- vpcEndpointId + - _time + - additionalEventData.AuthenticationMethod + - additionalEventData.CipherSuite + - additionalEventData.SignatureVersion + - additionalEventData.bytesTransferredIn + - additionalEventData.bytesTransferredOut + - additionalEventData.x-amz-id-2 + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object + - object_category + - object_id + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.Host + - requestParameters.VersioningConfiguration.Status + - requestParameters.VersioningConfiguration.xmlns + - requestParameters.bucketName + - requestParameters.versioning + - resources{}.ARN + - resources{}.accountId + - resources{}.type + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region + - vpcEndpointId example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WP4HD6:daftpunk@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/daftpunk@splunk.com", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAQ5VXXXX", "sessionContext": diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml index 263b630172..713ed667e1 100644 --- a/data_sources/aws_cloudtrail_putimage.yml +++ b/data_sources/aws_cloudtrail_putimage.yml @@ -1,102 +1,103 @@ name: AWS CloudTrail PutImage id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a container image is uploaded to a repository in AWS CloudTrail. +description: Logs an event when a container image is uploaded to a repository in AWS + CloudTrail. mitre_components: -- Image Creation -- Image Metadata + - Image Creation + - Image Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: PutImage supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.imageManifest -- requestParameters.imageManifestMediaType -- requestParameters.imageTag -- requestParameters.registryId -- requestParameters.repositoryName -- resources{}.ARN -- resources{}.accountId -- responseElements.image.imageId.imageDigest -- responseElements.image.imageId.imageTag -- responseElements.image.imageManifest -- responseElements.image.imageManifestMediaType -- responseElements.image.registryId -- responseElements.image.repositoryName -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.invokedBy -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.imageManifest + - requestParameters.imageManifestMediaType + - requestParameters.imageTag + - requestParameters.registryId + - requestParameters.repositoryName + - resources{}.ARN + - resources{}.accountId + - responseElements.image.imageId.imageDigest + - responseElements.image.imageId.imageTag + - responseElements.image.imageManifest + - responseElements.image.imageManifestMediaType + - responseElements.image.registryId + - responseElements.image.repositoryName + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.invokedBy + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AAAAAAAAAAAAAAAAAAAAA", "arn": "arn:aws:iam::111111111111:user/test", "accountId": "111111111111", "accessKeyId": "AAAAAAAAAAAAAAAAAAAAA", "userName": "test", "sessionContext": diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml index edac5877b5..d291365312 100644 --- a/data_sources/aws_cloudtrail_putkeypolicy.yml +++ b/data_sources/aws_cloudtrail_putkeypolicy.yml @@ -1,101 +1,102 @@ name: AWS CloudTrail PutKeyPolicy id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs changes made to AWS Key Management Service (KMS) key policies, including updates and permission assignments. +description: Logs changes made to AWS Key Management Service (KMS) key policies, including + updates and permission assignments. source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.bypassPolicyLockoutSafetyCheck -- requestParameters.keyId -- requestParameters.policy -- requestParameters.policyName -- resources{}.ARN -- resources{}.accountId -- resources{}.type -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.bypassPolicyLockoutSafetyCheck + - requestParameters.keyId + - requestParameters.policy + - requestParameters.policyName + - resources{}.ARN + - resources{}.accountId + - resources{}.type + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region mitre_components: -- Cloud Service Modification + - Cloud Service Modification example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext": diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml index af51b981b1..4e7c3f9359 100644 --- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml @@ -1,110 +1,110 @@ name: AWS CloudTrail ReplaceNetworkAclEntry id: db0c240e-3754-40e4-86ef-cde018ee9f65 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail. mitre_components: -- Firewall Rule Modification -- Cloud Service Modification + - Firewall Rule Modification + - Cloud Service Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: ReplaceNetworkAclEntry supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- direction -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- protocol -- protocol_code -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.aclProtocol -- requestParameters.cidrBlock -- requestParameters.egress -- requestParameters.networkAclId -- requestParameters.ruleAction -- requestParameters.ruleNumber -- responseElements._return -- responseElements.requestId -- rule_action -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- src_ip_range -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - direction + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - protocol + - protocol_code + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.aclProtocol + - requestParameters.cidrBlock + - requestParameters.egress + - requestParameters.networkAclId + - requestParameters.ruleAction + - requestParameters.ruleNumber + - responseElements._return + - responseElements.requestId + - rule_action + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - src_ip_range + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext": diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml index df1e0b4657..d5c2a78694 100644 --- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml +++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml @@ -1,95 +1,96 @@ name: AWS CloudTrail SetDefaultPolicyVersion id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when the default version of a resource policy in AWS is set or changed. +description: Logs an event when the default version of a resource policy in AWS is + set or changed. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata + - Cloud Service Modification + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: SetDefaultPolicyVersion supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.policyArn -- requestParameters.versionId -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.policyArn + - requestParameters.versionId + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLESDK2NOSX", "arn": "arn:aws:iam::111111111111:user/AtomicRedTeam", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKMZDMPVA", "userName": diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml index 69859da19d..934920e8fb 100644 --- a/data_sources/aws_cloudtrail_stoplogging.yml +++ b/data_sources/aws_cloudtrail_stoplogging.yml @@ -1,90 +1,91 @@ name: AWS CloudTrail StopLogging id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated or stopped. +description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated + or stopped. mitre_components: -- Cloud Service Disable + - Cloud Service Disable source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: StopLogging supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.name -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.name + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml index 3959397892..6fd33c83e7 100644 --- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml @@ -1,102 +1,102 @@ name: AWS CloudTrail UpdateAccountPasswordPolicy id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an AWS account's password policy is updated. mitre_components: -- User Account Modification -- Cloud Service Modification + - User Account Modification + - Cloud Service Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: UpdateAccountPasswordPolicy supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.allowUsersToChangePassword -- requestParameters.hardExpiry -- requestParameters.minimumPasswordLength -- requestParameters.requireLowercaseCharacters -- requestParameters.requireNumbers -- requestParameters.requireSymbols -- requestParameters.requireUppercaseCharacters -- responseElements -- sessionCredentialFromConsole -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.allowUsersToChangePassword + - requestParameters.hardExpiry + - requestParameters.minimumPasswordLength + - requestParameters.requireLowercaseCharacters + - requestParameters.requireNumbers + - requestParameters.requireSymbols + - requestParameters.requireUppercaseCharacters + - responseElements + - sessionCredentialFromConsole + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111", "accessKeyId": "ASIASBMSCQHHZZ4THONS", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml index e8d28c061a..911021b6d6 100644 --- a/data_sources/aws_cloudtrail_updateloginprofile.yml +++ b/data_sources/aws_cloudtrail_updateloginprofile.yml @@ -1,94 +1,94 @@ name: AWS CloudTrail UpdateLoginProfile id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an IAM user's login profile is updated. mitre_components: -- User Account Modification -- User Account Authentication + - User Account Modification + - User Account Authentication source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: UpdateLoginProfile supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.userName -- responseElements -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.userName + - responseElements + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml index 9477d6a455..3c7f55c5ea 100644 --- a/data_sources/aws_cloudtrail_updatesamlprovider.yml +++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml @@ -1,192 +1,211 @@ name: AWS CloudTrail UpdateSAMLProvider id: e5eb628d-711e-499c-87d9-8fa5dee419ec -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a SAML provider is updated in AWS. mitre_components: -- Cloud Service Modification -- User Account Modification -- Cloud Service Metadata + - Cloud Service Modification + - User Account Modification + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: UpdateSAMLProvider supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- action -- app -- awsRegion -- aws_account_id -- change_type -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- eventtype -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.sAMLMetadataDocument -- requestParameters.sAMLProviderArn -- responseElements.sAMLProviderArn -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.sessionContext.attributes.creationDate -- userIdentity.sessionContext.attributes.mfaAuthenticated -- userIdentity.sessionContext.sessionIssuer.accountId -- userIdentity.sessionContext.sessionIssuer.arn -- userIdentity.sessionContext.sessionIssuer.principalId -- userIdentity.sessionContext.sessionIssuer.type -- userIdentity.sessionContext.sessionIssuer.userName -- userIdentity.type -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region -example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": - "AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com", - "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLMZGPIW6C", "sessionContext": - {"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLKFUVAQAIJ", "arn": - "arn:aws:iam::111111111111:role/rodonmicrotestrole", "accountId": "111111111111", - "userName": "rodonmicrotestrole"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated": - "false", "creationDate": "2021-01-20T03:10:32Z"}}}, "eventTime": "2021-01-20T03:12:39Z", - "eventSource": "iam.amazonaws.com", "eventName": "UpdateSAMLProvider", "awsRegion": - "us-east-1", "sourceIPAddress": "66.176.252.11", "userAgent": "aws-internal/3 aws-sdk-java/1.11.930 - Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.275-b01 - java/1.8.0_275 vendor/Oracle_Corporation", "requestParameters": {"sAMLMetadataDocument": - "ncp+pf0e75KdoRTy1PQeu74OKXjcVNM+bnT7Ns6cwQI=J9PRCq201gGMzMtt4Ye+gsM7xOgrNvDg/usqIMvsyUy2r/MeTBz5FKCK+Okjwm49vyTWUoUioYGiwm/TD2Knv59g1zy+/OjZcmBJgDrCmksFJdkwG/fDlOZQNGuj2qh1CEKL5n6Ipy2z1dQ9XUmhhndtXNnjdZ0fJ9QWufWoxveSCLHcU7eUB9obwq96pbAp+6as0XreMNC/xPv5gDdHfKaIppsXtEwcZY7m1c25jDWqPUTQrtbVC0uryffg1Yu0JLTr646GMTzxulBSpQGRfNf5UT0bUiLtKngi++UHrngKdv3ovWwpVmY82JhG7rMDhkuWZu3LdEFvY3svNxGtsQ==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNNameThe + - _time + - action + - app + - awsRegion + - aws_account_id + - change_type + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - eventtype + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.sAMLMetadataDocument + - requestParameters.sAMLProviderArn + - responseElements.sAMLProviderArn + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.sessionContext.attributes.creationDate + - userIdentity.sessionContext.attributes.mfaAuthenticated + - userIdentity.sessionContext.sessionIssuer.accountId + - userIdentity.sessionContext.sessionIssuer.arn + - userIdentity.sessionContext.sessionIssuer.principalId + - userIdentity.sessionContext.sessionIssuer.type + - userIdentity.sessionContext.sessionIssuer.userName + - userIdentity.type + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region +example_log: "{\"eventVersion\": \"1.08\", \"userIdentity\": {\"type\": \"AssumedRole\"\ + , \"principalId\": \"AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com\", \"\ + arn\": \"arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com\"\ + , \"accountId\": \"111111111111\", \"accessKeyId\": \"ASIAYTOGP2RLMZGPIW6C\", \"\ + sessionContext\": {\"sessionIssuer\": {\"type\": \"Role\", \"principalId\": \"AROAYTOGP2RLKFUVAQAIJ\"\ + , \"arn\": \"arn:aws:iam::111111111111:role/rodonmicrotestrole\", \"accountId\" + : \"111111111111\", \"userName\": \"rodonmicrotestrole\"}, \"webIdFederationData\"\ + : {}, \"attributes\": {\"mfaAuthenticated\": \"false\", \"creationDate\": \"2021-01-20T03:10:32Z\"\ + }}}, \"eventTime\": \"2021-01-20T03:12:39Z\", \"eventSource\": \"iam.amazonaws.com\"\ + , \"eventName\": \"UpdateSAMLProvider\", \"awsRegion\": \"us-east-1\", \"sourceIPAddress\"\ + : \"66.176.252.11\", \"userAgent\": \"aws-internal/3 aws-sdk-java/1.11.930 Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 + OpenJDK_64-Bit_Server_VM/25.275-b01 java/1.8.0_275 vendor/Oracle_Corporation\", + \"requestParameters\": {\"sAMLMetadataDocument\": \"ncp+pf0e75KdoRTy1PQeu74OKXjcVNM+bnT7Ns6cwQI=J9PRCq201gGMzMtt4Ye+gsM7xOgrNvDg/usqIMvsyUy2r/MeTBz5FKCK+Okjwm49vyTWUoUioYGiwm/TD2Knv59g1zy+/OjZcmBJgDrCmksFJdkwG/fDlOZQNGuj2qh1CEKL5n6Ipy2z1dQ9XUmhhndtXNnjdZ0fJ9QWufWoxveSCLHcU7eUB9obwq96pbAp+6as0XreMNC/xPv5gDdHfKaIppsXtEwcZY7m1c25jDWqPUTQrtbVC0uryffg1Yu0JLTr646GMTzxulBSpQGRfNf5UT0bUiLtKngi++UHrngKdv3ovWwpVmY82JhG7rMDhkuWZu3LdEFvY3svNxGtsQ==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNNameThe mutable display name of the user.SubjectAn + Uri=\\\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier\\\"\ + \ xmlns:auth=\\\"http://docs.oasis-open.org/wsfed/authorization/200706\\\">SubjectAn immutable, globally unique, non-reusable identifier of the user that is unique to the application for which a token is issued.Given + Uri=\\\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname\\\" xmlns:auth=\\\ + \"http://docs.oasis-open.org/wsfed/authorization/200706\\\">Given NameFirst name of the user.SurnameLast - name of the user.Display + Uri=\\\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname\\\" xmlns:auth=\\\ + \"http://docs.oasis-open.org/wsfed/authorization/200706\\\">SurnameLast + name of the user.Display NameDisplay name of the user.Nick + Uri=\\\"http://schemas.microsoft.com/identity/claims/nickname\\\" xmlns:auth=\\\"\ + http://docs.oasis-open.org/wsfed/authorization/200706\\\">Nick NameNick name of the user.Authentication + Uri=\\\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant\\\ + \" xmlns:auth=\\\"http://docs.oasis-open.org/wsfed/authorization/200706\\\">Authentication InstantThe time (UTC) when the user is authenticated to Windows Azure Active Directory.Authentication + Uri=\\\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod\\\ + \" xmlns:auth=\\\"http://docs.oasis-open.org/wsfed/authorization/200706\\\">Authentication MethodThe method that Windows Azure Active Directory uses to authenticate users.ObjectIdentifierPrimary + Uri=\\\"http://schemas.microsoft.com/identity/claims/objectidentifier\\\" xmlns:auth=\\\ + \"http://docs.oasis-open.org/wsfed/authorization/200706\\\">ObjectIdentifierPrimary identifier for the user in the directory. Immutable, globally unique, non-reusable.TenantIdIdentifier - for the user''s tenant.IdentityProviderIdentity - provider for the user.EmailEmail - address of the user.GroupsGroups - of the user.External + Uri=\\\"http://schemas.microsoft.com/identity/claims/tenantid\\\" xmlns:auth=\\\"\ + http://docs.oasis-open.org/wsfed/authorization/200706\\\">TenantIdIdentifier + for the user's tenant.IdentityProviderIdentity + provider for the user.EmailEmail + address of the user.GroupsGroups + of the user.External Access TokenAccess token issued by external - identity provider.External + identity provider.External Access Token ExpirationUTC expiration time of access token issued by external identity provider.External + Uri=\\\"http://schemas.microsoft.com/identity/claims/openid2_id\\\" xmlns:auth=\\\ + \"http://docs.oasis-open.org/wsfed/authorization/200706\\\">External OpenID 2.0 IdentifierOpenID 2.0 identifier issued by external identity provider.GroupsOverageClaimIssued - when number of user''s group claims exceeds return limit.Role + Uri=\\\"http://schemas.microsoft.com/claims/groups.link\\\" xmlns:auth=\\\"http://docs.oasis-open.org/wsfed/authorization/200706\\\ + \">GroupsOverageClaimIssued + when number of user's group claims exceeds return limit.Role ClaimRoles that the user or Service Principal - is attached toRoleTemplate + is attached toRoleTemplate Id ClaimRole template id of the Built-in Directory Roles that the user is a member ofhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNhttps://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN", "sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}, - "responseElements": {"sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}, - "requestID": "83d621ad-5b33-4ff0-acf4-0043cb432844", "eventID": "51b6d859-0cc4-4591-ba76-3494f3f43832", - "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": - "Management", "recipientAccountId": "111111111111"}' + xmlns:wsa=\\\"http://www.w3.org/2005/08/addressing\\\">https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNhttps://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN\", \"sAMLProviderArn\": \"arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft\"\ + }, \"responseElements\": {\"sAMLProviderArn\": \"arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft\"\ + }, \"requestID\": \"83d621ad-5b33-4ff0-acf4-0043cb432844\", \"eventID\": \"51b6d859-0cc4-4591-ba76-3494f3f43832\"\ + , \"readOnly\": false, \"eventType\": \"AwsApiCall\", \"managementEvent\": true, + \"eventCategory\": \"Management\", \"recipientAccountId\": \"111111111111\"}" diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml index edc2d3ff2a..6020310ebe 100644 --- a/data_sources/aws_cloudtrail_updatetrail.yml +++ b/data_sources/aws_cloudtrail_updatetrail.yml @@ -1,99 +1,100 @@ name: AWS CloudTrail UpdateTrail id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when an AWS CloudTrail trail is updated, typically involving changes to settings or configuration. +description: Logs an event when an AWS CloudTrail trail is updated, typically involving + changes to settings or configuration. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata + - Cloud Service Modification + - Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: UpdateTrail supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- app -- awsRegion -- aws_account_id -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- errorCode -- eventCategory -- eventID -- eventName -- eventSource -- eventTime -- eventType -- eventVersion -- host -- index -- linecount -- managementEvent -- msg -- object_category -- product -- punct -- readOnly -- recipientAccountId -- region -- requestID -- requestParameters.includeGlobalServiceEvents -- requestParameters.isMultiRegionTrail -- requestParameters.name -- responseElements.includeGlobalServiceEvents -- responseElements.isMultiRegionTrail -- responseElements.isOrganizationTrail -- responseElements.logFileValidationEnabled -- responseElements.name -- responseElements.s3BucketName -- responseElements.trailARN -- signature -- source -- sourceIPAddress -- sourcetype -- splunk_server -- src -- src_ip -- start_time -- timeendpos -- timestartpos -- tlsDetails.cipherSuite -- tlsDetails.clientProvidedHostHeader -- tlsDetails.tlsVersion -- user -- userAgent -- userIdentity.accessKeyId -- userIdentity.accountId -- userIdentity.arn -- userIdentity.principalId -- userIdentity.type -- userIdentity.userName -- userName -- user_access_key -- user_agent -- user_arn -- user_group_id -- user_id -- user_name -- user_type -- vendor -- vendor_account -- vendor_product -- vendor_region + - _time + - app + - awsRegion + - aws_account_id + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - errorCode + - eventCategory + - eventID + - eventName + - eventSource + - eventTime + - eventType + - eventVersion + - host + - index + - linecount + - managementEvent + - msg + - object_category + - product + - punct + - readOnly + - recipientAccountId + - region + - requestID + - requestParameters.includeGlobalServiceEvents + - requestParameters.isMultiRegionTrail + - requestParameters.name + - responseElements.includeGlobalServiceEvents + - responseElements.isMultiRegionTrail + - responseElements.isOrganizationTrail + - responseElements.logFileValidationEnabled + - responseElements.name + - responseElements.s3BucketName + - responseElements.trailARN + - signature + - source + - sourceIPAddress + - sourcetype + - splunk_server + - src + - src_ip + - start_time + - timeendpos + - timestartpos + - tlsDetails.cipherSuite + - tlsDetails.clientProvidedHostHeader + - tlsDetails.tlsVersion + - user + - userAgent + - userIdentity.accessKeyId + - userIdentity.accountId + - userIdentity.arn + - userIdentity.principalId + - userIdentity.type + - userIdentity.userName + - userName + - user_access_key + - user_agent + - user_arn + - user_group_id + - user_id + - user_name + - user_type + - vendor + - vendor_account + - vendor_product + - vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudwatchlogs_vpcflow.yml b/data_sources/aws_cloudwatchlogs_vpcflow.yml index bec254d4fa..6cd8b1cec1 100644 --- a/data_sources/aws_cloudwatchlogs_vpcflow.yml +++ b/data_sources/aws_cloudwatchlogs_vpcflow.yml @@ -1,71 +1,73 @@ name: AWS CloudWatchLogs VPCflow id: 38a34fc4-e128-4478-a8f4-7835d51d5135 -version: 1 +version: 2 author: Bhavin Patel, Splunk -date: '2024-07-18' -description: Logs an event when network traffic flow information such as source and destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in AWS. +date: '2025-01-23' +description: Logs an event when network traffic flow information such as source and + destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in + AWS. mitre_components: -- Network Traffic Flow -- Network Connection Creation + - Network Traffic Flow + - Network Connection Creation source: aws_cloudwatchlogs_vpcflow sourcetype: aws:cloudwatchlogs:vpcflow supported_TA: -- name: Splunk Add-on for AWS - version: 7.9.0 - url: https://splunkbase.splunk.com/app/1876 + - name: Splunk Add-on for AWS + version: 7.9.0 + url: https://splunkbase.splunk.com/app/1876 fields: -- _raw -- _time -- account_id -- action -- app -- aws_account_id -- bytes -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_ip -- dest_port -- duration -- dvc -- end_time -- eventtype -- host -- index -- interface_id -- linecount -- log_status -- packets -- protocol -- protocol_code -- protocol_full_name -- protocol_version -- punct -- region -- source -- sourcetype -- splunk_server -- splunk_server_group -- src -- src_ip -- src_port -- start_time -- tag -- tag::action -- tag::eventtype -- timeendpos -- timestartpos -- transport -- user_id -- vendor_account -- vendor_product -- version -- vpcflow_action + - _raw + - _time + - account_id + - action + - app + - aws_account_id + - bytes + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_ip + - dest_port + - duration + - dvc + - end_time + - eventtype + - host + - index + - interface_id + - linecount + - log_status + - packets + - protocol + - protocol_code + - protocol_full_name + - protocol_version + - punct + - region + - source + - sourcetype + - splunk_server + - splunk_server_group + - src + - src_ip + - src_port + - start_time + - tag + - tag::action + - tag::eventtype + - timeendpos + - timestartpos + - transport + - user_id + - vendor_account + - vendor_product + - version + - vpcflow_action example_log: 2 123397614277 eni-0b0f9f261f45e6489 10.0.1.30 10.0.1.1 47254 22 17 2 98 1697608042 1697608070 ACCEPT OK diff --git a/data_sources/aws_security_hub.yml b/data_sources/aws_security_hub.yml index 5d72ddeb75..0173357cdf 100644 --- a/data_sources/aws_security_hub.yml +++ b/data_sources/aws_security_hub.yml @@ -1,124 +1,125 @@ name: AWS Security Hub id: b02bfbf3-294f-478e-99a1-e24b8c692d7e -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when AWS Security Hub identifies potential security risks or deviations from configured best practices across AWS accounts. +description: Logs an event when AWS Security Hub identifies potential security risks + or deviations from configured best practices across AWS accounts. mitre_components: -- Cloud Service Metadata -- Cloud Service Enumeration -- Cloud Service Modification -- Cloud Service Disable + - Cloud Service Metadata + - Cloud Service Enumeration + - Cloud Service Modification + - Cloud Service Disable source: aws_securityhub_finding sourcetype: aws:securityhub:finding supported_TA: -- name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 + - name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: -- _time -- AwsAccountId -- CreatedAt -- Description -- FirstObservedAt -- GeneratorId -- Id -- LastObservedAt -- ProductArn -- ProductFields.aws/guardduty/service/action/actionType -- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket -- ProductFields.aws/guardduty/service/action/awsApiCallAction/api -- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType -- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName -- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName -- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat -- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon -- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4 -- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn -- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg -- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp -- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org -- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName -- ProductFields.aws/guardduty/service/additionalInfo/sample -- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_ -- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_ -- ProductFields.aws/guardduty/service/archived -- ProductFields.aws/guardduty/service/count -- ProductFields.aws/guardduty/service/detectorId -- ProductFields.aws/guardduty/service/eventFirstSeen -- ProductFields.aws/guardduty/service/eventLastSeen -- ProductFields.aws/guardduty/service/resourceRole -- ProductFields.aws/guardduty/service/serviceName -- ProductFields.aws/securityhub/CompanyName -- ProductFields.aws/securityhub/FindingId -- ProductFields.aws/securityhub/ProductName -- RecordState -- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn -- Resources{}.Details.AwsEc2Instance.ImageId -- Resources{}.Details.AwsEc2Instance.IpV4Addresses{} -- Resources{}.Details.AwsEc2Instance.LaunchedAt -- Resources{}.Details.AwsEc2Instance.SubnetId -- Resources{}.Details.AwsEc2Instance.Type -- Resources{}.Details.AwsEc2Instance.VpcId -- Resources{}.Details.AwsIamAccessKey.PrincipalId -- Resources{}.Details.AwsIamAccessKey.PrincipalName -- Resources{}.Details.AwsIamAccessKey.PrincipalType -- Resources{}.Details.AwsS3Bucket.CreatedAt -- Resources{}.Details.AwsS3Bucket.OwnerId -- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID -- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm -- Resources{}.Id -- Resources{}.Partition -- Resources{}.Region -- Resources{}.Tags.GeneratedFindingInstaceTag1 -- Resources{}.Tags.GeneratedFindingInstaceTag2 -- Resources{}.Tags.GeneratedFindingInstaceTag3 -- Resources{}.Tags.GeneratedFindingInstaceTag4 -- Resources{}.Tags.GeneratedFindingInstaceTag5 -- Resources{}.Tags.GeneratedFindingInstaceTag6 -- Resources{}.Tags.GeneratedFindingInstaceTag7 -- Resources{}.Tags.GeneratedFindingInstaceTag8 -- Resources{}.Tags.GeneratedFindingInstaceTag9 -- Resources{}.Tags.foo -- Resources{}.Type -- SchemaVersion -- Severity.Label -- Severity.Normalized -- Severity.Product -- SourceUrl -- Title -- Types{} -- UpdatedAt -- Workflow.Status -- WorkflowState -- accesskey_extract -- app -- body -- description -- dest -- dest_type -- eventtype -- host -- id -- index -- instance_extract -- linecount -- punct -- s3bucket_extract -- severity -- severity_id -- signature -- signature_id -- source -- sourcetype -- splunk_server -- subject -- tag -- tag::eventtype -- timestamp -- type -- vendor_account -- vendor_region + - _time + - AwsAccountId + - CreatedAt + - Description + - FirstObservedAt + - GeneratorId + - Id + - LastObservedAt + - ProductArn + - ProductFields.aws/guardduty/service/action/actionType + - ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket + - ProductFields.aws/guardduty/service/action/awsApiCallAction/api + - ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType + - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName + - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName + - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat + - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon + - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4 + - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn + - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg + - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp + - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org + - ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName + - ProductFields.aws/guardduty/service/additionalInfo/sample + - ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_ + - ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_ + - ProductFields.aws/guardduty/service/archived + - ProductFields.aws/guardduty/service/count + - ProductFields.aws/guardduty/service/detectorId + - ProductFields.aws/guardduty/service/eventFirstSeen + - ProductFields.aws/guardduty/service/eventLastSeen + - ProductFields.aws/guardduty/service/resourceRole + - ProductFields.aws/guardduty/service/serviceName + - ProductFields.aws/securityhub/CompanyName + - ProductFields.aws/securityhub/FindingId + - ProductFields.aws/securityhub/ProductName + - RecordState + - Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn + - Resources{}.Details.AwsEc2Instance.ImageId + - Resources{}.Details.AwsEc2Instance.IpV4Addresses{} + - Resources{}.Details.AwsEc2Instance.LaunchedAt + - Resources{}.Details.AwsEc2Instance.SubnetId + - Resources{}.Details.AwsEc2Instance.Type + - Resources{}.Details.AwsEc2Instance.VpcId + - Resources{}.Details.AwsIamAccessKey.PrincipalId + - Resources{}.Details.AwsIamAccessKey.PrincipalName + - Resources{}.Details.AwsIamAccessKey.PrincipalType + - Resources{}.Details.AwsS3Bucket.CreatedAt + - Resources{}.Details.AwsS3Bucket.OwnerId + - Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID + - Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm + - Resources{}.Id + - Resources{}.Partition + - Resources{}.Region + - Resources{}.Tags.GeneratedFindingInstaceTag1 + - Resources{}.Tags.GeneratedFindingInstaceTag2 + - Resources{}.Tags.GeneratedFindingInstaceTag3 + - Resources{}.Tags.GeneratedFindingInstaceTag4 + - Resources{}.Tags.GeneratedFindingInstaceTag5 + - Resources{}.Tags.GeneratedFindingInstaceTag6 + - Resources{}.Tags.GeneratedFindingInstaceTag7 + - Resources{}.Tags.GeneratedFindingInstaceTag8 + - Resources{}.Tags.GeneratedFindingInstaceTag9 + - Resources{}.Tags.foo + - Resources{}.Type + - SchemaVersion + - Severity.Label + - Severity.Normalized + - Severity.Product + - SourceUrl + - Title + - Types{} + - UpdatedAt + - Workflow.Status + - WorkflowState + - accesskey_extract + - app + - body + - description + - dest + - dest_type + - eventtype + - host + - id + - index + - instance_extract + - linecount + - punct + - s3bucket_extract + - severity + - severity_id + - signature + - signature_id + - source + - sourcetype + - splunk_server + - subject + - tag + - tag::eventtype + - timestamp + - type + - vendor_account + - vendor_region example_log: '{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software and Configuration Checks/Exfiltration:S3.ObjectRead.Unusual"],"SourceUrl":"https://us-east-1.console.aws.amazon.com/guardduty/home?region=us-east-1#/findings?macros=current&fId=6aba6b696aea10606e8b336f68d98819","Description":"Principal GeneratedFindingUserName read objects from S3 bucket GeneratedFindingS3Bucket in diff --git a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml index 2afbd8e4ba..b0f85d0cb5 100644 --- a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml +++ b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml @@ -1,97 +1,99 @@ name: Azure Active Directory Add app role assignment to service principal id: 8b2e84cd-6db0-47e9-badc-75c17df1995f -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the addition of an application role assignment to a service principal in Azure Active Directory, including details about the role, service principal, and the user or process performing the action. +description: Logs the addition of an application role assignment to a service principal + in Azure Active Directory, including details about the role, service principal, + and the user or process performing the action. mitre_components: -- User Account Modification -- Group Modification -- Cloud Service Modification -- Cloud Service Metadata + - User Account Modification + - Group Modification + - Cloud Service Modification + - Cloud Service Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Add app role assignment to service principal supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- additional_details -- additional_details_name -- additional_details_value -- category -- command -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_type -- durationMs -- dvc -- eventtype -- host -- id -- identity -- index -- linecount -- object_attrs -- object_id -- operationName -- operationVersion -- path_from_resourceId -- properties.activityDateTime -- properties.activityDisplayName -- properties.additionalDetails{}.key -- properties.additionalDetails{}.value -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.app.appId -- properties.initiatedBy.app.displayName -- properties.initiatedBy.app.servicePrincipalId -- properties.initiatedBy.app.servicePrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.targetResources{}.type -- properties.userAgent -- punct -- resourceId -- result -- resultSignature -- result_id -- signature -- source -- sourcetype -- splunk_server -- src_user_type -- status -- tag -- tag::eventtype -- tenantId -- time -- timeendpos -- timestartpos -- user_agent -- user_type -- vendor_account -- vendor_product + - _time + - Level + - additional_details + - additional_details_name + - additional_details_value + - category + - command + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_type + - durationMs + - dvc + - eventtype + - host + - id + - identity + - index + - linecount + - object_attrs + - object_id + - operationName + - operationVersion + - path_from_resourceId + - properties.activityDateTime + - properties.activityDisplayName + - properties.additionalDetails{}.key + - properties.additionalDetails{}.value + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.app.appId + - properties.initiatedBy.app.displayName + - properties.initiatedBy.app.servicePrincipalId + - properties.initiatedBy.app.servicePrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.targetResources{}.type + - properties.userAgent + - punct + - resourceId + - result + - resultSignature + - result_id + - signature + - source + - sourcetype + - splunk_server + - src_user_type + - status + - tag + - tag::eventtype + - tenantId + - time + - timeendpos + - timestartpos + - user_agent + - user_type + - vendor_account + - vendor_product example_log: '{"time": "2024-02-08T21:49:53.7643129Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam", "operationName": "Add app role assignment to service principal", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml index c2dfa64ecb..8a977d8625 100644 --- a/data_sources/azure_active_directory_add_member_to_role.yml +++ b/data_sources/azure_active_directory_add_member_to_role.yml @@ -1,73 +1,75 @@ name: Azure Active Directory Add member to role id: 1660d196-127f-4678-81b2-472d51711b07 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the addition of a member to a directory role in Azure Active Directory, including details about the role, the member added, and the user or process performing the action. +description: Logs the addition of a member to a directory role in Azure Active Directory, + including details about the role, the member added, and the user or process performing + the action. mitre_components: -- Group Modification -- Group Metadata -- User Account Metadata -- Cloud Service Modification + - Group Modification + - Group Metadata + - User Account Metadata + - Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Add member to role supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.targetResources{}.type -- properties.targetResources{}.userPrincipalName -- properties.userAgent -- punct -- resourceId -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.targetResources{}.type + - properties.targetResources{}.userPrincipalName + - properties.userAgent + - punct + - resourceId + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-04-28T16:39:51.9312625Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Add member to role", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs": diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml index f174ee00b6..70948b2b1f 100644 --- a/data_sources/azure_active_directory_add_owner_to_application.yml +++ b/data_sources/azure_active_directory_add_owner_to_application.yml @@ -1,78 +1,80 @@ name: Azure Active Directory Add owner to application id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the addition of an owner to an application in Azure Active Directory, including details about the application, the owner added, and the user or process performing the action. +description: Logs the addition of an owner to an application in Azure Active Directory, + including details about the application, the owner added, and the user or process + performing the action. mitre_components: -- User Account Modification -- Group Modification -- Cloud Service Modification -- Cloud Service Metadata + - User Account Modification + - Group Modification + - Cloud Service Modification + - Cloud Service Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Add owner to application supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- eventtype -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.additionalDetails{}.key -- properties.additionalDetails{}.value -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.targetResources{}.type -- properties.targetResources{}.userPrincipalName -- properties.userAgent -- punct -- resourceId -- resultSignature -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - eventtype + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.additionalDetails{}.key + - properties.additionalDetails{}.value + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.targetResources{}.type + - properties.targetResources{}.userPrincipalName + - properties.userAgent + - punct + - resourceId + - resultSignature + - source + - sourcetype + - splunk_server + - tag + - tag::eventtype + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-06-20T15:54:13.2420879Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Add owner to application", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml index d100855262..46f3c3d7d9 100644 --- a/data_sources/azure_active_directory_add_service_principal.yml +++ b/data_sources/azure_active_directory_add_service_principal.yml @@ -1,73 +1,75 @@ name: Azure Active Directory Add service principal id: fd89d337-e4c0-4162-ad13-bca36f096fe6 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of a new service principal in Azure Active Directory, including details about the service principal, associated application, and the user or process performing the action. +description: Logs the creation of a new service principal in Azure Active Directory, + including details about the service principal, associated application, and the user + or process performing the action. mitre_components: -- Cloud Service Creation -- Cloud Service Metadata -- User Account Metadata -- Active Directory Object Creation + - Cloud Service Creation + - Cloud Service Metadata + - User Account Metadata + - Active Directory Object Creation source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Add service principal supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.additionalDetails{}.key -- properties.additionalDetails{}.value -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.targetResources{}.type -- properties.userAgent -- punct -- resourceId -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.additionalDetails{}.key + - properties.additionalDetails{}.value + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.targetResources{}.type + - properties.userAgent + - punct + - resourceId + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2024-02-07T22:31:14.4970418Z", "resourceId": "/tenants/a417c578-c7ee-480d-a225-d48057e74df5/providers/Microsoft.aadiam", "operationName": "Add service principal", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "a417c578-c7ee-480d-a225-d48057e74df5", "resultSignature": diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml index 1b06002e40..444d3e1a6f 100644 --- a/data_sources/azure_active_directory_add_unverified_domain.yml +++ b/data_sources/azure_active_directory_add_unverified_domain.yml @@ -1,73 +1,74 @@ name: Azure Active Directory Add unverified domain id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the addition of an unverified domain to Azure Active Directory, including details about the domain name and the user or process performing the action. +description: Logs the addition of an unverified domain to Azure Active Directory, + including details about the domain name and the user or process performing the action. mitre_components: -- Domain Registration -- Cloud Service Modification -- Cloud Service Metadata -- Configuration Modification + - Domain Registration + - Cloud Service Modification + - Cloud Service Metadata + - Configuration Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Add unverified domain supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.additionalDetails{}.key -- properties.additionalDetails{}.value -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.userAgent -- punct -- resourceId -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.additionalDetails{}.key + - properties.additionalDetails{}.value + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.userAgent + - punct + - resourceId + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-07-26T13:45:54.1582053Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Add unverified domain", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml index cc0ee34156..4222ab6a7c 100644 --- a/data_sources/azure_active_directory_consent_to_application.yml +++ b/data_sources/azure_active_directory_consent_to_application.yml @@ -1,78 +1,80 @@ name: Azure Active Directory Consent to application id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs user or admin consent to an application's permissions in Azure Active Directory, including details about the application, granted permissions, and the consenting user or process. +description: Logs user or admin consent to an application's permissions in Azure Active + Directory, including details about the application, granted permissions, and the + consenting user or process. mitre_components: -- User Account Modification -- Cloud Service Modification -- Cloud Service Metadata -- Configuration Modification + - User Account Modification + - Cloud Service Modification + - Cloud Service Metadata + - Configuration Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Consent to application supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- eventtype -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.additionalDetails{}.key -- properties.additionalDetails{}.value -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.targetResources{}.type -- properties.userAgent -- punct -- resourceId -- resultDescription -- resultSignature -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - eventtype + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.additionalDetails{}.key + - properties.additionalDetails{}.value + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.targetResources{}.type + - properties.userAgent + - punct + - resourceId + - resultDescription + - resultSignature + - source + - sourcetype + - splunk_server + - tag + - tag::eventtype + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-10-27T16:14:14.9747033Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam", "operationName": "Consent to application", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature": diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml index c32bf6b639..6c329d8872 100644 --- a/data_sources/azure_active_directory_disable_strong_authentication.yml +++ b/data_sources/azure_active_directory_disable_strong_authentication.yml @@ -1,71 +1,72 @@ name: Azure Active Directory Disable Strong Authentication id: 8f31966d-c496-496d-8837-f7fd11f31255 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when strong authentication methods are disabled in Azure Active Directory. +description: Logs an event when strong authentication methods are disabled in Azure + Active Directory. mitre_components: -- User Account Authentication -- User Account Modification -- Cloud Service Modification + - User Account Authentication + - User Account Modification + - Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Disable Strong Authentication supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.targetResources{}.type -- properties.targetResources{}.userPrincipalName -- properties.userAgent -- punct -- resourceId -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.targetResources{}.type + - properties.targetResources{}.userPrincipalName + - properties.userAgent + - punct + - resourceId + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-07-11T00:01:35.0251899Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Disable Strong Authentication", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml index d335c79ffc..2e3380277d 100644 --- a/data_sources/azure_active_directory_enable_account.yml +++ b/data_sources/azure_active_directory_enable_account.yml @@ -1,72 +1,72 @@ name: Azure Active Directory Enable account id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Active Directory account is enabled. mitre_components: -- User Account Modification -- User Account Authentication -- User Account Metadata + - User Account Modification + - User Account Authentication + - User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Enable account supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.targetResources{}.type -- properties.targetResources{}.userPrincipalName -- properties.userAgent -- punct -- resourceId -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.targetResources{}.type + - properties.targetResources{}.userPrincipalName + - properties.userAgent + - punct + - resourceId + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-07-24T14:28:15.2223487Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Enable account", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs": diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml index d7cb59bbba..08726897f3 100644 --- a/data_sources/azure_active_directory_invite_external_user.yml +++ b/data_sources/azure_active_directory_invite_external_user.yml @@ -1,71 +1,72 @@ name: Azure Active Directory Invite external user id: d3818bd5-f283-4518-8b67-df19240c3e40 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when an external user is invited to join an Azure Active Directory tenant. +description: Logs an event when an external user is invited to join an Azure Active + Directory tenant. mitre_components: -- Active Directory Object Creation -- User Account Creation -- User Account Authentication + - Active Directory Object Creation + - User Account Creation + - User Account Authentication source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Invite external user supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.additionalDetails{}.key -- properties.additionalDetails{}.value -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.type -- properties.targetResources{}.userPrincipalName -- properties.userAgent -- punct -- resourceId -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.additionalDetails{}.key + - properties.additionalDetails{}.value + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.type + - properties.targetResources{}.userPrincipalName + - properties.userAgent + - punct + - resourceId + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-07-13T00:29:59.5100003Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Invite external user", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml index 9c4db01f1f..54208cb250 100644 --- a/data_sources/azure_active_directory_reset_password_(by_admin).yml +++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml @@ -1,72 +1,73 @@ name: Azure Active Directory Reset password (by admin) id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when an admin resets a user's password in Azure Active Directory. +description: Logs an event when an admin resets a user's password in Azure Active + Directory. mitre_components: -- User Account Authentication -- User Account Modification -- Active Directory Object Modification + - User Account Authentication + - User Account Modification + - Active Directory Object Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Reset password (by admin) supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.additionalDetails{}.key -- properties.additionalDetails{}.value -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.type -- properties.targetResources{}.userPrincipalName -- properties.userAgent -- punct -- resourceId -- resultDescription -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.additionalDetails{}.key + - properties.additionalDetails{}.value + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.type + - properties.targetResources{}.userPrincipalName + - properties.userAgent + - punct + - resourceId + - resultDescription + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-07-24T14:28:55.0648789Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Reset password (by admin)", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml index c20d10043c..c29183d14e 100644 --- a/data_sources/azure_active_directory_set_domain_authentication.yml +++ b/data_sources/azure_active_directory_set_domain_authentication.yml @@ -1,72 +1,73 @@ name: Azure Active Directory Set domain authentication id: e7bcdab9-908c-40ab-ba38-5db54fa87750 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when the authentication method for a domain in Azure Active Directory is set or modified. +description: Logs an event when the authentication method for a domain in Azure Active + Directory is set or modified. mitre_components: -- Active Directory Object Modification -- User Account Authentication -- Cloud Service Modification + - Active Directory Object Modification + - User Account Authentication + - Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Set domain authentication supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.additionalDetails{}.key -- properties.additionalDetails{}.value -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.userAgent -- punct -- resourceId -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.additionalDetails{}.key + - properties.additionalDetails{}.value + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.userAgent + - punct + - resourceId + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-07-26T13:44:59.0372448Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Set domain authentication", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml index 3fca810c95..d5ed7fa94d 100644 --- a/data_sources/azure_active_directory_sign_in_activity.yml +++ b/data_sources/azure_active_directory_sign_in_activity.yml @@ -1,122 +1,123 @@ name: Azure Active Directory Sign-in activity id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a user attempts to sign into Azure Active Directory, capturing authentication details and outcomes. +description: Logs an event when a user attempts to sign into Azure Active Directory, + capturing authentication details and outcomes. mitre_components: -- User Account Authentication -- Logon Session Creation -- User Account Metadata + - User Account Authentication + - Logon Session Creation + - User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Sign-in activity supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- identity -- index -- linecount -- location -- operationName -- operationVersion -- properties.alternateSignInName -- properties.appDisplayName -- properties.appId -- properties.appServicePrincipalId -- properties.authenticationDetails{}.RequestSequence -- properties.authenticationDetails{}.StatusSequence -- properties.authenticationDetails{}.authenticationMethod -- properties.authenticationDetails{}.authenticationMethodDetail -- properties.authenticationDetails{}.authenticationStepDateTime -- properties.authenticationDetails{}.authenticationStepRequirement -- properties.authenticationDetails{}.authenticationStepResultDetail -- properties.authenticationDetails{}.succeeded -- properties.authenticationProcessingDetails{}.key -- properties.authenticationProcessingDetails{}.value -- properties.authenticationProtocol -- properties.authenticationRequirement -- properties.authenticationRequirementPolicies{}.detail -- properties.authenticationRequirementPolicies{}.requirementProvider -- properties.autonomousSystemNumber -- properties.clientAppUsed -- properties.clientCredentialType -- properties.conditionalAccessStatus -- properties.correlationId -- properties.createdDateTime -- properties.crossTenantAccessType -- properties.deviceDetail.deviceId -- properties.deviceDetail.operatingSystem -- properties.flaggedForReview -- properties.homeTenantId -- properties.id -- properties.incomingTokenType -- properties.ipAddress -- properties.isInteractive -- properties.isTenantRestricted -- properties.location.city -- properties.location.countryOrRegion -- properties.location.geoCoordinates.latitude -- properties.location.geoCoordinates.longitude -- properties.location.state -- properties.originalRequestId -- properties.originalTransferMethod -- properties.processingTimeInMilliseconds -- properties.resourceDisplayName -- properties.resourceId -- properties.resourceServicePrincipalId -- properties.resourceTenantId -- properties.riskDetail -- properties.riskLevelAggregated -- properties.riskLevelDuringSignIn -- properties.riskState -- properties.rngcStatus -- properties.servicePrincipalId -- properties.signInIdentifier -- properties.signInTokenProtectionStatus -- properties.ssoExtensionVersion -- properties.status.additionalDetails -- properties.status.errorCode -- properties.status.failureReason -- properties.tenantId -- properties.tokenIssuerName -- properties.tokenIssuerType -- properties.uniqueTokenIdentifier -- properties.userAgent -- properties.userDisplayName -- properties.userId -- properties.userPrincipalName -- properties.userType -- punct -- resourceId -- resultDescription -- resultSignature -- resultType -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - identity + - index + - linecount + - location + - operationName + - operationVersion + - properties.alternateSignInName + - properties.appDisplayName + - properties.appId + - properties.appServicePrincipalId + - properties.authenticationDetails{}.RequestSequence + - properties.authenticationDetails{}.StatusSequence + - properties.authenticationDetails{}.authenticationMethod + - properties.authenticationDetails{}.authenticationMethodDetail + - properties.authenticationDetails{}.authenticationStepDateTime + - properties.authenticationDetails{}.authenticationStepRequirement + - properties.authenticationDetails{}.authenticationStepResultDetail + - properties.authenticationDetails{}.succeeded + - properties.authenticationProcessingDetails{}.key + - properties.authenticationProcessingDetails{}.value + - properties.authenticationProtocol + - properties.authenticationRequirement + - properties.authenticationRequirementPolicies{}.detail + - properties.authenticationRequirementPolicies{}.requirementProvider + - properties.autonomousSystemNumber + - properties.clientAppUsed + - properties.clientCredentialType + - properties.conditionalAccessStatus + - properties.correlationId + - properties.createdDateTime + - properties.crossTenantAccessType + - properties.deviceDetail.deviceId + - properties.deviceDetail.operatingSystem + - properties.flaggedForReview + - properties.homeTenantId + - properties.id + - properties.incomingTokenType + - properties.ipAddress + - properties.isInteractive + - properties.isTenantRestricted + - properties.location.city + - properties.location.countryOrRegion + - properties.location.geoCoordinates.latitude + - properties.location.geoCoordinates.longitude + - properties.location.state + - properties.originalRequestId + - properties.originalTransferMethod + - properties.processingTimeInMilliseconds + - properties.resourceDisplayName + - properties.resourceId + - properties.resourceServicePrincipalId + - properties.resourceTenantId + - properties.riskDetail + - properties.riskLevelAggregated + - properties.riskLevelDuringSignIn + - properties.riskState + - properties.rngcStatus + - properties.servicePrincipalId + - properties.signInIdentifier + - properties.signInTokenProtectionStatus + - properties.ssoExtensionVersion + - properties.status.additionalDetails + - properties.status.errorCode + - properties.status.failureReason + - properties.tenantId + - properties.tokenIssuerName + - properties.tokenIssuerType + - properties.uniqueTokenIdentifier + - properties.userAgent + - properties.userDisplayName + - properties.userId + - properties.userPrincipalName + - properties.userType + - punct + - resourceId + - resultDescription + - resultSignature + - resultType + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-10-24T20:13:31.4449614Z", "resourceId": "/tenants/887c9144-28b8-431b-885b-764fdeefcf62/providers/Microsoft.aadiam", "operationName": "Sign-in activity", "operationVersion": "1.0", "category": "SignInLogs", "tenantId": "887c9144-28b8-431b-885b-764fdeefcf62", "resultType": "50076", "resultSignature": diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml index cc9da95340..fe57e659f8 100644 --- a/data_sources/azure_active_directory_update_application.yml +++ b/data_sources/azure_active_directory_update_application.yml @@ -1,72 +1,73 @@ name: Azure Active Directory Update application id: 2c08188a-ba25-496e-87c7-803cf28b6c90 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when an application in Azure Active Directory is updated, such as changes to its settings or permissions. +description: Logs an event when an application in Azure Active Directory is updated, + such as changes to its settings or permissions. mitre_components: -- Service Modification -- User Account Modification -- Cloud Service Modification + - Service Modification + - User Account Modification + - Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Update application supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.additionalDetails{}.key -- properties.additionalDetails{}.value -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.targetResources{}.type -- properties.userAgent -- punct -- resourceId -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.additionalDetails{}.key + - properties.additionalDetails{}.value + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.targetResources{}.type + - properties.userAgent + - punct + - resourceId + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2024-01-29T21:31:03.0102031Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam", "operationName": "Update application", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature": "None", "durationMs": diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml index 37b2c7c4be..34e141f92e 100644 --- a/data_sources/azure_active_directory_update_authorization_policy.yml +++ b/data_sources/azure_active_directory_update_authorization_policy.yml @@ -1,73 +1,74 @@ name: Azure Active Directory Update authorization policy id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when an authorization policy is updated in Azure Active Directory. +description: Logs an event when an authorization policy is updated in Azure Active + Directory. mitre_components: -- User Account Modification -- Group Modification -- Active Directory Object Modification + - User Account Modification + - Group Modification + - Active Directory Object Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Update authorization policy supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.additionalDetails{}.key -- properties.additionalDetails{}.value -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.targetResources{}.type -- properties.userAgent -- punct -- resourceId -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.additionalDetails{}.key + - properties.additionalDetails{}.value + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.targetResources{}.type + - properties.userAgent + - punct + - resourceId + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-10-26T19:22:20.2814027Z", "resourceId": "/tenants/5f210575-a69b-41a7-b623-3f6d79ccd432/providers/Microsoft.aadiam", "operationName": "Update authorization policy", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "5f210575-a69b-41a7-b623-3f6d79ccd432", "resultSignature": diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml index a37a792233..3bc111e209 100644 --- a/data_sources/azure_active_directory_update_user.yml +++ b/data_sources/azure_active_directory_update_user.yml @@ -1,73 +1,73 @@ name: Azure Active Directory Update user id: 5495c90a-047c-4b8e-b2fe-1db6282d3872 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a user account is updated in Azure Active Directory. mitre_components: -- User Account Modification -- User Account Metadata + - User Account Modification + - User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Update user supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.additionalDetails{}.key -- properties.additionalDetails{}.value -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.modifiedProperties{}.displayName -- properties.targetResources{}.modifiedProperties{}.newValue -- properties.targetResources{}.modifiedProperties{}.oldValue -- properties.targetResources{}.type -- properties.targetResources{}.userPrincipalName -- properties.userAgent -- punct -- resourceId -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.additionalDetails{}.key + - properties.additionalDetails{}.value + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.modifiedProperties{}.displayName + - properties.targetResources{}.modifiedProperties{}.newValue + - properties.targetResources{}.modifiedProperties{}.oldValue + - properties.targetResources{}.type + - properties.targetResources{}.userPrincipalName + - properties.userAgent + - punct + - resourceId + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-07-24T14:28:15.2233481Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Update user", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs": diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml index ae651e960d..db1c5af928 100644 --- a/data_sources/azure_active_directory_user_registered_security_info.yml +++ b/data_sources/azure_active_directory_user_registered_security_info.yml @@ -1,69 +1,70 @@ name: Azure Active Directory User registered security info id: b63240de-8a01-4ba8-8987-89d18d4b375d -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a user registers or updates their security information in Azure Active Directory. +description: Logs an event when a user registers or updates their security information + in Azure Active Directory. mitre_components: -- User Account Modification -- User Account Metadata + - User Account Modification + - User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: User registered security info supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- Level -- callerIpAddress -- category -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- durationMs -- host -- index -- linecount -- operationName -- operationVersion -- properties.activityDateTime -- properties.activityDisplayName -- properties.category -- properties.correlationId -- properties.id -- properties.initiatedBy.user.displayName -- properties.initiatedBy.user.id -- properties.initiatedBy.user.ipAddress -- properties.initiatedBy.user.userPrincipalName -- properties.loggedByService -- properties.operationType -- properties.result -- properties.resultReason -- properties.targetResources{}.displayName -- properties.targetResources{}.id -- properties.targetResources{}.type -- properties.targetResources{}.userPrincipalName -- properties.userAgent -- punct -- resourceId -- resultDescription -- resultSignature -- source -- sourcetype -- splunk_server -- tenantId -- time -- timeendpos -- timestartpos + - _time + - Level + - callerIpAddress + - category + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - durationMs + - host + - index + - linecount + - operationName + - operationVersion + - properties.activityDateTime + - properties.activityDisplayName + - properties.category + - properties.correlationId + - properties.id + - properties.initiatedBy.user.displayName + - properties.initiatedBy.user.id + - properties.initiatedBy.user.ipAddress + - properties.initiatedBy.user.userPrincipalName + - properties.loggedByService + - properties.operationType + - properties.result + - properties.resultReason + - properties.targetResources{}.displayName + - properties.targetResources{}.id + - properties.targetResources{}.type + - properties.targetResources{}.userPrincipalName + - properties.userAgent + - punct + - resourceId + - resultDescription + - resultSignature + - source + - sourcetype + - splunk_server + - tenantId + - time + - timeendpos + - timestartpos example_log: '{"time": "2023-01-30T21:11:30.8690619Z", "resourceId": "/tenants/91da745f-8abb-4a7d-ba94-5667c6f9e01a/providers/Microsoft.aadiam", "operationName": "User registered security info", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "91da745f-8abb-4a7d-ba94-5667c6f9e01a", "resultSignature": diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml index 290688b816..d16b39fe67 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml @@ -1,110 +1,110 @@ name: Azure Audit Create or Update an Azure Automation account id: 2ab182e7-feda-4249-9418-32710b55a885 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Automation account is created or updated. mitre_components: -- Cloud Service Creation -- Cloud Service Modification -- Cloud Service Metadata + - Cloud Service Creation + - Cloud Service Modification + - Cloud Service Metadata source: mscs:azure:audit sourcetype: mscs:azure:audit separator: operationName.localizedValue separator_value: Create or Update an Azure Automation account supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- authorization.action -- authorization.scope -- caller -- channels -- claims.aio -- claims.altsecid -- claims.appid -- claims.appidacr -- claims.aud -- claims.exp -- claims.groups -- claims.http://schemas.microsoft.com/claims/authnclassreference -- claims.http://schemas.microsoft.com/claims/authnmethodsreferences -- claims.http://schemas.microsoft.com/identity/claims/identityprovider -- claims.http://schemas.microsoft.com/identity/claims/objectidentifier -- claims.http://schemas.microsoft.com/identity/claims/scope -- claims.http://schemas.microsoft.com/identity/claims/tenantid -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname -- claims.iat -- claims.ipaddr -- claims.iss -- claims.name -- claims.nbf -- claims.puid -- claims.rh -- claims.uti -- claims.ver -- claims.wids -- claims.xms_tcdt -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- eventDataId -- eventName.localizedValue -- eventName.value -- eventSource.localizedValue -- eventSource.value -- eventTimestamp -- host -- id -- index -- level -- linecount -- object -- object_id -- object_path -- operationId -- operationName.localizedValue -- operationName.value -- product -- properties.entity -- properties.eventCategory -- properties.hierarchy -- properties.message -- punct -- resourceGroupName -- resourceProviderName.localizedValue -- resourceProviderName.value -- resourceUri -- source -- sourcetype -- splunk_server -- status -- status.localizedValue -- status.value -- subStatus.value -- submissionTimestamp -- subscriptionId -- timeendpos -- timestartpos -- user -- user_name -- vendor -- vendor_product -- vendor_res_code + - _time + - authorization.action + - authorization.scope + - caller + - channels + - claims.aio + - claims.altsecid + - claims.appid + - claims.appidacr + - claims.aud + - claims.exp + - claims.groups + - claims.http://schemas.microsoft.com/claims/authnclassreference + - claims.http://schemas.microsoft.com/claims/authnmethodsreferences + - claims.http://schemas.microsoft.com/identity/claims/identityprovider + - claims.http://schemas.microsoft.com/identity/claims/objectidentifier + - claims.http://schemas.microsoft.com/identity/claims/scope + - claims.http://schemas.microsoft.com/identity/claims/tenantid + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname + - claims.iat + - claims.ipaddr + - claims.iss + - claims.name + - claims.nbf + - claims.puid + - claims.rh + - claims.uti + - claims.ver + - claims.wids + - claims.xms_tcdt + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - eventDataId + - eventName.localizedValue + - eventName.value + - eventSource.localizedValue + - eventSource.value + - eventTimestamp + - host + - id + - index + - level + - linecount + - object + - object_id + - object_path + - operationId + - operationName.localizedValue + - operationName.value + - product + - properties.entity + - properties.eventCategory + - properties.hierarchy + - properties.message + - punct + - resourceGroupName + - resourceProviderName.localizedValue + - resourceProviderName.value + - resourceUri + - source + - sourcetype + - splunk_server + - status + - status.localizedValue + - status.value + - subStatus.value + - submissionTimestamp + - subscriptionId + - timeendpos + - timestartpos + - user + - user_name + - vendor + - vendor_product + - vendor_res_code example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/write", "scope": "/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount"}, "caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/", diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml index e7ee46661a..8522e7ab79 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml @@ -1,109 +1,110 @@ name: Azure Audit Create or Update an Azure Automation Runbook id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a new Azure Automation Runbook is created or an existing one is updated. +description: Logs an event when a new Azure Automation Runbook is created or an existing + one is updated. mitre_components: -- Scheduled Job Modification -- Scheduled Job Creation + - Scheduled Job Modification + - Scheduled Job Creation source: mscs:azure:audit sourcetype: mscs:azure:audit separator: operationName.localizedValue separator_value: Create or Update an Azure Automation Runbook supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- authorization.action -- authorization.scope -- caller -- channels -- claims.aio -- claims.altsecid -- claims.appid -- claims.appidacr -- claims.aud -- claims.exp -- claims.groups -- claims.http://schemas.microsoft.com/claims/authnclassreference -- claims.http://schemas.microsoft.com/claims/authnmethodsreferences -- claims.http://schemas.microsoft.com/identity/claims/identityprovider -- claims.http://schemas.microsoft.com/identity/claims/objectidentifier -- claims.http://schemas.microsoft.com/identity/claims/scope -- claims.http://schemas.microsoft.com/identity/claims/tenantid -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname -- claims.iat -- claims.ipaddr -- claims.iss -- claims.name -- claims.nbf -- claims.puid -- claims.rh -- claims.uti -- claims.ver -- claims.wids -- claims.xms_tcdt -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- eventDataId -- eventName.localizedValue -- eventName.value -- eventSource.localizedValue -- eventSource.value -- eventTimestamp -- host -- id -- index -- level -- linecount -- object -- object_id -- object_path -- operationId -- operationName.localizedValue -- operationName.value -- product -- properties.entity -- properties.eventCategory -- properties.hierarchy -- properties.message -- punct -- resourceGroupName -- resourceProviderName.localizedValue -- resourceProviderName.value -- resourceUri -- source -- sourcetype -- splunk_server -- status -- status.localizedValue -- status.value -- subStatus.value -- submissionTimestamp -- subscriptionId -- timeendpos -- timestartpos -- user -- user_name -- vendor -- vendor_product -- vendor_res_code + - _time + - authorization.action + - authorization.scope + - caller + - channels + - claims.aio + - claims.altsecid + - claims.appid + - claims.appidacr + - claims.aud + - claims.exp + - claims.groups + - claims.http://schemas.microsoft.com/claims/authnclassreference + - claims.http://schemas.microsoft.com/claims/authnmethodsreferences + - claims.http://schemas.microsoft.com/identity/claims/identityprovider + - claims.http://schemas.microsoft.com/identity/claims/objectidentifier + - claims.http://schemas.microsoft.com/identity/claims/scope + - claims.http://schemas.microsoft.com/identity/claims/tenantid + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname + - claims.iat + - claims.ipaddr + - claims.iss + - claims.name + - claims.nbf + - claims.puid + - claims.rh + - claims.uti + - claims.ver + - claims.wids + - claims.xms_tcdt + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - eventDataId + - eventName.localizedValue + - eventName.value + - eventSource.localizedValue + - eventSource.value + - eventTimestamp + - host + - id + - index + - level + - linecount + - object + - object_id + - object_path + - operationId + - operationName.localizedValue + - operationName.value + - product + - properties.entity + - properties.eventCategory + - properties.hierarchy + - properties.message + - punct + - resourceGroupName + - resourceProviderName.localizedValue + - resourceProviderName.value + - resourceUri + - source + - sourcetype + - splunk_server + - status + - status.localizedValue + - status.value + - subStatus.value + - submissionTimestamp + - subscriptionId + - timeendpos + - timestartpos + - user + - user_name + - vendor + - vendor_product + - vendor_res_code example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/runbooks/write", "scope": "/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourceGroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook"}, "caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/", diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml index 584e44aaff..eb21ed90a8 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml @@ -1,119 +1,119 @@ name: Azure Audit Create or Update an Azure Automation webhook id: 575faeb2-09d0-4849-b1f6-eae241f26ff2 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a webhook is created or updated in Azure Automation. mitre_components: -- Scheduled Job Modification -- Cloud Service Modification -- Scheduled Job Metadata + - Scheduled Job Modification + - Cloud Service Modification + - Scheduled Job Metadata source: mscs:azure:audit sourcetype: mscs:azure:audit separator: operationName.localizedValue separator_value: Create or Update an Azure Automation webhook supported_TA: -- name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 + - name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: -- _time -- authorization.action -- authorization.scope -- caller -- channels -- claims.aio -- claims.altsecid -- claims.appid -- claims.appidacr -- claims.aud -- claims.exp -- claims.groups -- claims.http://schemas.microsoft.com/claims/authnclassreference -- claims.http://schemas.microsoft.com/claims/authnmethodsreferences -- claims.http://schemas.microsoft.com/identity/claims/identityprovider -- claims.http://schemas.microsoft.com/identity/claims/objectidentifier -- claims.http://schemas.microsoft.com/identity/claims/scope -- claims.http://schemas.microsoft.com/identity/claims/tenantid -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier -- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname -- claims.iat -- claims.ipaddr -- claims.iss -- claims.name -- claims.nbf -- claims.puid -- claims.rh -- claims.uti -- claims.ver -- claims.wids -- claims.xms_tcdt -- correlationId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- eventDataId -- eventName.localizedValue -- eventName.value -- eventSource.localizedValue -- eventSource.value -- eventTimestamp -- host -- httpRequest.clientIpAddress -- httpRequest.clientRequestId -- httpRequest.method -- id -- index -- level -- linecount -- object -- object_id -- object_path -- operationId -- operationName.localizedValue -- operationName.value -- product -- properties.entity -- properties.eventCategory -- properties.hierarchy -- properties.message -- properties.serviceRequestId -- properties.statusCode -- punct -- resourceGroupName -- resourceProviderName.localizedValue -- resourceProviderName.value -- resourceUri -- result -- result_id -- source -- sourcetype -- splunk_server -- src -- status -- status.localizedValue -- status.value -- subStatus.localizedValue -- subStatus.value -- submissionTimestamp -- subscriptionId -- timeendpos -- timestartpos -- user -- user_name -- vendor -- vendor_product -- vendor_res_code + - _time + - authorization.action + - authorization.scope + - caller + - channels + - claims.aio + - claims.altsecid + - claims.appid + - claims.appidacr + - claims.aud + - claims.exp + - claims.groups + - claims.http://schemas.microsoft.com/claims/authnclassreference + - claims.http://schemas.microsoft.com/claims/authnmethodsreferences + - claims.http://schemas.microsoft.com/identity/claims/identityprovider + - claims.http://schemas.microsoft.com/identity/claims/objectidentifier + - claims.http://schemas.microsoft.com/identity/claims/scope + - claims.http://schemas.microsoft.com/identity/claims/tenantid + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier + - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname + - claims.iat + - claims.ipaddr + - claims.iss + - claims.name + - claims.nbf + - claims.puid + - claims.rh + - claims.uti + - claims.ver + - claims.wids + - claims.xms_tcdt + - correlationId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - eventDataId + - eventName.localizedValue + - eventName.value + - eventSource.localizedValue + - eventSource.value + - eventTimestamp + - host + - httpRequest.clientIpAddress + - httpRequest.clientRequestId + - httpRequest.method + - id + - index + - level + - linecount + - object + - object_id + - object_path + - operationId + - operationName.localizedValue + - operationName.value + - product + - properties.entity + - properties.eventCategory + - properties.hierarchy + - properties.message + - properties.serviceRequestId + - properties.statusCode + - punct + - resourceGroupName + - resourceProviderName.localizedValue + - resourceProviderName.value + - resourceUri + - result + - result_id + - source + - sourcetype + - splunk_server + - src + - status + - status.localizedValue + - status.value + - subStatus.localizedValue + - subStatus.value + - submissionTimestamp + - subscriptionId + - timeendpos + - timestartpos + - user + - user_name + - vendor + - vendor_product + - vendor_res_code example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/webhooks/write", "scope": "/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook"}, "caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/", diff --git a/data_sources/bro_conn.yml b/data_sources/bro_conn.yml index d4ed14b382..992da75275 100644 --- a/data_sources/bro_conn.yml +++ b/data_sources/bro_conn.yml @@ -1,14 +1,15 @@ name: Bro conn id: c5a7e93b-2172-45a7-a7e9-3b217255a7f5 -version: 1 -date: '2025-20-01' +version: 2 +date: '2025-01-23' author: Jacob Delgado, SnapAttack -description: Logs network connection metadata captured by Zeek (formerly Bro), including details such as source and destination IPs, ports, connection state, and protocol. +description: Logs network connection metadata captured by Zeek (formerly Bro), including + details such as source and destination IPs, ports, connection state, and protocol. mitre_components: -- Network Connection Creation -- Network Traffic Flow -- Response Metadata -- Application Log Content + - Network Connection Creation + - Network Traffic Flow + - Response Metadata + - Application Log Content source: bro:conn:json sourcetype: bro:conn:json supported_TA: [] diff --git a/data_sources/bro_dns.yml b/data_sources/bro_dns.yml index 2b7cf87568..7d878c681b 100644 --- a/data_sources/bro_dns.yml +++ b/data_sources/bro_dns.yml @@ -1,15 +1,16 @@ name: Bro dns id: a4576cbf-06cc-4ed0-976c-bf06ccaed011 -version: 1 -date: '2025-20-01' +version: 2 +date: '2025-01-23' author: Jacob Delgado, SnapAttack -description: Logs DNS queries and responses captured by Zeek (formerly Bro), including details such as queried domains, resolved IPs, query types, and response codes. +description: Logs DNS queries and responses captured by Zeek (formerly Bro), including + details such as queried domains, resolved IPs, query types, and response codes. mitre_components: -- Active DNS -- Passive DNS -- Network Traffic Content -- Network Traffic Flow -- Response Metadata + - Active DNS + - Passive DNS + - Network Traffic Content + - Network Traffic Flow + - Response Metadata source: bro:dns:json sourcetype: bro:dns:json supported_TA: [] diff --git a/data_sources/bro_files.yml b/data_sources/bro_files.yml index b8b0f83dc8..4cb84af9fa 100644 --- a/data_sources/bro_files.yml +++ b/data_sources/bro_files.yml @@ -1,15 +1,17 @@ name: Bro files id: f72d34d0-3495-4826-ad34-d03495782633 -version: 1 -date: '2025-20-01' +version: 2 +date: '2025-01-23' author: Jacob Delgado, SnapAttack -description: Logs metadata about files transferred over the network captured by Zeek (formerly Bro), including details such as file names, hashes, MIME types, and transfer protocols. +description: Logs metadata about files transferred over the network captured by Zeek + (formerly Bro), including details such as file names, hashes, MIME types, and transfer + protocols. mitre_components: -- File Metadata -- Network Traffic Content -- Network Traffic Flow -- Response Metadata -- Application Log Content + - File Metadata + - Network Traffic Content + - Network Traffic Flow + - Response Metadata + - Application Log Content source: bro:files:json sourcetype: bro:files:json supported_TA: [] diff --git a/data_sources/bro_http.yml b/data_sources/bro_http.yml index f0e879954e..59232b529e 100644 --- a/data_sources/bro_http.yml +++ b/data_sources/bro_http.yml @@ -1,15 +1,16 @@ name: Bro http id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2 -version: 2 -date: '2024-07-18' +version: 3 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs HTTP traffic analyzed by Zeek (formerly Bro), including details such as request methods, URLs, user agents, response codes, and headers. +description: Logs HTTP traffic analyzed by Zeek (formerly Bro), including details + such as request methods, URLs, user agents, response codes, and headers. mitre_components: -- Network Traffic Content -- Network Traffic Flow -- Response Content -- Response Metadata -- Application Log Content + - Network Traffic Content + - Network Traffic Flow + - Response Content + - Response Metadata + - Application Log Content source: bro:http:json sourcetype: bro:http:json supported_TA: [] diff --git a/data_sources/bro_loaded_scripts.yml b/data_sources/bro_loaded_scripts.yml index e6f2764604..be17c3a7e1 100644 --- a/data_sources/bro_loaded_scripts.yml +++ b/data_sources/bro_loaded_scripts.yml @@ -1,14 +1,15 @@ name: Bro loaded_scripts id: 81e08a21-a735-42b1-a08a-21a73582b1bf -version: 1 -date: '2025-20-01' +version: 2 +date: '2025-01-23' author: Jacob Delgado, SnapAttack -description: Logs details about the scripts loaded by Zeek (formerly Bro) during initialization, including script names and paths. +description: Logs details about the scripts loaded by Zeek (formerly Bro) during initialization, + including script names and paths. mitre_components: -- Application Log Content -- Configuration Modification -- Script Execution -- OS API Execution + - Application Log Content + - Configuration Modification + - Script Execution + - OS API Execution source: bro:loaded_scripts:json sourcetype: bro:loaded_scripts:json supported_TA: [] diff --git a/data_sources/bro_ntp.yml b/data_sources/bro_ntp.yml index 15ea709585..b849d5d5db 100644 --- a/data_sources/bro_ntp.yml +++ b/data_sources/bro_ntp.yml @@ -1,14 +1,15 @@ name: Bro ntp id: 3f64a544-47a4-4958-a4a5-4447a47958df -version: 1 -date: '2025-20-01' +version: 2 +date: '2025-01-23' author: Jacob Delgado, SnapAttack -description: Logs Network Time Protocol (NTP) activity captured by Zeek (formerly Bro), including details such as NTP requests, responses, and server metadata. +description: Logs Network Time Protocol (NTP) activity captured by Zeek (formerly + Bro), including details such as NTP requests, responses, and server metadata. mitre_components: -- Network Traffic Flow -- Network Traffic Content -- Response Metadata -- Application Log Content + - Network Traffic Flow + - Network Traffic Content + - Response Metadata + - Application Log Content source: bro:ntp:json sourcetype: bro:ntp:json supported_TA: [] diff --git a/data_sources/bro_ocsp.yml b/data_sources/bro_ocsp.yml index c0da63d49e..00e8942e83 100644 --- a/data_sources/bro_ocsp.yml +++ b/data_sources/bro_ocsp.yml @@ -1,15 +1,16 @@ name: Bro ocsp id: d20909ab-70be-409a-8909-ab70be609af1 -version: 1 -date: '2025-20-01' +version: 2 +date: '2025-01-23' author: Jacob Delgado, SnapAttack -description: Logs Online Certificate Status Protocol (OCSP) activity captured by Zeek (formerly Bro), including details such as certificate validation requests and responses. +description: Logs Online Certificate Status Protocol (OCSP) activity captured by Zeek + (formerly Bro), including details such as certificate validation requests and responses. mitre_components: -- Certificate Registration -- Network Traffic Flow -- Network Traffic Content -- Response Metadata -- Application Log Content + - Certificate Registration + - Network Traffic Flow + - Network Traffic Content + - Response Metadata + - Application Log Content source: bro:ocsp:json sourcetype: bro:ocsp:json -supported_TA: [] \ No newline at end of file +supported_TA: [] diff --git a/data_sources/bro_ssl.yml b/data_sources/bro_ssl.yml index 2616ce8186..a2c17d7261 100644 --- a/data_sources/bro_ssl.yml +++ b/data_sources/bro_ssl.yml @@ -1,15 +1,16 @@ name: Bro ssl id: 22c637eb-f62e-41f0-8637-ebf62e11f0a8 -version: 1 -date: '2025-20-01' +version: 2 +date: '2025-01-23' author: Jacob Delgado, SnapAttack -description: Logs SSL/TLS handshake and session details captured by Zeek (formerly Bro), including certificates, cipher suites, and session information. +description: Logs SSL/TLS handshake and session details captured by Zeek (formerly + Bro), including certificates, cipher suites, and session information. mitre_components: -- Certificate Registration -- Network Traffic Flow -- Network Traffic Content -- Response Metadata -- Application Log Content + - Certificate Registration + - Network Traffic Flow + - Network Traffic Content + - Response Metadata + - Application Log Content source: bro:ssl:json sourcetype: bro:ssl:json -supported_TA: [] \ No newline at end of file +supported_TA: [] diff --git a/data_sources/bro_weird.yml b/data_sources/bro_weird.yml index 346236e53d..1fc72ac2de 100644 --- a/data_sources/bro_weird.yml +++ b/data_sources/bro_weird.yml @@ -1,15 +1,16 @@ name: Bro weird id: e03762c5-c4b8-44e3-b762-c5c4b8e4e3b6 -version: 1 -date: '2025-20-01' +version: 2 +date: '2025-01-23' author: Jacob Delgado, SnapAttack -description: Logs anomalous or unexpected network behaviors identified by Zeek (formerly Bro), including protocol violations and unusual traffic patterns. +description: Logs anomalous or unexpected network behaviors identified by Zeek (formerly + Bro), including protocol violations and unusual traffic patterns. mitre_components: -- Network Traffic Flow -- Network Traffic Content -- Response Metadata -- Application Log Content -- Host Status + - Network Traffic Flow + - Network Traffic Content + - Response Metadata + - Application Log Content + - Host Status source: bro:weird:json sourcetype: bro:weird:json supported_TA: [] diff --git a/data_sources/bro_x509.yml b/data_sources/bro_x509.yml index 8c41ee6ac1..3d9d08adf7 100644 --- a/data_sources/bro_x509.yml +++ b/data_sources/bro_x509.yml @@ -1,15 +1,16 @@ name: Bro x509 id: e8792367-64b0-47e9-b923-6764b0f7e936 -version: 1 -date: '2025-20-01' +version: 2 +date: '2025-01-23' author: Jacob Delgado, SnapAttack -description: Logs details about X.509 certificates observed in network traffic captured by Zeek (formerly Bro), including certificate fields, validity periods, and issuers. +description: Logs details about X.509 certificates observed in network traffic captured + by Zeek (formerly Bro), including certificate fields, validity periods, and issuers. mitre_components: -- Certificate Registration -- Network Traffic Content -- Response Metadata -- Application Log Content -- Host Status + - Certificate Registration + - Network Traffic Content + - Response Metadata + - Application Log Content + - Host Status source: bro:x509:json sourcetype: bro:x509:json -supported_TA: [] \ No newline at end of file +supported_TA: [] diff --git a/data_sources/circleci.yml b/data_sources/circleci.yml index 6cf9ff1092..b07ad95c84 100644 --- a/data_sources/circleci.yml +++ b/data_sources/circleci.yml @@ -1,74 +1,75 @@ name: CircleCI id: 34ad06fc-a296-4ab5-8315-2f07714948e3 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs activities related to CI/CD pipelines executed in CircleCI, including job execution, workflow progress, and configuration changes. +description: Logs activities related to CI/CD pipelines executed in CircleCI, including + job execution, workflow progress, and configuration changes. mitre_components: -- Scheduled Job Execution -- Scheduled Job Metadata -- Application Log Content -- Configuration Modification -- Host Status + - Scheduled Job Execution + - Scheduled Job Metadata + - Application Log Content + - Configuration Modification + - Host Status source: circleci sourcetype: circleci supported_TA: -- name: App for CircleCI - url: https://splunkbase.splunk.com/app/5162 - version: 0.1.1 + - name: App for CircleCI + url: https://splunkbase.splunk.com/app/5162 + version: 0.1.1 fields: -- _time -- author_name -- avatar_url -- branch -- build_num -- build_time_millis -- build_url -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- eventtype -- fail_reason -- host -- index -- job_name -- job_time -- linecount -- owners{} -- project_slug -- punct -- queued_time -- reponame -- source -- sourcetype -- splunk_server -- start_time -- status -- stop_time -- tag -- tag::eventtype -- timedout -- timeendpos -- timestartpos -- username -- vcs.commit_time -- vcs.committer_name -- vcs.revision -- vcs.subject -- vcs.tag -- vcs.type -- vcs.url -- workflows.job_id -- workflows.job_name -- workflows.upstream_job_ids{} -- workflows.workflow_id -- workflows.workflow_name -- workflows.workspace_id + - _time + - author_name + - avatar_url + - branch + - build_num + - build_time_millis + - build_url + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - eventtype + - fail_reason + - host + - index + - job_name + - job_time + - linecount + - owners{} + - project_slug + - punct + - queued_time + - reponame + - source + - sourcetype + - splunk_server + - start_time + - status + - stop_time + - tag + - tag::eventtype + - timedout + - timeendpos + - timestartpos + - username + - vcs.commit_time + - vcs.committer_name + - vcs.revision + - vcs.subject + - vcs.tag + - vcs.type + - vcs.url + - workflows.job_id + - workflows.job_name + - workflows.upstream_job_ids{} + - workflows.workflow_id + - workflows.workflow_name + - workflows.workspace_id example_log: '{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z", "start_time": "2021-09-02T08:10:15.829Z", "queued_time": "2021-09-02T08:10:12.764Z", "job_name": "Unknown", "reponame": "devsecops_poc", "build_num": 94, "build_url": diff --git a/data_sources/crowdstrike_processrollup2.yml b/data_sources/crowdstrike_processrollup2.yml index e9074afdd5..d160cf8620 100644 --- a/data_sources/crowdstrike_processrollup2.yml +++ b/data_sources/crowdstrike_processrollup2.yml @@ -1,113 +1,115 @@ name: CrowdStrike ProcessRollup2 id: cbb06880-9dd9-4542-ac60-bd6e5d3c3e4e -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs process-related activities captured by CrowdStrike, including process creation, termination, and metadata such as hashes, parent processes, and command-line arguments. +description: Logs process-related activities captured by CrowdStrike, including process + creation, termination, and metadata such as hashes, parent processes, and command-line + arguments. mitre_components: -- Process Creation -- Process Termination -- Process Metadata -- Command Execution -- OS API Execution + - Process Creation + - Process Termination + - Process Metadata + - Command Execution + - OS API Execution source: crowdstrike sourcetype: crowdstrike:events:sensor separator: event_simpleName separator_value: ProcessRollup2 supported_TA: -- name: Splunk Add-on for CrowdStrike FDR - url: https://splunkbase.splunk.com/app/5579 - version: 2.0.3 + - name: Splunk Add-on for CrowdStrike FDR + url: https://splunkbase.splunk.com/app/5579 + version: 2.0.3 fields: -- AuthenticationId -- AuthenticationId_meaning -- AuthenticodeHashData -- CommandLine -- ConfigBuild -- ConfigStateHash -- EffectiveTransmissionClass -- Entitlements -- EventOrigin -- ImageFileName -- ImageSubsystem -- ImageSubsystem_meaning -- IntegrityLevel -- IntegrityLevel_meaning -- MD5HashData -- ParentAuthenticationId -- ParentBaseFileName -- ParentProcessId -- ProcessCreateFlags -- ProcessEndTime -- ProcessParameterFlags -- ProcessParameterFlags_meaning -- ProcessStartTime -- ProcessSxsFlags -- ProcessSxsFlags_meaning -- RawProcessId -- SHA1HashData -- SHA256HashData -- SessionId -- SignInfoFlags -- SignInfoFlags_meaning -- SourceProcessId -- SourceThreadId -- Tags -- TargetProcessId -- TokenType -- TokenType_meaning -- UserSid -- WindowFlags -- WindowFlags_meaning -- action -- aid -- aid_city -- aid_computer_name -- aid_continent -- aid_country -- aid_machine_domain -- aid_os_version -- aid_ou -- aid_site_name -- aid_system_product_name -- aip -- cid -- dest -- event_ingest_time -- event_platform -- event_simpleName -- eventtype -- host_res_aid -- id -- os -- parent_process_exec -- parent_process_id -- parent_process_name -- process -- process_exec -- process_hash -- process_id -- process_integrity_level -- process_name -- process_path -- resolve_dest -- resolve_process_integrity_level -- tag -- timestamp -- user -- user_id -- vendor_product + - AuthenticationId + - AuthenticationId_meaning + - AuthenticodeHashData + - CommandLine + - ConfigBuild + - ConfigStateHash + - EffectiveTransmissionClass + - Entitlements + - EventOrigin + - ImageFileName + - ImageSubsystem + - ImageSubsystem_meaning + - IntegrityLevel + - IntegrityLevel_meaning + - MD5HashData + - ParentAuthenticationId + - ParentBaseFileName + - ParentProcessId + - ProcessCreateFlags + - ProcessEndTime + - ProcessParameterFlags + - ProcessParameterFlags_meaning + - ProcessStartTime + - ProcessSxsFlags + - ProcessSxsFlags_meaning + - RawProcessId + - SHA1HashData + - SHA256HashData + - SessionId + - SignInfoFlags + - SignInfoFlags_meaning + - SourceProcessId + - SourceThreadId + - Tags + - TargetProcessId + - TokenType + - TokenType_meaning + - UserSid + - WindowFlags + - WindowFlags_meaning + - action + - aid + - aid_city + - aid_computer_name + - aid_continent + - aid_country + - aid_machine_domain + - aid_os_version + - aid_ou + - aid_site_name + - aid_system_product_name + - aip + - cid + - dest + - event_ingest_time + - event_platform + - event_simpleName + - eventtype + - host_res_aid + - id + - os + - parent_process_exec + - parent_process_id + - parent_process_name + - process + - process_exec + - process_hash + - process_id + - process_integrity_level + - process_name + - process_path + - resolve_dest + - resolve_process_integrity_level + - tag + - timestamp + - user + - user_id + - vendor_product field_mappings: -- data_model: cim - data_set: Endpoint.Processes - mapping: - CommandLine: Processes.process - ImageFileName: Processes.process_path - ParentBaseFileName: Processes.parent_process_name - ParentProcessId: Processes.parent_process_id - RawProcessId: Processes.process_id - SHA256HashData: Processes.process_hash - UserSid: Processes.user + - data_model: cim + data_set: Endpoint.Processes + mapping: + CommandLine: Processes.process + ImageFileName: Processes.process_path + ParentBaseFileName: Processes.parent_process_name + ParentProcessId: Processes.parent_process_id + RawProcessId: Processes.process_id + SHA256HashData: Processes.process_hash + UserSid: Processes.user example_log: '{"LinkName":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\Windows PowerShell.lnk","ProcessCreateFlags":"67634196","IntegrityLevel":"12288","ParentProcessId":"5459598860","SourceProcessId":"5459598860","aip":"3.126.231.40","SHA1HashData":"0000000000000000000000000000000000000000","UserSid":"S-1-5-21-586445407-708991241-1829972403-500","event_platform":"Win","TokenType":"1","ProcessEndTime":"","AuthenticodeHashData":"3b98faafc17b47beb9027c437fceeafdf0624a1c","ParentBaseFileName":"explorer.exe","EventOrigin":"1","ImageSubsystem":"3","id":"e2210781-0e8f-47d2-bf6a-56d2c59f38ee","EffectiveTransmissionClass":"3","SessionId":"2","ShowWindowFlags":"1","Tags":"27, 40, 151, 874, 924, 12094627905582, 12094627906234, 211106232533012, 212205744161605, diff --git a/data_sources/crushftp.yml b/data_sources/crushftp.yml index 04a5b0827c..67968d73ef 100644 --- a/data_sources/crushftp.yml +++ b/data_sources/crushftp.yml @@ -1,21 +1,22 @@ name: CrushFTP id: 8a42ace5-e4c8-4653-80cf-1b8e7e6024ef -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs activities related to file transfers and user interactions in CrushFTP, including file uploads, downloads, user authentication, and session details. +description: Logs activities related to file transfers and user interactions in CrushFTP, + including file uploads, downloads, user authentication, and session details. mitre_components: -- File Access -- File Metadata -- User Account Authentication -- Logon Session Metadata -- Network Traffic Content + - File Access + - File Metadata + - User Account Authentication + - Logon Session Metadata + - Network Traffic Content source: crushftp sourcetype: crushftp:sessionlogs supported_TA: [] fields: -- _time -- _raw + - _time + - _raw example_log: 'SESSION|05/14/2024 17:36:21.859|[HTTPS:169_52326_sMa:anonymous:10.0.1.30] READ: *POST /WebInterface/function/?c2f=CmF1&command=zip&path=%3CINCLUDE%3Eusers/MainUsers/groups.XML%3C/INCLUDE%3E&names=/a HTTP/1.1*' diff --git a/data_sources/g_suite_drive.yml b/data_sources/g_suite_drive.yml index a07ee5cd8c..0d56a7944d 100644 --- a/data_sources/g_suite_drive.yml +++ b/data_sources/g_suite_drive.yml @@ -1,53 +1,54 @@ name: G Suite Drive id: 5f79120f-a235-4468-bd0d-55203758ac22 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs activities related to Google Drive in G Suite, including file creation, modification, sharing, and access details. +description: Logs activities related to Google Drive in G Suite, including file creation, + modification, sharing, and access details. mitre_components: -- File Access -- File Creation -- File Modification -- Cloud Storage Access -- Cloud Storage Metadata + - File Access + - File Creation + - File Modification + - Cloud Storage Access + - Cloud Storage Metadata source: http:gsuite sourcetype: gsuite:drive:json supported_TA: -- name: Splunk Add-on for Google Workspace - url: https://splunkbase.splunk.com/app/5556 - version: 3.0.2 + - name: Splunk Add-on for Google Workspace + url: https://splunkbase.splunk.com/app/5556 + version: 3.0.2 fields: -- _time -- email -- host -- index -- ip_address -- linecount -- name -- parameters.actor_is_collaborator_account -- parameters.billable -- parameters.doc_id -- parameters.doc_title -- parameters.doc_type -- parameters.is_encrypted -- parameters.new_value{} -- parameters.old_value{} -- parameters.old_visibility -- parameters.originating_app_id -- parameters.owner -- parameters.owner_is_shared_drive -- parameters.owner_is_team_drive -- parameters.primary_event -- parameters.target_user -- parameters.visibility -- parameters.visibility_change -- punct -- source -- sourcetype -- splunk_server -- timestamp -- type -- unique_id + - _time + - email + - host + - index + - ip_address + - linecount + - name + - parameters.actor_is_collaborator_account + - parameters.billable + - parameters.doc_id + - parameters.doc_title + - parameters.doc_type + - parameters.is_encrypted + - parameters.new_value{} + - parameters.old_value{} + - parameters.old_visibility + - parameters.originating_app_id + - parameters.owner + - parameters.owner_is_shared_drive + - parameters.owner_is_team_drive + - parameters.primary_event + - parameters.target_user + - parameters.visibility + - parameters.visibility_change + - punct + - source + - sourcetype + - splunk_server + - timestamp + - type + - unique_id example_log: '{"type": "acl_change", "name": "change_user_access", "parameters": {"primary_event": true, "billable": true, "visibility_change": "none", "target_user": "alberto@internal_test_email.com", "old_value": ["none"], "new_value": ["can_edit"], "old_visibility": "private", "doc_id": diff --git a/data_sources/g_suite_gmail.yml b/data_sources/g_suite_gmail.yml index 0a6ddc9596..c89e7087fb 100644 --- a/data_sources/g_suite_gmail.yml +++ b/data_sources/g_suite_gmail.yml @@ -1,91 +1,92 @@ name: G Suite Gmail id: 706c3978-41de-406b-b6e0-75bd01e12a5d -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs Gmail activities in G Suite, including email sending, receiving, and access details, as well as potential security-related events. +description: Logs Gmail activities in G Suite, including email sending, receiving, + and access details, as well as potential security-related events. mitre_components: -- Application Log Content -- User Account Metadata -- Email Metadata -- Cloud Service Metadata + - Application Log Content + - User Account Metadata + - Email Metadata + - Cloud Service Metadata source: http:gsuite sourcetype: gsuite:gmail:bigquery supported_TA: -- name: Splunk Add-on for Google Workspace - url: https://splunkbase.splunk.com/app/5556 - version: 3.0.2 + - name: Splunk Add-on for Google Workspace + url: https://splunkbase.splunk.com/app/5556 + version: 3.0.2 fields: -- _time -- action_type -- attachment{}.file_extension_type -- attachment{}.malware_family -- attachment{}.sha256 -- connection_info.authenticated_domain{}.name -- connection_info.authenticated_domain{}.type -- connection_info.client_host_zone -- connection_info.client_ip -- connection_info.dkim_pass -- connection_info.dmarc_pass -- connection_info.dmarc_published_domain -- connection_info.ip_geo_city -- connection_info.ip_geo_country -- connection_info.is_internal -- connection_info.is_intra_domain -- connection_info.smtp_in_connect_ip -- connection_info.smtp_out_connect_ip -- connection_info.smtp_out_remote_host -- connection_info.smtp_reply_code -- connection_info.smtp_response_reason -- connection_info.smtp_tls_cipher -- connection_info.smtp_tls_state -- connection_info.smtp_tls_version -- connection_info.smtp_user_agent_ip -- connection_info.spf_pass -- connection_info.tls_required_but_unavailable -- description -- destination{}.address -- destination{}.rcpt_response -- destination{}.selector -- destination{}.service -- destination{}.smime_decryption_success -- destination{}.smime_extraction_success -- destination{}.smime_parsing_success -- destination{}.smime_signature_verification_success -- eventtype -- flattened_destinations -- flattened_triggered_rule_info -- host -- index -- is_policy_check_for_sender -- is_spam -- linecount -- message_set{}.type -- num_message_attachments -- payload_size -- punct -- rfc2822_message_id -- smime_content_type -- smime_encrypt_message -- smime_extraction_success -- smime_packaging_success -- smime_sign_message -- smtp_relay_error -- source -- source.address -- source.from_header_address -- source.from_header_displayname -- source.selector -- source.service -- sourcetype -- spam_info -- splunk_server -- structured_policy_log_info -- subject -- tag -- tag::eventtype -- timestamp -- upload_error_category + - _time + - action_type + - attachment{}.file_extension_type + - attachment{}.malware_family + - attachment{}.sha256 + - connection_info.authenticated_domain{}.name + - connection_info.authenticated_domain{}.type + - connection_info.client_host_zone + - connection_info.client_ip + - connection_info.dkim_pass + - connection_info.dmarc_pass + - connection_info.dmarc_published_domain + - connection_info.ip_geo_city + - connection_info.ip_geo_country + - connection_info.is_internal + - connection_info.is_intra_domain + - connection_info.smtp_in_connect_ip + - connection_info.smtp_out_connect_ip + - connection_info.smtp_out_remote_host + - connection_info.smtp_reply_code + - connection_info.smtp_response_reason + - connection_info.smtp_tls_cipher + - connection_info.smtp_tls_state + - connection_info.smtp_tls_version + - connection_info.smtp_user_agent_ip + - connection_info.spf_pass + - connection_info.tls_required_but_unavailable + - description + - destination{}.address + - destination{}.rcpt_response + - destination{}.selector + - destination{}.service + - destination{}.smime_decryption_success + - destination{}.smime_extraction_success + - destination{}.smime_parsing_success + - destination{}.smime_signature_verification_success + - eventtype + - flattened_destinations + - flattened_triggered_rule_info + - host + - index + - is_policy_check_for_sender + - is_spam + - linecount + - message_set{}.type + - num_message_attachments + - payload_size + - punct + - rfc2822_message_id + - smime_content_type + - smime_encrypt_message + - smime_extraction_success + - smime_packaging_success + - smime_sign_message + - smtp_relay_error + - source + - source.address + - source.from_header_address + - source.from_header_displayname + - source.selector + - source.service + - sourcetype + - spam_info + - splunk_server + - structured_policy_log_info + - subject + - tag + - tag::eventtype + - timestamp + - upload_error_category example_log: '{"action_type": 10, "rfc2822_message_id": "", "subject": "New Order DHL0000001 - Dummy email for Detection Development", "payload_size": 6733, "source": {"address": "john@external_test_email.com", "service": "gmail-for-work", diff --git a/data_sources/github.yml b/data_sources/github.yml index e9125f7f07..32ebea53e7 100644 --- a/data_sources/github.yml +++ b/data_sources/github.yml @@ -1,211 +1,212 @@ name: GitHub id: 88aa4632-3c3e-43f6-a00a-998d71f558e3 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs activities on GitHub repositories, including push events, pull requests, issue creation, and user authentication events. +description: Logs activities on GitHub repositories, including push events, pull requests, + issue creation, and user authentication events. mitre_components: -- User Account Authentication -- Configuration Modification -- Application Log Content -- User Account Metadata -- Scheduled Job Metadata + - User Account Authentication + - Configuration Modification + - Application Log Content + - User Account Metadata + - Scheduled Job Metadata source: github sourcetype: aws:firehose:json supported_TA: -- name: Splunk Add-on for Github - url: https://splunkbase.splunk.com/app/6254 - version: 3.1.0 + - name: Splunk Add-on for Github + url: https://splunkbase.splunk.com/app/6254 + version: 3.1.0 fields: -- _time -- action -- host -- index -- linecount -- meta -- punct -- source -- sourcetype -- splunk_server -- timestamp -- workflow_run.actor.avatar_url -- workflow_run.actor.events_url -- workflow_run.actor.followers_url -- workflow_run.actor.following_url -- workflow_run.actor.gists_url -- workflow_run.actor.gravatar_id -- workflow_run.actor.html_url -- workflow_run.actor.id -- workflow_run.actor.login -- workflow_run.actor.node_id -- workflow_run.actor.organizations_url -- workflow_run.actor.received_events_url -- workflow_run.actor.repos_url -- workflow_run.actor.site_admin -- workflow_run.actor.starred_url -- workflow_run.actor.subscriptions_url -- workflow_run.actor.type -- workflow_run.actor.url -- workflow_run.artifacts_url -- workflow_run.cancel_url -- workflow_run.check_suite_id -- workflow_run.check_suite_node_id -- workflow_run.check_suite_url -- workflow_run.conclusion -- workflow_run.created_at -- workflow_run.event -- workflow_run.head_branch -- workflow_run.head_commit.author.email -- workflow_run.head_commit.author.name -- workflow_run.head_commit.committer.email -- workflow_run.head_commit.committer.name -- workflow_run.head_commit.id -- workflow_run.head_commit.message -- workflow_run.head_commit.timestamp -- workflow_run.head_commit.tree_id -- workflow_run.head_repository.collaborators_url -- workflow_run.head_repository.description -- workflow_run.head_repository.fork -- workflow_run.head_repository.forks_url -- workflow_run.head_repository.full_name -- workflow_run.head_repository.hooks_url -- workflow_run.head_repository.html_url -- workflow_run.head_repository.id -- workflow_run.head_repository.keys_url -- workflow_run.head_repository.name -- workflow_run.head_repository.node_id -- workflow_run.head_repository.owner.avatar_url -- workflow_run.head_repository.owner.events_url -- workflow_run.head_repository.owner.followers_url -- workflow_run.head_repository.owner.following_url -- workflow_run.head_repository.owner.gists_url -- workflow_run.head_repository.owner.gravatar_id -- workflow_run.head_repository.owner.html_url -- workflow_run.head_repository.owner.id -- workflow_run.head_repository.owner.login -- workflow_run.head_repository.owner.node_id -- workflow_run.head_repository.owner.organizations_url -- workflow_run.head_repository.owner.received_events_url -- workflow_run.head_repository.owner.repos_url -- workflow_run.head_repository.owner.site_admin -- workflow_run.head_repository.owner.starred_url -- workflow_run.head_repository.owner.subscriptions_url -- workflow_run.head_repository.owner.type -- workflow_run.head_repository.owner.url -- workflow_run.head_repository.private -- workflow_run.head_repository.teams_url -- workflow_run.head_repository.url -- workflow_run.head_sha -- workflow_run.html_url -- workflow_run.id -- workflow_run.jobs_url -- workflow_run.logs_url -- workflow_run.name -- workflow_run.node_id -- workflow_run.previous_attempt_url -- workflow_run.pull_requests{}.base.ref -- workflow_run.pull_requests{}.base.repo.id -- workflow_run.pull_requests{}.base.repo.name -- workflow_run.pull_requests{}.base.repo.url -- workflow_run.pull_requests{}.base.sha -- workflow_run.pull_requests{}.head.ref -- workflow_run.pull_requests{}.head.repo.id -- workflow_run.pull_requests{}.head.repo.name -- workflow_run.pull_requests{}.head.repo.url -- workflow_run.pull_requests{}.head.sha -- workflow_run.pull_requests{}.id -- workflow_run.pull_requests{}.number -- workflow_run.pull_requests{}.url -- workflow_run.repository.archive_url -- workflow_run.repository.assignees_url -- workflow_run.repository.blobs_url -- workflow_run.repository.branches_url -- workflow_run.repository.collaborators_url -- workflow_run.repository.comments_url -- workflow_run.repository.commits_url -- workflow_run.repository.compare_url -- workflow_run.repository.contents_url -- workflow_run.repository.contributors_url -- workflow_run.repository.deployments_url -- workflow_run.repository.description -- workflow_run.repository.downloads_url -- workflow_run.repository.events_url -- workflow_run.repository.fork -- workflow_run.repository.forks_url -- workflow_run.repository.full_name -- workflow_run.repository.git_commits_url -- workflow_run.repository.git_refs_url -- workflow_run.repository.git_tags_url -- workflow_run.repository.hooks_url -- workflow_run.repository.html_url -- workflow_run.repository.id -- workflow_run.repository.issue_comment_url -- workflow_run.repository.issue_events_url -- workflow_run.repository.issues_url -- workflow_run.repository.keys_url -- workflow_run.repository.labels_url -- workflow_run.repository.languages_url -- workflow_run.repository.merges_url -- workflow_run.repository.milestones_url -- workflow_run.repository.name -- workflow_run.repository.node_id -- workflow_run.repository.notifications_url -- workflow_run.repository.owner.avatar_url -- workflow_run.repository.owner.events_url -- workflow_run.repository.owner.followers_url -- workflow_run.repository.owner.following_url -- workflow_run.repository.owner.gists_url -- workflow_run.repository.owner.gravatar_id -- workflow_run.repository.owner.html_url -- workflow_run.repository.owner.id -- workflow_run.repository.owner.login -- workflow_run.repository.owner.node_id -- workflow_run.repository.owner.organizations_url -- workflow_run.repository.owner.received_events_url -- workflow_run.repository.owner.repos_url -- workflow_run.repository.owner.site_admin -- workflow_run.repository.owner.starred_url -- workflow_run.repository.owner.subscriptions_url -- workflow_run.repository.owner.type -- workflow_run.repository.owner.url -- workflow_run.repository.private -- workflow_run.repository.pulls_url -- workflow_run.repository.releases_url -- workflow_run.repository.stargazers_url -- workflow_run.repository.statuses_url -- workflow_run.repository.subscribers_url -- workflow_run.repository.subscription_url -- workflow_run.repository.tags_url -- workflow_run.repository.teams_url -- workflow_run.repository.trees_url -- workflow_run.repository.url -- workflow_run.rerun_url -- workflow_run.run_attempt -- workflow_run.run_number -- workflow_run.run_started_at -- workflow_run.status -- workflow_run.triggering_actor.avatar_url -- workflow_run.triggering_actor.events_url -- workflow_run.triggering_actor.followers_url -- workflow_run.triggering_actor.following_url -- workflow_run.triggering_actor.gists_url -- workflow_run.triggering_actor.gravatar_id -- workflow_run.triggering_actor.html_url -- workflow_run.triggering_actor.id -- workflow_run.triggering_actor.login -- workflow_run.triggering_actor.node_id -- workflow_run.triggering_actor.organizations_url -- workflow_run.triggering_actor.received_events_url -- workflow_run.triggering_actor.repos_url -- workflow_run.triggering_actor.site_admin -- workflow_run.triggering_actor.starred_url -- workflow_run.triggering_actor.subscriptions_url -- workflow_run.triggering_actor.type -- workflow_run.triggering_actor.url -- workflow_run.updated_at -- workflow_run.url -- workflow_run.workflow_id -- workflow_run.workflow_url + - _time + - action + - host + - index + - linecount + - meta + - punct + - source + - sourcetype + - splunk_server + - timestamp + - workflow_run.actor.avatar_url + - workflow_run.actor.events_url + - workflow_run.actor.followers_url + - workflow_run.actor.following_url + - workflow_run.actor.gists_url + - workflow_run.actor.gravatar_id + - workflow_run.actor.html_url + - workflow_run.actor.id + - workflow_run.actor.login + - workflow_run.actor.node_id + - workflow_run.actor.organizations_url + - workflow_run.actor.received_events_url + - workflow_run.actor.repos_url + - workflow_run.actor.site_admin + - workflow_run.actor.starred_url + - workflow_run.actor.subscriptions_url + - workflow_run.actor.type + - workflow_run.actor.url + - workflow_run.artifacts_url + - workflow_run.cancel_url + - workflow_run.check_suite_id + - workflow_run.check_suite_node_id + - workflow_run.check_suite_url + - workflow_run.conclusion + - workflow_run.created_at + - workflow_run.event + - workflow_run.head_branch + - workflow_run.head_commit.author.email + - workflow_run.head_commit.author.name + - workflow_run.head_commit.committer.email + - workflow_run.head_commit.committer.name + - workflow_run.head_commit.id + - workflow_run.head_commit.message + - workflow_run.head_commit.timestamp + - workflow_run.head_commit.tree_id + - workflow_run.head_repository.collaborators_url + - workflow_run.head_repository.description + - workflow_run.head_repository.fork + - workflow_run.head_repository.forks_url + - workflow_run.head_repository.full_name + - workflow_run.head_repository.hooks_url + - workflow_run.head_repository.html_url + - workflow_run.head_repository.id + - workflow_run.head_repository.keys_url + - workflow_run.head_repository.name + - workflow_run.head_repository.node_id + - workflow_run.head_repository.owner.avatar_url + - workflow_run.head_repository.owner.events_url + - workflow_run.head_repository.owner.followers_url + - workflow_run.head_repository.owner.following_url + - workflow_run.head_repository.owner.gists_url + - workflow_run.head_repository.owner.gravatar_id + - workflow_run.head_repository.owner.html_url + - workflow_run.head_repository.owner.id + - workflow_run.head_repository.owner.login + - workflow_run.head_repository.owner.node_id + - workflow_run.head_repository.owner.organizations_url + - workflow_run.head_repository.owner.received_events_url + - workflow_run.head_repository.owner.repos_url + - workflow_run.head_repository.owner.site_admin + - workflow_run.head_repository.owner.starred_url + - workflow_run.head_repository.owner.subscriptions_url + - workflow_run.head_repository.owner.type + - workflow_run.head_repository.owner.url + - workflow_run.head_repository.private + - workflow_run.head_repository.teams_url + - workflow_run.head_repository.url + - workflow_run.head_sha + - workflow_run.html_url + - workflow_run.id + - workflow_run.jobs_url + - workflow_run.logs_url + - workflow_run.name + - workflow_run.node_id + - workflow_run.previous_attempt_url + - workflow_run.pull_requests{}.base.ref + - workflow_run.pull_requests{}.base.repo.id + - workflow_run.pull_requests{}.base.repo.name + - workflow_run.pull_requests{}.base.repo.url + - workflow_run.pull_requests{}.base.sha + - workflow_run.pull_requests{}.head.ref + - workflow_run.pull_requests{}.head.repo.id + - workflow_run.pull_requests{}.head.repo.name + - workflow_run.pull_requests{}.head.repo.url + - workflow_run.pull_requests{}.head.sha + - workflow_run.pull_requests{}.id + - workflow_run.pull_requests{}.number + - workflow_run.pull_requests{}.url + - workflow_run.repository.archive_url + - workflow_run.repository.assignees_url + - workflow_run.repository.blobs_url + - workflow_run.repository.branches_url + - workflow_run.repository.collaborators_url + - workflow_run.repository.comments_url + - workflow_run.repository.commits_url + - workflow_run.repository.compare_url + - workflow_run.repository.contents_url + - workflow_run.repository.contributors_url + - workflow_run.repository.deployments_url + - workflow_run.repository.description + - workflow_run.repository.downloads_url + - workflow_run.repository.events_url + - workflow_run.repository.fork + - workflow_run.repository.forks_url + - workflow_run.repository.full_name + - workflow_run.repository.git_commits_url + - workflow_run.repository.git_refs_url + - workflow_run.repository.git_tags_url + - workflow_run.repository.hooks_url + - workflow_run.repository.html_url + - workflow_run.repository.id + - workflow_run.repository.issue_comment_url + - workflow_run.repository.issue_events_url + - workflow_run.repository.issues_url + - workflow_run.repository.keys_url + - workflow_run.repository.labels_url + - workflow_run.repository.languages_url + - workflow_run.repository.merges_url + - workflow_run.repository.milestones_url + - workflow_run.repository.name + - workflow_run.repository.node_id + - workflow_run.repository.notifications_url + - workflow_run.repository.owner.avatar_url + - workflow_run.repository.owner.events_url + - workflow_run.repository.owner.followers_url + - workflow_run.repository.owner.following_url + - workflow_run.repository.owner.gists_url + - workflow_run.repository.owner.gravatar_id + - workflow_run.repository.owner.html_url + - workflow_run.repository.owner.id + - workflow_run.repository.owner.login + - workflow_run.repository.owner.node_id + - workflow_run.repository.owner.organizations_url + - workflow_run.repository.owner.received_events_url + - workflow_run.repository.owner.repos_url + - workflow_run.repository.owner.site_admin + - workflow_run.repository.owner.starred_url + - workflow_run.repository.owner.subscriptions_url + - workflow_run.repository.owner.type + - workflow_run.repository.owner.url + - workflow_run.repository.private + - workflow_run.repository.pulls_url + - workflow_run.repository.releases_url + - workflow_run.repository.stargazers_url + - workflow_run.repository.statuses_url + - workflow_run.repository.subscribers_url + - workflow_run.repository.subscription_url + - workflow_run.repository.tags_url + - workflow_run.repository.teams_url + - workflow_run.repository.trees_url + - workflow_run.repository.url + - workflow_run.rerun_url + - workflow_run.run_attempt + - workflow_run.run_number + - workflow_run.run_started_at + - workflow_run.status + - workflow_run.triggering_actor.avatar_url + - workflow_run.triggering_actor.events_url + - workflow_run.triggering_actor.followers_url + - workflow_run.triggering_actor.following_url + - workflow_run.triggering_actor.gists_url + - workflow_run.triggering_actor.gravatar_id + - workflow_run.triggering_actor.html_url + - workflow_run.triggering_actor.id + - workflow_run.triggering_actor.login + - workflow_run.triggering_actor.node_id + - workflow_run.triggering_actor.organizations_url + - workflow_run.triggering_actor.received_events_url + - workflow_run.triggering_actor.repos_url + - workflow_run.triggering_actor.site_admin + - workflow_run.triggering_actor.starred_url + - workflow_run.triggering_actor.subscriptions_url + - workflow_run.triggering_actor.type + - workflow_run.triggering_actor.url + - workflow_run.updated_at + - workflow_run.url + - workflow_run.workflow_id + - workflow_run.workflow_url example_log: '{"action":"requested","workflow_run":{"id":2088708615,"name":"auto-update","node_id":"WFR_kwLOCa00Ec58fyoH","head_branch":"mac_os_detections","head_sha":"4049334910ea3d52a917ca35aed66d11c80ed966","run_number":9504,"event":"push","status":"queued","conclusion":null,"workflow_id":4692335,"check_suite_id":5918781611,"check_suite_node_id":"CS_kwDOCa00Ec8AAAABYMlwqw","url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615","html_url":"https://github.com/splunk/security_content/actions/runs/2088708615","pull_requests":[{"url":"https://api.github.com/repos/splunk/security_content/pulls/2131","id":893091277,"number":2131,"head":{"ref":"mac_os_detections","sha":"4049334910ea3d52a917ca35aed66d11c80ed966","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}},"base":{"ref":"develop","sha":"a7d3d1dc57f9bf36fe22e470bcf518fcc2c89283","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}}}],"created_at":"2022-04-04T08:43:15Z","updated_at":"2022-04-04T08:43:15Z","actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"run_attempt":1,"run_started_at":"2022-04-04T08:43:15Z","triggering_actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"jobs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/jobs","logs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/logs","check_suite_url":"https://api.github.com/repos/splunk/security_content/check-suites/5918781611","artifacts_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/artifacts","cancel_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/cancel","rerun_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/rerun","previous_attempt_url":null,"workflow_url":"https://api.github.com/repos/splunk/security_content/actions/workflows/4692335","head_commit":{"id":"4049334910ea3d52a917ca35aed66d11c80ed966","tree_id":"df4ddc1359be3b19f093b7a27dbf5708187743a0","message":"small change","timestamp":"2022-04-04T08:43:01Z","author":{"name":"jsmith","email":"jsmith@evilcorp.com"},"committer":{"name":"jsmith","email":"jsmith@evilcorp.com"}},"repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/number}","events_url":"https://api.github.com/repos/splunk/security_content/events","assignees_url":"https://api.github.com/repos/splunk/security_content/assignees{/user}","branches_url":"https://api.github.com/repos/splunk/security_content/branches{/branch}","tags_url":"https://api.github.com/repos/splunk/security_content/tags","blobs_url":"https://api.github.com/repos/splunk/security_content/git/blobs{/sha}","git_tags_url":"https://api.github.com/repos/splunk/security_content/git/tags{/sha}","git_refs_url":"https://api.github.com/repos/splunk/security_content/git/refs{/sha}","trees_url":"https://api.github.com/repos/splunk/security_content/git/trees{/sha}","statuses_url":"https://api.github.com/repos/splunk/security_content/statuses/{sha}","languages_url":"https://api.github.com/repos/splunk/security_content/languages","stargazers_url":"https://api.github.com/repos/splunk/security_content/stargazers","contributors_url":"https://api.github.com/repos/splunk/security_content/contributors","subscribers_url":"https://api.github.com/repos/splunk/security_content/subscribers","subscription_url":"https://api.github.com/repos/splunk/security_content/subscription","commits_url":"https://api.github.com/repos/splunk/security_content/commits{/sha}","git_commits_url":"https://api.github.com/repos/splunk/security_content/git/commits{/sha}","comments_url":"https://api.github.com/repos/splunk/security_content/comments{/number}","issue_comment_url":"https://api.github.com/repos/splunk/security_content/issues/comments{/number}","contents_url":"https://api.github.com/repos/splunk/security_content/contents/{+path}","compare_url":"https://api.github.com/repos/splunk/security_content/compare/{base}...{head}","merges_url":"https://api.github.com/repos/splunk/security_content/merges","archive_url":"https://api.github.com/repos/splunk/security_content/{archive_format}{/ref}","downloads_url":"https://api.github.com/repos/splunk/security_content/downloads","issues_url":"https://api.github.com/repos/splunk/security_content/issues{/number}","pulls_url":"https://api.github.com/repos/splunk/security_content/pulls{/number}","milestones_url":"https://api.github.com/repos/splunk/security_content/milestones{/number}","notifications_url":"https://api.github.com/repos/splunk/security_content/notifications{?since,all,participating}","labels_url":"https://api.github.com/repos/splunk/security_content/labels{/name}","releases_url":"https://api.github.com/repos/splunk/security_content/releases{/id}","deployments_url":"https://api.github.com/repos/splunk/security_content/deployments"},"head_repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk diff --git a/data_sources/google_workspace_login_failure.yml b/data_sources/google_workspace_login_failure.yml index 4f49e2a565..f853aa35f3 100644 --- a/data_sources/google_workspace_login_failure.yml +++ b/data_sources/google_workspace_login_failure.yml @@ -1,58 +1,59 @@ name: Google Workspace login_failure id: cabec7cf-4008-4899-b47e-39c34a9a1255 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs failed login attempts to Google Workspace accounts, including details about the user, IP address, and reason for failure. +description: Logs failed login attempts to Google Workspace accounts, including details + about the user, IP address, and reason for failure. mitre_components: -- User Account Authentication -- Logon Session Metadata -- User Account Metadata -- Application Log Content + - User Account Authentication + - Logon Session Metadata + - User Account Metadata + - Application Log Content source: gws:reports:admin sourcetype: gws:reports:admin separator: event.name separator_value: login_failure supported_TA: -- name: Splunk Add-on for Google Workspace - url: https://splunkbase.splunk.com/app/5556 - version: 3.0.2 + - name: Splunk Add-on for Google Workspace + url: https://splunkbase.splunk.com/app/5556 + version: 3.0.2 fields: -- _time -- actor.email -- actor.profileId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- etag -- event.name -- event.parameters{}.multiValue{} -- event.parameters{}.name -- event.parameters{}.value -- event.type -- eventtype -- host -- id.applicationName -- id.customerId -- id.time -- id.uniqueQualifier -- index -- ipAddress -- kind -- linecount -- punct -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- timeendpos -- timestartpos + - _time + - actor.email + - actor.profileId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - etag + - event.name + - event.parameters{}.multiValue{} + - event.parameters{}.name + - event.parameters{}.value + - event.type + - eventtype + - host + - id.applicationName + - id.customerId + - id.time + - id.uniqueQualifier + - index + - ipAddress + - kind + - linecount + - punct + - source + - sourcetype + - splunk_server + - tag + - tag::eventtype + - timeendpos + - timestartpos example_log: '{"kind": "admin#reports#activity", "id": {"time": "2022-10-12T01:05:35.119Z", "uniqueQualifier": "720229394436", "applicationName": "login", "customerId": "C046r85ir"}, "etag": "\"JCPRxFaiNR1s5TJ6ecIH8OpGdY4efiOYXbIB65itOzY/_lixtTooT11WXorGf6w6ElN0m0g\"", diff --git a/data_sources/google_workspace_login_success.yml b/data_sources/google_workspace_login_success.yml index 723b1b2724..4f0d7d8265 100644 --- a/data_sources/google_workspace_login_success.yml +++ b/data_sources/google_workspace_login_success.yml @@ -1,56 +1,57 @@ name: Google Workspace login_success id: bffe8013-9cdf-4fe6-9c1b-6784391a4951 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs successful login attempts to Google Workspace accounts, including details about the user, IP address, and session metadata. +description: Logs successful login attempts to Google Workspace accounts, including + details about the user, IP address, and session metadata. mitre_components: -- User Account Authentication -- Logon Session Creation -- User Account Metadata -- Logon Session Metadata + - User Account Authentication + - Logon Session Creation + - User Account Metadata + - Logon Session Metadata source: gws:reports:admin sourcetype: gws:reports:admin separator: event.name separator_value: login_success supported_TA: -- name: Splunk Add-on for Google Workspace - url: https://splunkbase.splunk.com/app/5556 - version: 3.0.2 + - name: Splunk Add-on for Google Workspace + url: https://splunkbase.splunk.com/app/5556 + version: 3.0.2 fields: -- _time -- actor.email -- actor.profileId -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- etag -- event.name -- event.parameters{}.boolValue -- event.parameters{}.multiValue{} -- event.parameters{}.name -- event.parameters{}.value -- event.type -- host -- id.applicationName -- id.customerId -- id.time -- id.uniqueQualifier -- index -- ipAddress -- kind -- linecount -- punct -- source -- sourcetype -- splunk_server -- timeendpos -- timestartpos + - _time + - actor.email + - actor.profileId + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - etag + - event.name + - event.parameters{}.boolValue + - event.parameters{}.multiValue{} + - event.parameters{}.name + - event.parameters{}.value + - event.type + - host + - id.applicationName + - id.customerId + - id.time + - id.uniqueQualifier + - index + - ipAddress + - kind + - linecount + - punct + - source + - sourcetype + - splunk_server + - timeendpos + - timestartpos example_log: '{"kind": "admin#reports#activity", "id": {"time": "2022-10-13T20:57:35.833Z", "uniqueQualifier": "437744618349", "applicationName": "login", "customerId": "C046r85ir"}, "etag": "\"JCPRxFaiNR1s5TJ6ecIH8OpGdY4efiOYXbIB65itOzY/OgAbD-Tz8hSD1vUJWw7NLiJ5SF4\"", diff --git a/data_sources/ivanti_vtm_audit.yml b/data_sources/ivanti_vtm_audit.yml index a10ae34f02..389bf9b8d9 100644 --- a/data_sources/ivanti_vtm_audit.yml +++ b/data_sources/ivanti_vtm_audit.yml @@ -1,25 +1,27 @@ name: Ivanti VTM Audit id: b04be6e5-2002-4a49-8722-52285635b8f5 -version: 1 -date: '2024-08-19' +version: 2 +date: '2025-01-23' author: Michael Haag, Splunk -description: Logs administrative and operational activities in Ivanti Virtual Traffic Manager (VTM), including configuration changes, user actions, and system events. +description: Logs administrative and operational activities in Ivanti Virtual Traffic + Manager (VTM), including configuration changes, user actions, and system events. mitre_components: -- Configuration Modification -- Application Log Content -- User Account Metadata -- Host Status -- Service Modification + - Configuration Modification + - Application Log Content + - User Account Metadata + - Host Status + - Service Modification source: ivanti_vtm sourcetype: ivanti_vtm_audit supported_TA: [] fields: -- _time -- IP -- MODUSER -- OPERATION -- MODGROUP -- AUTH -- USER -- GROUP -example_log: '[19/Aug/2024:19:41:22 +0000] USER=!!ABSENT!! GROUP=!!ABSENT!! AUTH=!!ABSENT!! IP=!!ABSENT!! OPERATION=adduser MODUSER=newadmin MODGROUP=admin' + - _time + - IP + - MODUSER + - OPERATION + - MODGROUP + - AUTH + - USER + - GROUP +example_log: '[19/Aug/2024:19:41:22 +0000] USER=!!ABSENT!! GROUP=!!ABSENT!! AUTH=!!ABSENT!! + IP=!!ABSENT!! OPERATION=adduser MODUSER=newadmin MODGROUP=admin' diff --git a/data_sources/kubernetes_audit.yml b/data_sources/kubernetes_audit.yml index 9035f6c381..89588cee18 100644 --- a/data_sources/kubernetes_audit.yml +++ b/data_sources/kubernetes_audit.yml @@ -1,66 +1,67 @@ name: Kubernetes Audit id: 6c25181a-0c07-4aaf-90e6-77ab1f0e6699 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs activities within a Kubernetes cluster, including API server requests, resource access, configuration changes, and user authentication events. +description: Logs activities within a Kubernetes cluster, including API server requests, + resource access, configuration changes, and user authentication events. mitre_components: -- Pod Metadata -- Pod Modification -- Cluster Metadata -- User Account Authentication -- Configuration Modification -- Application Log Content + - Pod Metadata + - Pod Modification + - Cluster Metadata + - User Account Authentication + - Configuration Modification + - Application Log Content source: kubernetes sourcetype: _json supported_TA: [] fields: -- _time -- annotations.authorization.k8s.io/decision -- annotations.authorization.k8s.io/reason -- apiVersion -- auditID -- eventtype -- host -- index -- kind -- level -- linecount -- objectRef.apiGroup -- objectRef.apiVersion -- objectRef.namespace -- objectRef.resource -- punct -- requestReceivedTimestamp -- requestURI -- responseObject.apiVersion -- responseObject.code -- responseObject.details.group -- responseObject.details.kind -- responseObject.kind -- responseObject.message -- responseObject.reason -- responseObject.status -- responseStatus.code -- responseStatus.details.group -- responseStatus.details.kind -- responseStatus.message -- responseStatus.reason -- responseStatus.status -- source -- sourceIPs{} -- sourcetype -- splunk_server -- stage -- stageTimestamp -- tag -- tag::eventtype -- timestamp -- user.groups{} -- user.uid -- user.username -- userAgent -- verb + - _time + - annotations.authorization.k8s.io/decision + - annotations.authorization.k8s.io/reason + - apiVersion + - auditID + - eventtype + - host + - index + - kind + - level + - linecount + - objectRef.apiGroup + - objectRef.apiVersion + - objectRef.namespace + - objectRef.resource + - punct + - requestReceivedTimestamp + - requestURI + - responseObject.apiVersion + - responseObject.code + - responseObject.details.group + - responseObject.details.kind + - responseObject.kind + - responseObject.message + - responseObject.reason + - responseObject.status + - responseStatus.code + - responseStatus.details.group + - responseStatus.details.kind + - responseStatus.message + - responseStatus.reason + - responseStatus.status + - source + - sourceIPs{} + - sourcetype + - splunk_server + - stage + - stageTimestamp + - tag + - tag::eventtype + - timestamp + - user.groups{} + - user.uid + - user.username + - userAgent + - verb example_log: '{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"RequestResponse","auditID":"582c31ab-4906-49bb-9ff9-872f980ccb84","stage":"ResponseComplete","requestURI":"/apis/batch/v1/namespaces/test2/jobs?fieldManager=kubectl-create\u0026fieldValidation=Strict","verb":"create","user":{"username":"k8s-test-user","uid":"aws-iam-authenticator:591511147606:AROAYTOGP2RLFHNBOTP5J","groups":["system:authenticated"]},"sourceIPs":["176.95.188.101"],"userAgent":"kubectl/v1.27.2 (darwin/arm64) kubernetes/7f6f68f","objectRef":{"resource":"jobs","namespace":"test2","apiGroup":"batch","apiVersion":"v1"},"responseStatus":{"metadata":{},"status":"Failure","message":"jobs.batch is forbidden: User \"k8s-test-user\" cannot create resource \"jobs\" in API group diff --git a/data_sources/kubernetes_falco.yml b/data_sources/kubernetes_falco.yml index 6b21e39781..cff1b27f1c 100644 --- a/data_sources/kubernetes_falco.yml +++ b/data_sources/kubernetes_falco.yml @@ -1,54 +1,55 @@ name: Kubernetes Falco id: 23c0eeed-840a-4711-a41b-6819c1ffbba5 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs suspicious or anomalous activities within a Kubernetes environment detected by Falco, including system calls, file access, and network activity. +description: Logs suspicious or anomalous activities within a Kubernetes environment + detected by Falco, including system calls, file access, and network activity. mitre_components: -- File Access -- Network Traffic Content -- Process Creation -- Process Modification -- Application Log Content -- Host Status + - File Access + - Network Traffic Content + - Process Creation + - Process Modification + - Application Log Content + - Host Status source: kubernetes sourcetype: kube:container:falco supported_TA: [] fields: -- _time -- command -- container_id -- container_image -- container_image_tag -- container_name -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- evt_type -- exe_flags -- host -- index -- k8s_ns -- k8s_pod_name -- linecount -- parent -- proc_exepath -- process -- punct -- source -- sourcetype -- splunk_server -- terminal -- timeendpos -- timestartpos -- user -- user_loginuid -- user_uid + - _time + - command + - container_id + - container_image + - container_image_tag + - container_name + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - evt_type + - exe_flags + - host + - index + - k8s_ns + - k8s_pod_name + - linecount + - parent + - proc_exepath + - process + - punct + - source + - sourcetype + - splunk_server + - terminal + - timeendpos + - timestartpos + - user + - user_loginuid + - user_uid example_log: '12:18:18.691725165: Notice A shell was spawned in a container with an attached terminal (evt_type=execve user=root user_uid=0 user_loginuid=-1 process=bash proc_exepath=/usr/lib/splunk-otel-collector/agent-bundle/bin/bash parent=runc command=bash diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml index 1b6bb6ba17..da361ede71 100644 --- a/data_sources/linux_auditd_add_user.yml +++ b/data_sources/linux_auditd_add_user.yml @@ -1,40 +1,44 @@ name: Linux Auditd Add User id: 30f79353-e1d2-4585-8735-1e0359559f3f -version: 1 -date: '2024-08-08' +version: 2 +date: '2025-01-23' author: Teoderick Contreras, Splunk -description: Logs activities related to the addition of a new user account on a Linux system, including details about the username, UID, and the process initiating the action. +description: Logs activities related to the addition of a new user account on a Linux + system, including details about the username, UID, and the process initiating the + action. mitre_components: -- User Account Creation -- User Account Metadata -- OS API Execution -- Application Log Content + - User Account Creation + - User Account Metadata + - OS API Execution + - Application Log Content source: /var/log/audit/audit.log sourcetype: linux:audit separator: type separator_value: ADD_USER configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: -- name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 + - name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: -- msg -- type -- pid -- uid -- auid -- ses -- subj -- msg -- op -- id -- exe -- hostname -- addr -- terminal -- res -- UID -- AUID -- ID -example_log: 'type=ADD_USER msg=audit(1722950859.266:6994): pid=1788 uid=0 auid=1000 ses=1 subj=unconfined msg=''op=adding user id=1002 exe="/usr/sbin/useradd" hostname=ar-linux1 addr=? terminal=pts/1 res=success''UID="root" AUID="ubuntu" ID="unknown(1002)"' + - msg + - type + - pid + - uid + - auid + - ses + - subj + - msg + - op + - id + - exe + - hostname + - addr + - terminal + - res + - UID + - AUID + - ID +example_log: "type=ADD_USER msg=audit(1722950859.266:6994): pid=1788 uid=0 auid=1000 + ses=1 subj=unconfined msg='op=adding user id=1002 exe=\"/usr/sbin/useradd\" hostname=ar-linux1 + addr=? terminal=pts/1 res=success'UID=\"root\" AUID=\"ubuntu\" ID=\"unknown(1002)\"" diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml index f70b98a8f9..72433806de 100644 --- a/data_sources/linux_auditd_execve.yml +++ b/data_sources/linux_auditd_execve.yml @@ -1,27 +1,29 @@ name: Linux Auditd Execve id: 9ef6364d-cc67-480e-8448-3306829a6a24 -version: 1 -date: '2024-08-08' +version: 2 +date: '2025-01-23' author: Teoderick Contreras, Splunk -description: Logs the execution of processes on a Linux system, including details about the executed command, arguments, and the initiating process. +description: Logs the execution of processes on a Linux system, including details + about the executed command, arguments, and the initiating process. mitre_components: -- Command Execution -- Process Creation -- Process Metadata -- OS API Execution -- Application Log Content + - Command Execution + - Process Creation + - Process Metadata + - OS API Execution + - Application Log Content source: /var/log/audit/audit.log sourcetype: linux:audit separator: type separator_value: EXECVE configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: -- name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 + - name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: -- msg -- type -- msg -- argc -example_log: 'type=EXECVE msg=audit(1723044684.257:15795): argc=3 a0="sudo" a1="LD_PRELOAD=./myfopen.so" a2="./prog"' + - msg + - type + - msg + - argc +example_log: 'type=EXECVE msg=audit(1723044684.257:15795): argc=3 a0="sudo" a1="LD_PRELOAD=./myfopen.so" + a2="./prog"' diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml index 3dd0c9d22a..d612530b4e 100644 --- a/data_sources/linux_auditd_path.yml +++ b/data_sources/linux_auditd_path.yml @@ -1,41 +1,44 @@ name: Linux Auditd Path id: 3d86125c-0496-4a5a-aae3-0d355a4f3d7d -version: 1 -date: '2024-08-08' +version: 2 +date: '2025-01-23' author: Teoderick Contreras, Splunk -description: Logs file system access events on a Linux system, including details about file paths, permissions, and associated processes. +description: Logs file system access events on a Linux system, including details about + file paths, permissions, and associated processes. mitre_components: -- File Access -- File Metadata -- Process Metadata -- OS API Execution -- Application Log Content + - File Access + - File Metadata + - Process Metadata + - OS API Execution + - Application Log Content source: /var/log/audit/audit.log sourcetype: linux:audit separator: type separator_value: PATH configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: -- name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 + - name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: -- msg -- type -- item -- name -- inode -- dev -- mode -- ouid -- ogid -- rdev -- nametype -- cap_fp -- cap_fi -- cap_fe -- cap_fver -- cap_frootid -- OUID -- OGID -example_log: 'type=PATH msg=audit(1723043687.149:14898): item=1 name="/etc/ssh/ssh_config~" inode=1292 dev=103:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 nametype=DELETE cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 OUID="root" OGID="root"' + - msg + - type + - item + - name + - inode + - dev + - mode + - ouid + - ogid + - rdev + - nametype + - cap_fp + - cap_fi + - cap_fe + - cap_fver + - cap_frootid + - OUID + - OGID +example_log: 'type=PATH msg=audit(1723043687.149:14898): item=1 name="/etc/ssh/ssh_config~" + inode=1292 dev=103:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 nametype=DELETE cap_fp=0 + cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 OUID="root" OGID="root"' diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml index e0038b6a94..fbd067aed5 100644 --- a/data_sources/linux_auditd_proctitle.yml +++ b/data_sources/linux_auditd_proctitle.yml @@ -1,25 +1,26 @@ name: Linux Auditd Proctitle id: 5a25984a-2789-400a-858b-d75c923e06b1 -version: 1 -date: '2024-08-08' +version: 2 +date: '2025-01-23' author: Teoderick Contreras, Splunk -description: Logs the full command-line arguments of a process execution on a Linux system, providing visibility into the executed command and its parameters. +description: Logs the full command-line arguments of a process execution on a Linux + system, providing visibility into the executed command and its parameters. mitre_components: -- Command Execution -- Process Metadata -- OS API Execution -- Application Log Content + - Command Execution + - Process Metadata + - OS API Execution + - Application Log Content separator: type separator_value: PROCTITLE source: /var/log/audit/audit.log sourcetype: linux:audit configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: -- name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 + - name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: -- proctitle -- msg -- type + - proctitle + - msg + - type example_log: 'type=PROCTITLE msg=audit(1722944427.844:4146): proctitle=63686D6F640037373700312E7368' diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml index 3c4f41bcbf..8b1c94b0f2 100644 --- a/data_sources/linux_auditd_service_stop.yml +++ b/data_sources/linux_auditd_service_stop.yml @@ -1,38 +1,42 @@ name: Linux Auditd Service Stop id: 0643483c-bc62-455c-8d6e-1630e5f0e00d -version: 1 -date: '2024-08-08' +version: 2 +date: '2025-01-23' author: Teoderick Contreras, Splunk -description: Logs events related to the stoppage of a service on a Linux system, including details about the service name, the process initiating the stop, and associated timestamps. +description: Logs events related to the stoppage of a service on a Linux system, including + details about the service name, the process initiating the stop, and associated + timestamps. mitre_components: -- Service Modification -- Service Metadata -- OS API Execution -- Application Log Content + - Service Modification + - Service Metadata + - OS API Execution + - Application Log Content separator: type separator_value: SERVICE_STOP source: /var/log/audit/audit.log sourcetype: linux:audit configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: -- name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 + - name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: -- msg -- type -- pid -- uid -- auid -- ses -- subj -- msg -- comm -- exe -- hostname -- addr -- terminal -- res -- UID -- AUID -example_log: 'type=SERVICE_STOP msg=audit(1722957155.494:4802): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=unconfined msg=''unit=atd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success''UID="root" AUID="unset"' + - msg + - type + - pid + - uid + - auid + - ses + - subj + - msg + - comm + - exe + - hostname + - addr + - terminal + - res + - UID + - AUID +example_log: "type=SERVICE_STOP msg=audit(1722957155.494:4802): pid=1 uid=0 auid=4294967295 + ses=4294967295 subj=unconfined msg='unit=atd comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\"\ + \ hostname=? addr=? terminal=? res=success'UID=\"root\" AUID=\"unset\"" diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml index 46f043e357..c753a66b54 100644 --- a/data_sources/linux_auditd_syscall.yml +++ b/data_sources/linux_auditd_syscall.yml @@ -1,61 +1,67 @@ name: Linux Auditd Syscall id: 4dff7047-0d43-4096-bb3f-b756c889bbad -version: 1 -date: '2024-08-08' +version: 2 +date: '2025-01-23' author: Teoderick Contreras, Splunk -description: Logs system calls made by processes on a Linux system, including details about the syscall number, arguments, return values, and associated process metadata. +description: Logs system calls made by processes on a Linux system, including details + about the syscall number, arguments, return values, and associated process metadata. mitre_components: -- OS API Execution -- Process Metadata -- Application Log Content -- Host Status + - OS API Execution + - Process Metadata + - Application Log Content + - Host Status source: /var/log/audit/audit.log sourcetype: linux:audit separator: type separator_value: syscall configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: -- name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 + - name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: -- msg -- type -- msg -- arch -- syscall -- success -- exit -- a1 -- a2 -- a3 -- items -- ppid -- pid -- auid -- uid -- gid -- euid -- suid -- fsuid -- egid -- sgid -- fsgid -- tty -- ses -- comm -- exe -- subj -- key -- ARCH -- SYSCALL -- AUID -- UID -- GID -- EUID -- SUID -- FSUID -- EGID -- SGID -- FSGID -example_log: 'type=SYSCALL msg=audit(1723035666.627:3663): arch=c000003e syscall=59 success=yes exit=0 a0=556a6d697a58 a1=556a6d68ad00 a2=556a6d69c980 a3=0 items=2 ppid=1300 pid=1301 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=1 comm="lsmod" exe="/usr/bin/kmod" subj=unconfined key="rootcmd" ARCH=x86_64 SYSCALL=execve AUID="ubuntu" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"' + - msg + - type + - msg + - arch + - syscall + - success + - exit + - a1 + - a2 + - a3 + - items + - ppid + - pid + - auid + - uid + - gid + - euid + - suid + - fsuid + - egid + - sgid + - fsgid + - tty + - ses + - comm + - exe + - subj + - key + - ARCH + - SYSCALL + - AUID + - UID + - GID + - EUID + - SUID + - FSUID + - EGID + - SGID + - FSGID +example_log: 'type=SYSCALL msg=audit(1723035666.627:3663): arch=c000003e syscall=59 + success=yes exit=0 a0=556a6d697a58 a1=556a6d68ad00 a2=556a6d69c980 a3=0 items=2 + ppid=1300 pid=1301 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 + tty=pts1 ses=1 comm="lsmod" exe="/usr/bin/kmod" subj=unconfined key="rootcmd" ARCH=x86_64 + SYSCALL=execve AUID="ubuntu" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" + EGID="root" SGID="root" FSGID="root"' diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index 1f1c1917e3..e6f8b78160 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -1,53 +1,54 @@ name: Linux Secure id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs authentication and authorization events on a Linux system, including login attempts, SSH connections, and privilege escalation activities. +description: Logs authentication and authorization events on a Linux system, including + login attempts, SSH connections, and privilege escalation activities. mitre_components: -- User Account Authentication -- Logon Session Creation -- Logon Session Metadata -- User Account Metadata -- Application Log Content + - User Account Authentication + - Logon Session Creation + - Logon Session Metadata + - User Account Metadata + - Application Log Content source: /var/log/secure sourcetype: linux_secure supported_TA: [] fields: -- _time -- action -- app -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- eventtype -- host -- index -- linecount -- pid -- process -- punct -- source -- sourcetype -- splunk_server -- src -- src_port -- sshd_protocol -- tag -- tag::action -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_name -- vendor_action -- vendor_product + - _time + - action + - app + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - eventtype + - host + - index + - linecount + - pid + - process + - punct + - source + - sourcetype + - splunk_server + - src + - src_port + - sshd_protocol + - tag + - tag::action + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_name + - vendor_action + - vendor_product example_log: 'May 27 09:28:36 ip-172-31-24-46 sshd[5617]: Accepted password for mikael from 84.202.159.161 port 63487 ssh2' diff --git a/data_sources/ms365_defender_incident_alerts.yml b/data_sources/ms365_defender_incident_alerts.yml index d8114c0151..80e582df46 100644 --- a/data_sources/ms365_defender_incident_alerts.yml +++ b/data_sources/ms365_defender_incident_alerts.yml @@ -1,189 +1,241 @@ name: MS365 Defender Incident Alerts id: 12345678-90ab-cdef-1234-567890abcdef -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Bhavin Patel, Splunk -description: Logs security incidents and correlated alerts in Microsoft 365 Defender, including details about affected assets, threat types, and remediation steps. +description: Logs security incidents and correlated alerts in Microsoft 365 Defender, + including details about affected assets, threat types, and remediation steps. mitre_components: -- Host Status -- User Account Metadata -- Application Log Content -- Malware Metadata -- Active Directory Object Access + - Host Status + - User Account Metadata + - Application Log Content + - Malware Metadata + - Active Directory Object Access source: ms365_defender_incident_alerts sourcetype: ms365:defender:incident:alerts supported_TA: -- name: Splunk Add-on for Microsoft Security - url: https://splunkbase.splunk.com/app/6207 - version: 2.4.1 + - name: Splunk Add-on for Microsoft Security + url: https://splunkbase.splunk.com/app/6207 + version: 2.4.1 fields: -- actorName -- alertId -- app -- assignedTo -- body -- category -- classification -- creationTime -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- description -- dest -- detectionSource -- detectorId -- determination -- devices{}.aadDeviceId -- devices{}.defenderAvStatus -- devices{}.deviceDnsName -- devices{}.firstSeen -- devices{}.healthStatus -- devices{}.loggedOnUsers{}.accountName -- devices{}.loggedOnUsers{}.domainName -- devices{}.mdatpDeviceId -- devices{}.onboardingStatus -- devices{}.osBuild -- devices{}.osPlatform -- devices{}.osProcessor -- devices{}.rbacGroupName -- devices{}.riskScore -- devices{}.version -- devices{}.vmMetadata -- devices{}.vmMetadata.cloudProvider -- devices{}.vmMetadata.resourceId -- devices{}.vmMetadata.subscriptionId -- devices{}.vmMetadata.vmId -- entities{}.aadUserId -- entities{}.accountName -- entities{}.applicationId -- entities{}.applicationName -- entities{}.detectionStatus -- entities{}.deviceId -- entities{}.domainName -- entities{}.entityType -- entities{}.evidenceCreationTime -- entities{}.fileName -- entities{}.filePath -- entities{}.ipAddress -- entities{}.parentProcessCreationTime -- entities{}.parentProcessFileName -- entities{}.parentProcessFilePath -- entities{}.parentProcessId -- entities{}.processCommandLine -- entities{}.processCreationTime -- entities{}.processId -- entities{}.remediationStatus -- entities{}.remediationStatusDetails -- entities{}.sha1 -- entities{}.sha256 -- entities{}.userPrincipalName -- entities{}.userSid -- entities{}.verdict -- eventtype -- firstActivity -- host -- id -- incidentId -- index -- investigationId -- investigationState -- lastActivity -- lastUpdatedTime -- linecount -- mitreTechniques{} -- mitre_technique_id -- providerAlertId -- resolvedTime -- serviceSource -- severity -- signature -- signature_id -- source -- sourcetype -- splunk_server -- splunk_server_group -- src -- status -- subject -- tag -- tag::app -- tag::eventtype -- threatFamilyName -- timeendpos -- timestartpos -- title -- type -- user -- user_name -- _bkt -- _cd -- _eventtype_color -- _indextime -- _raw -- _serial -- _si -- _sourcetype -- _subsecond -- _time -example_log: "{\n \"alertId\": \"da638001130101730338_582949328\",\n \"providerAlertId\"\ - : \"da638001130101730338_582949328\",\n \"incidentId\": 486,\n \"serviceSource\"\ - : \"MicrosoftDefenderForEndpoint\",\n \"creationTime\": \"2022-09-30T05:36:50.1732198Z\"\ - ,\n \"lastUpdatedTime\": \"2022-11-19T01:35:42.7033333Z\",\n \"resolvedTime\"\ - : \"2022-10-01T01:36:00.5066667Z\",\n \"firstActivity\": \"2022-09-30T05:06:43.8196597Z\"\ - ,\n \"lastActivity\": \"2022-09-30T05:06:43.8196597Z\",\n \"title\": \"Suspicious\ - \ URL clicked\",\n \"description\": \"A user opened a potentially malicious URL.\ - \ This alert was triggered based on a Microsoft Defender for Office 365 alert.\"\ - ,\n \"category\": \"InitialAccess\",\n \"status\": \"Resolved\",\n \"severity\"\ - : \"High\",\n \"investigationId\": null,\n \"investigationState\": \"UnsupportedAlertType\"\ - ,\n \"classification\": \"TruePositive\",\n \"determination\": \"SecurityTesting\"\ - ,\n \"detectionSource\": \"MTP\",\n \"detectorId\": \"359b36eb-337c-4f1c-b280-8c5e08f9c4a0\"\ - ,\n \"assignedTo\": \"msftadmin@metal.m365dpoc.com\",\n \"actorName\": null,\n\ - \ \"threatFamilyName\": null,\n \"mitreTechniques\": [\n \"T1566.002\"\n ],\n\ - \ \"devices\": [\n {\n \"mdatpDeviceId\": \"c7e147cb0eb3534a4dcea5acb8e61c933713b145\"\ - ,\n \"aadDeviceId\": null,\n \"deviceDnsName\": \"metal-win10v.metal.m365dpoc.com\"\ - ,\n \"osPlatform\": \"Windows10\",\n \"version\": \"1809\",\n \"\ - osProcessor\": \"x64\",\n \"osBuild\": 17763,\n \"healthStatus\": \"Active\"\ - ,\n \"riskScore\": \"High\",\n \"rbacGroupName\": \"Full Auto Clients\"\ - ,\n \"firstSeen\": \"2022-08-08T08:51:02.455Z\",\n \"tags\": [\n \ - \ \"Full auto\"\n ],\n \"defenderAvStatus\": \"Updated\",\n \"\ - onboardingStatus\": \"Onboarded\",\n \"vmMetadata\": {\n \"vmId\": \"\ - 17881b39-b03f-4a2c-9b56-078be1330bd0\",\n \"cloudProvider\": \"Unknown\"\ - ,\n \"resourceId\": \"/subscriptions/29e73d07-8740-4164-a257-592a19a7b77c/resourceGroups/MSDXV2/providers/Microsoft.Compute/virtualMachines/MSDXV2-Win10V\"\ - ,\n \"subscriptionId\": \"29e73d07-8740-4164-a257-592a19a7b77c\"\n },\n\ - \ \"loggedOnUsers\": [\n {\n \"accountName\": \"hetfield\"\ - ,\n \"domainName\": \"MSDXV2\"\n }\n ]\n }\n ],\n \"entities\"\ - : [\n {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\":\ - \ \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\ - remediationStatus\": \"None\",\n \"sha1\": \"6cbce4a295c163791b60fc23d285e6d84f28ee4c\"\ - ,\n \"sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\"\ - ,\n \"fileName\": \"powershell.exe\",\n \"filePath\": \"\",\n \"\ - processId\": 7068,\n \"processCommandLine\": \"powershell.exe -command \\\"\ - \ $Process = New-Object\ - \ System.Diagnostics.Process; \ - \ $Process.StartInfo.FileName = 'https://nam12.safelinks.protection.outlook.com/?url=http%3A%2F%2Fgcajebahdi.corporatelogon.xyz%2Fab%2Fjnkmbkkdnlgedc&data=05%7C01%7Chetfield%40metal.m365dpoc.com%7Cca409616a82145bd6a5f08daa2a10255%7C1a49212958c8401191cd245285f5345c%7C0%7C0%7C638001109710345383%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=FyEjRS5qOd2SkJELlueibuxLFMYNjL7fz8EbuOAvFwg%3D&reserved=0';\ - \ $Process.StartInfo.UseShellExecute\ - \ = $true; $Process.Start()\ - \ | Out-Null; \\\" \ - \ \",\n \"processCreationTime\"\ - : \"2022-09-30T05:06:43.3390523Z\",\n \"parentProcessId\": 7116,\n \"\ - parentProcessCreationTime\": \"2022-09-30T05:06:43.3100364Z\",\n \"accountName\"\ - : \"hetfield\",\n \"userSid\": \"S-1-5-21-2300221942-1987151257-321556088-1104\"\ - \n },\n {\n \"entityType\": \"File\",\n \"evidenceCreationTime\"\ - : \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\ - remediationStatus\": \"None\",\n \"sha1\": \"6cbce4a295c163791b60fc23d285e6d84f28ee4c\"\ - ,\n \"sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\"\ - ,\n \"fileName\": \"powershell.exe\",\n \"filePath\": \"\"\n },\n \ - \ {\n \"entityType\": \"User\",\n \"evidenceCreationTime\": \"2022-09-30T05:36:50.2133333Z\"\ - ,\n \"verdict\": \"Suspicious\",\n \"remediationStatus\": \"None\",\n\ - \ \"accountName\": \"hetfield\",\n \"domainName\": \"metal.m365dpoc\"\ - ,\n \"userSid\": \"S-1-5-21-2300221942-1987151257-321556088-1104\",\n \ - \ \"aadUserId\": \"e848b07a-87af-4448-9979-09f0b809c8d4\",\n \"userPrincipalName\"\ - : \"daftpunk\"\n },\n {\n \"entityType\": \"Url\",\n \"evidenceCreationTime\"\ - : \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\ - remediationStatus\": \"None\",\n \"url\": \"http://gcajebahdi.corporatelogon.xyz/ab/jnkmbkkdnlgedc\"\ - \n }\n ]\n}" + - actorName + - alertId + - app + - assignedTo + - body + - category + - classification + - creationTime + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - description + - dest + - detectionSource + - detectorId + - determination + - devices{}.aadDeviceId + - devices{}.defenderAvStatus + - devices{}.deviceDnsName + - devices{}.firstSeen + - devices{}.healthStatus + - devices{}.loggedOnUsers{}.accountName + - devices{}.loggedOnUsers{}.domainName + - devices{}.mdatpDeviceId + - devices{}.onboardingStatus + - devices{}.osBuild + - devices{}.osPlatform + - devices{}.osProcessor + - devices{}.rbacGroupName + - devices{}.riskScore + - devices{}.version + - devices{}.vmMetadata + - devices{}.vmMetadata.cloudProvider + - devices{}.vmMetadata.resourceId + - devices{}.vmMetadata.subscriptionId + - devices{}.vmMetadata.vmId + - entities{}.aadUserId + - entities{}.accountName + - entities{}.applicationId + - entities{}.applicationName + - entities{}.detectionStatus + - entities{}.deviceId + - entities{}.domainName + - entities{}.entityType + - entities{}.evidenceCreationTime + - entities{}.fileName + - entities{}.filePath + - entities{}.ipAddress + - entities{}.parentProcessCreationTime + - entities{}.parentProcessFileName + - entities{}.parentProcessFilePath + - entities{}.parentProcessId + - entities{}.processCommandLine + - entities{}.processCreationTime + - entities{}.processId + - entities{}.remediationStatus + - entities{}.remediationStatusDetails + - entities{}.sha1 + - entities{}.sha256 + - entities{}.userPrincipalName + - entities{}.userSid + - entities{}.verdict + - eventtype + - firstActivity + - host + - id + - incidentId + - index + - investigationId + - investigationState + - lastActivity + - lastUpdatedTime + - linecount + - mitreTechniques{} + - mitre_technique_id + - providerAlertId + - resolvedTime + - serviceSource + - severity + - signature + - signature_id + - source + - sourcetype + - splunk_server + - splunk_server_group + - src + - status + - subject + - tag + - tag::app + - tag::eventtype + - threatFamilyName + - timeendpos + - timestartpos + - title + - type + - user + - user_name + - _bkt + - _cd + - _eventtype_color + - _indextime + - _raw + - _serial + - _si + - _sourcetype + - _subsecond + - _time +example_log: |- + { + "alertId": "da638001130101730338_582949328", + "providerAlertId": "da638001130101730338_582949328", + "incidentId": 486, + "serviceSource": "MicrosoftDefenderForEndpoint", + "creationTime": "2022-09-30T05:36:50.1732198Z", + "lastUpdatedTime": "2022-11-19T01:35:42.7033333Z", + "resolvedTime": "2022-10-01T01:36:00.5066667Z", + "firstActivity": "2022-09-30T05:06:43.8196597Z", + "lastActivity": "2022-09-30T05:06:43.8196597Z", + "title": "Suspicious URL clicked", + "description": "A user opened a potentially malicious URL. This alert was triggered based on a Microsoft Defender for Office 365 alert.", + "category": "InitialAccess", + "status": "Resolved", + "severity": "High", + "investigationId": null, + "investigationState": "UnsupportedAlertType", + "classification": "TruePositive", + "determination": "SecurityTesting", + "detectionSource": "MTP", + "detectorId": "359b36eb-337c-4f1c-b280-8c5e08f9c4a0", + "assignedTo": "msftadmin@metal.m365dpoc.com", + "actorName": null, + "threatFamilyName": null, + "mitreTechniques": [ + "T1566.002" + ], + "devices": [ + { + "mdatpDeviceId": "c7e147cb0eb3534a4dcea5acb8e61c933713b145", + "aadDeviceId": null, + "deviceDnsName": "metal-win10v.metal.m365dpoc.com", + "osPlatform": "Windows10", + "version": "1809", + "osProcessor": "x64", + "osBuild": 17763, + "healthStatus": "Active", + "riskScore": "High", + "rbacGroupName": "Full Auto Clients", + "firstSeen": "2022-08-08T08:51:02.455Z", + "tags": [ + "Full auto" + ], + "defenderAvStatus": "Updated", + "onboardingStatus": "Onboarded", + "vmMetadata": { + "vmId": "17881b39-b03f-4a2c-9b56-078be1330bd0", + "cloudProvider": "Unknown", + "resourceId": "/subscriptions/29e73d07-8740-4164-a257-592a19a7b77c/resourceGroups/MSDXV2/providers/Microsoft.Compute/virtualMachines/MSDXV2-Win10V", + "subscriptionId": "29e73d07-8740-4164-a257-592a19a7b77c" + }, + "loggedOnUsers": [ + { + "accountName": "hetfield", + "domainName": "MSDXV2" + } + ] + } + ], + "entities": [ + { + "entityType": "Process", + "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z", + "verdict": "Suspicious", + "remediationStatus": "None", + "sha1": "6cbce4a295c163791b60fc23d285e6d84f28ee4c", + "sha256": "de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c", + "fileName": "powershell.exe", + "filePath": "", + "processId": 7068, + "processCommandLine": "powershell.exe -command \" $Process = New-Object System.Diagnostics.Process; $Process.StartInfo.FileName = 'https://nam12.safelinks.protection.outlook.com/?url=http%3A%2F%2Fgcajebahdi.corporatelogon.xyz%2Fab%2Fjnkmbkkdnlgedc&data=05%7C01%7Chetfield%40metal.m365dpoc.com%7Cca409616a82145bd6a5f08daa2a10255%7C1a49212958c8401191cd245285f5345c%7C0%7C0%7C638001109710345383%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=FyEjRS5qOd2SkJELlueibuxLFMYNjL7fz8EbuOAvFwg%3D&reserved=0'; $Process.StartInfo.UseShellExecute = $true; $Process.Start() | Out-Null; \" ", + "processCreationTime": "2022-09-30T05:06:43.3390523Z", + "parentProcessId": 7116, + "parentProcessCreationTime": "2022-09-30T05:06:43.3100364Z", + "accountName": "hetfield", + "userSid": "S-1-5-21-2300221942-1987151257-321556088-1104" + }, + { + "entityType": "File", + "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z", + "verdict": "Suspicious", + "remediationStatus": "None", + "sha1": "6cbce4a295c163791b60fc23d285e6d84f28ee4c", + "sha256": "de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c", + "fileName": "powershell.exe", + "filePath": "" + }, + { + "entityType": "User", + "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z", + "verdict": "Suspicious", + "remediationStatus": "None", + "accountName": "hetfield", + "domainName": "metal.m365dpoc", + "userSid": "S-1-5-21-2300221942-1987151257-321556088-1104", + "aadUserId": "e848b07a-87af-4448-9979-09f0b809c8d4", + "userPrincipalName": "daftpunk" + }, + { + "entityType": "Url", + "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z", + "verdict": "Suspicious", + "remediationStatus": "None", + "url": "http://gcajebahdi.corporatelogon.xyz/ab/jnkmbkkdnlgedc" + } + ] + } diff --git a/data_sources/ms_defender_atp_alerts.yml b/data_sources/ms_defender_atp_alerts.yml index 09026a67d5..f1f68b0b7e 100644 --- a/data_sources/ms_defender_atp_alerts.yml +++ b/data_sources/ms_defender_atp_alerts.yml @@ -1,278 +1,429 @@ name: MS Defender ATP Alerts id: 38f034ed-1598-46c8-95e8-14edf01fdf5d -version: 1 -date: '2024-10-30' +version: 2 +date: '2025-01-23' author: Bryan Pluta, Bhavin Patel, Splunk -description: Logs security alerts generated by Microsoft Defender for Endpoint, including information about detected threats, impacted devices, and recommended actions. +description: Logs security alerts generated by Microsoft Defender for Endpoint, including + information about detected threats, impacted devices, and recommended actions. mitre_components: -- Host Status -- Malware Metadata -- Process Metadata -- User Account Metadata -- Application Log Content + - Host Status + - Malware Metadata + - Process Metadata + - User Account Metadata + - Application Log Content source: ms_defender_atp_alerts sourcetype: ms:defender:atp:alerts supported_TA: -- name: Splunk Add-on for Microsoft Security - url: https://splunkbase.splunk.com/app/6207 - version: 2.4.1 + - name: Splunk Add-on for Microsoft Security + url: https://splunkbase.splunk.com/app/6207 + version: 2.4.1 fields: -- column -- accountName -- action -- activity -- activityType -- actor -- actorName -- alertId -- app -- assignedTo -- body -- category -- classification -- creationTime -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- description -- dest -- detectionSource -- detectorId -- determination -- devices{}.aadDeviceId -- devices{}.defenderAvStatus -- devices{}.deviceDnsName -- devices{}.firstSeen -- devices{}.healthStatus -- devices{}.loggedOnUsers{}.accountName -- devices{}.loggedOnUsers{}.domainName -- devices{}.mdatpDeviceId -- devices{}.onboardingStatus -- devices{}.osBuild -- devices{}.osPlatform -- devices{}.osProcessor -- devices{}.rbacGroupName -- devices{}.riskScore -- devices{}.version -- devices{}.vmMetadata -- devices{}.vmMetadata.cloudProvider -- devices{}.vmMetadata.resourceId -- devices{}.vmMetadata.subscriptionId -- devices{}.vmMetadata.vmId -- entities{}.aadUserId -- entities{}.accountName -- entities{}.applicationId -- entities{}.applicationName -- entities{}.detectionStatus -- entities{}.deviceId -- entities{}.domainName -- entities{}.entityType -- entities{}.evidenceCreationTime -- entities{}.fileName -- entities{}.filePath -- entities{}.ipAddress -- entities{}.parentProcessCreationTime -- entities{}.parentProcessFileName -- entities{}.parentProcessFilePath -- entities{}.parentProcessId -- entities{}.processCommandLine -- entities{}.processCreationTime -- entities{}.processId -- entities{}.remediationStatus -- entities{}.remediationStatusDetails -- entities{}.sha1 -- entities{}.sha256 -- entities{}.userPrincipalName -- entities{}.userSid -- entities{}.verdict -- eventtype -- firstActivity -- host -- id -- incidentId -- index -- investigationId -- investigationState -- lastActivity -- lastUpdatedTime -- linecount -- mitreTechniques{} -- mitre_technique_id -- providerAlertId -- resolvedTime -- serviceSource -- severity -- signature -- signature_id -- source -- sourcetype -- splunk_server -- splunk_server_group -- src -- status -- subject -- tag -- tag::app -- tag::eventtype -- threatFamilyName -- timeendpos -- timestartpos -- title -- type -- user -- user_name -- _time -example_log: "{\n\"id\": \"da47dc5671-e560-4229-984b-457564996b31_1\",\n\"incidentId\"\ - : 989,\n\"investigationId\": null,\n\"assignedTo\": null,\n\"severity\": \"High\"\ - ,\n\"status\": \"New\",\n\"classification\": null,\n\"determination\": null,\n\"\ - investigationState\": \"UnsupportedAlertType\",\n\"detectionSource\": \"WindowsDefenderAtp\"\ - ,\n\"detectorId\": \"9c3a70ec-e18a-4f92-865a-530f73130b7c\",\n\"category\": \"LateralMovement\"\ - ,\n\"threatFamilyName\": null,\n\"title\": \"Ongoing hands-on-keyboard attack via\ - \ Impacket toolkit\",\n\"description\": \"Suspicious execution of a command via\ - \ Impacket was observed on this device. This tool connects to other hosts to explore\ - \ network shares and execute commands. Attackers might be attempting to move laterally\ - \ across the network using this tool. This usage of Impacket has often been observed\ - \ in hands-on-keyboard attacks, where ransomware and other payloads are installed\ - \ on target devices.\",\n\"alertCreationTime\": \"2023-01-24T05:33:37.3245808Z\"\ - ,\n\"firstEventTime\": \"2023-01-24T05:31:07.5276179Z\",\n\"lastEventTime\": \"\ - 2023-01-24T13:02:50.7831636Z\",\n\"lastUpdateTime\": \"2023-01-24T13:07:13.3233333Z\"\ - ,\n\"resolvedTime\": null,\n\"machineId\": \"302293d9f276eae65553e5042156bce93cbc7148\"\ - ,\n\"computerDnsName\": \"diytestmachine\",\n\"rbacGroupName\": \"UnassignedGroup\"\ - ,\n\"aadTenantId\": \"1a492129-58c8-4011-91cd-245285f5345c\",\n\"threatName\": null,\n\ - \"mitreTechniques\": [\n \"T1021.002\",\n \"T1047\",\n \"T1059.003\"\n],\n\"\ - relatedUser\": {\n \"userName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\"\ - \n},\n\"loggedOnUsers\": [\n {\n \"accountName\": \"administrator1\",\n \"\ - domainName\": \"DIYTESTMACHINE\"\n }\n],\n\"comments\": [],\n\"evidence\": [\n\ - \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:45:51.6833333Z\"\ - ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\ - \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\ - fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\ - wbem\",\n \"processId\": 4476,\n \"processCommandLine\": \"wmiprvse.exe -secured\ - \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:43:32.4631151Z\",\n\ - \ \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\ - ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\ - : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\ - \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ - : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ - accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \ - \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\ - : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\ - User\",\n \"evidenceCreationTime\": \"2023-01-24T05:33:37.4166667Z\",\n \"\ - sha1\": null,\n \"sha256\": null,\n \"fileName\": null,\n \"filePath\"\ - : null,\n \"processId\": null,\n \"processCommandLine\": null,\n \"processCreationTime\"\ - : null,\n \"parentProcessId\": null,\n \"parentProcessCreationTime\": null,\n\ - \ \"parentProcessFileName\": null,\n \"parentProcessFilePath\": null,\n \ - \ \"ipAddress\": null,\n \"url\": null,\n \"registryKey\": null,\n \"\ - registryHive\": null,\n \"registryValueType\": null,\n \"registryValue\":\ - \ null,\n \"registryValueName\": null,\n \"accountName\": \"User1\",\n \ - \ \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\": \"S-1-5-21-4215714199-1288013905-3478400915-1002\"\ - ,\n \"aadUserId\": null,\n \"userPrincipalName\": null,\n \"detectionStatus\"\ - : null\n },\n {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\"\ - : \"2023-01-24T05:33:37.4166667Z\",\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\"\ - ,\n \"sha256\": \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\"\ - ,\n \"fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\ - \\wbem\",\n \"processId\": 7824,\n \"processCommandLine\": \"wmiprvse.exe\ - \ -secured -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:30:50.8649791Z\"\ - ,\n \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\ - ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\ - : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\ - \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ - : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ - accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \ - \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\ - : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\ - Process\",\n \"evidenceCreationTime\": \"2023-01-24T13:07:13.2233333Z\",\n \ - \ \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\": \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\"\ - ,\n \"fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\"\ - ,\n \"processId\": 5500,\n \"processCommandLine\": \"cmd.exe /Q /c powershell\ - \ -NoProfile -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\\ - Desktop\\\\SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\ - \\__1674565222.7012053 2>&1\",\n \"processCreationTime\": \"2023-01-24T13:02:50.4661885Z\"\ - ,\n \"parentProcessId\": 756,\n \"parentProcessCreationTime\": \"2023-01-24T13:00:35.0107475Z\"\ - ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\ - : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\ - : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ - : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ - accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\ - : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\ - \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\ - \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:33:37.4166667Z\"\ - ,\n \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\":\ - \ \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\",\n \"\ - fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\",\n \ - \ \"processId\": 8964,\n \"processCommandLine\": \"cmd.exe /Q /c powershell -NoProfile\ - \ -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\Desktop\\\\\ - SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\\__1674538248.357367\ - \ 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:31:04.0743902Z\",\n \"\ - parentProcessId\": 7824,\n \"parentProcessCreationTime\": \"2023-01-24T05:30:50.8649791Z\"\ - ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\ - : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\ - : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ - : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ - accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\ - : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\ - \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\ - \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:39:47.1733333Z\"\ - ,\n \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\":\ - \ \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\",\n \"\ - fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\",\n \ - \ \"processId\": 884,\n \"processCommandLine\": \"cmd.exe /Q /c powershell -NoProfile\ - \ -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\Desktop\\\\\ - SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\\__1674538583.8648584\ - \ 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:36:38.826505Z\",\n \"\ - parentProcessId\": 7736,\n \"parentProcessCreationTime\": \"2023-01-24T05:36:26.0524655Z\"\ - ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\ - : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\ - : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ - : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ - accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\ - : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\ - \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\ - \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T13:07:13.2233333Z\"\ - ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\ - \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\ - fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\ - wbem\",\n \"processId\": 756,\n \"processCommandLine\": \"wmiprvse.exe -secured\ - \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T13:00:35.0107475Z\",\n\ - \ \"parentProcessId\": 908,\n \"parentProcessCreationTime\": \"2023-01-24T08:20:44.6877667Z\"\ - ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\ - : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\ - \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ - : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ - accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \ - \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\ - : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\ - Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:45:51.6833333Z\",\n \ - \ \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\": \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\"\ - ,\n \"fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\"\ - ,\n \"processId\": 1140,\n \"processCommandLine\": \"cmd.exe /Q /c powershell\ - \ -NoProfile -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\\ - Desktop\\\\SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\ - \\__1674538878.1586335 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:43:49.9375398Z\"\ - ,\n \"parentProcessId\": 4476,\n \"parentProcessCreationTime\": \"2023-01-24T05:43:32.4631151Z\"\ - ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\ - : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\ - : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ - : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ - accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\ - : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\ - \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\ - \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:39:47.1733333Z\"\ - ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\ - \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\ - fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\ - wbem\",\n \"processId\": 7736,\n \"processCommandLine\": \"wmiprvse.exe -secured\ - \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:36:26.0524655Z\",\n\ - \ \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\ - ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\ - : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\ - \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ - : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ - accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \ - \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\ - : null,\n \"detectionStatus\": \"Detected\"\n }\n],\n\"domains\": []\n}" + - column + - accountName + - action + - activity + - activityType + - actor + - actorName + - alertId + - app + - assignedTo + - body + - category + - classification + - creationTime + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - description + - dest + - detectionSource + - detectorId + - determination + - devices{}.aadDeviceId + - devices{}.defenderAvStatus + - devices{}.deviceDnsName + - devices{}.firstSeen + - devices{}.healthStatus + - devices{}.loggedOnUsers{}.accountName + - devices{}.loggedOnUsers{}.domainName + - devices{}.mdatpDeviceId + - devices{}.onboardingStatus + - devices{}.osBuild + - devices{}.osPlatform + - devices{}.osProcessor + - devices{}.rbacGroupName + - devices{}.riskScore + - devices{}.version + - devices{}.vmMetadata + - devices{}.vmMetadata.cloudProvider + - devices{}.vmMetadata.resourceId + - devices{}.vmMetadata.subscriptionId + - devices{}.vmMetadata.vmId + - entities{}.aadUserId + - entities{}.accountName + - entities{}.applicationId + - entities{}.applicationName + - entities{}.detectionStatus + - entities{}.deviceId + - entities{}.domainName + - entities{}.entityType + - entities{}.evidenceCreationTime + - entities{}.fileName + - entities{}.filePath + - entities{}.ipAddress + - entities{}.parentProcessCreationTime + - entities{}.parentProcessFileName + - entities{}.parentProcessFilePath + - entities{}.parentProcessId + - entities{}.processCommandLine + - entities{}.processCreationTime + - entities{}.processId + - entities{}.remediationStatus + - entities{}.remediationStatusDetails + - entities{}.sha1 + - entities{}.sha256 + - entities{}.userPrincipalName + - entities{}.userSid + - entities{}.verdict + - eventtype + - firstActivity + - host + - id + - incidentId + - index + - investigationId + - investigationState + - lastActivity + - lastUpdatedTime + - linecount + - mitreTechniques{} + - mitre_technique_id + - providerAlertId + - resolvedTime + - serviceSource + - severity + - signature + - signature_id + - source + - sourcetype + - splunk_server + - splunk_server_group + - src + - status + - subject + - tag + - tag::app + - tag::eventtype + - threatFamilyName + - timeendpos + - timestartpos + - title + - type + - user + - user_name + - _time +example_log: |- + { + "id": "da47dc5671-e560-4229-984b-457564996b31_1", + "incidentId": 989, + "investigationId": null, + "assignedTo": null, + "severity": "High", + "status": "New", + "classification": null, + "determination": null, + "investigationState": "UnsupportedAlertType", + "detectionSource": "WindowsDefenderAtp", + "detectorId": "9c3a70ec-e18a-4f92-865a-530f73130b7c", + "category": "LateralMovement", + "threatFamilyName": null, + "title": "Ongoing hands-on-keyboard attack via Impacket toolkit", + "description": "Suspicious execution of a command via Impacket was observed on this device. This tool connects to other hosts to explore network shares and execute commands. Attackers might be attempting to move laterally across the network using this tool. This usage of Impacket has often been observed in hands-on-keyboard attacks, where ransomware and other payloads are installed on target devices.", + "alertCreationTime": "2023-01-24T05:33:37.3245808Z", + "firstEventTime": "2023-01-24T05:31:07.5276179Z", + "lastEventTime": "2023-01-24T13:02:50.7831636Z", + "lastUpdateTime": "2023-01-24T13:07:13.3233333Z", + "resolvedTime": null, + "machineId": "302293d9f276eae65553e5042156bce93cbc7148", + "computerDnsName": "diytestmachine", + "rbacGroupName": "UnassignedGroup", + "aadTenantId": "1a492129-58c8-4011-91cd-245285f5345c", + "threatName": null, + "mitreTechniques": [ + "T1021.002", + "T1047", + "T1059.003" + ], + "relatedUser": { + "userName": "User1", + "domainName": "DIYTESTMACHINE" + }, + "loggedOnUsers": [ + { + "accountName": "administrator1", + "domainName": "DIYTESTMACHINE" + } + ], + "comments": [], + "evidence": [ + { + "entityType": "Process", + "evidenceCreationTime": "2023-01-24T05:45:51.6833333Z", + "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c", + "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3", + "fileName": "WmiPrvSE.exe", + "filePath": "C:\\Windows\\System32\\wbem", + "processId": 4476, + "processCommandLine": "wmiprvse.exe -secured -Embedding", + "processCreationTime": "2023-01-24T05:43:32.4631151Z", + "parentProcessId": 896, + "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z", + "parentProcessFileName": "svchost.exe", + "parentProcessFilePath": "C:\\Windows\\System32", + "ipAddress": null, + "url": null, + "registryKey": null, + "registryHive": null, + "registryValueType": null, + "registryValue": null, + "registryValueName": null, + "accountName": "NETWORK SERVICE", + "domainName": "NT AUTHORITY", + "userSid": "S-1-5-20", + "aadUserId": null, + "userPrincipalName": null, + "detectionStatus": "Detected" + }, + { + "entityType": "User", + "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z", + "sha1": null, + "sha256": null, + "fileName": null, + "filePath": null, + "processId": null, + "processCommandLine": null, + "processCreationTime": null, + "parentProcessId": null, + "parentProcessCreationTime": null, + "parentProcessFileName": null, + "parentProcessFilePath": null, + "ipAddress": null, + "url": null, + "registryKey": null, + "registryHive": null, + "registryValueType": null, + "registryValue": null, + "registryValueName": null, + "accountName": "User1", + "domainName": "DIYTESTMACHINE", + "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002", + "aadUserId": null, + "userPrincipalName": null, + "detectionStatus": null + }, + { + "entityType": "Process", + "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z", + "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c", + "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3", + "fileName": "WmiPrvSE.exe", + "filePath": "C:\\Windows\\System32\\wbem", + "processId": 7824, + "processCommandLine": "wmiprvse.exe -secured -Embedding", + "processCreationTime": "2023-01-24T05:30:50.8649791Z", + "parentProcessId": 896, + "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z", + "parentProcessFileName": "svchost.exe", + "parentProcessFilePath": "C:\\Windows\\System32", + "ipAddress": null, + "url": null, + "registryKey": null, + "registryHive": null, + "registryValueType": null, + "registryValue": null, + "registryValueName": null, + "accountName": "NETWORK SERVICE", + "domainName": "NT AUTHORITY", + "userSid": "S-1-5-20", + "aadUserId": null, + "userPrincipalName": null, + "detectionStatus": "Detected" + }, + { + "entityType": "Process", + "evidenceCreationTime": "2023-01-24T13:07:13.2233333Z", + "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d", + "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450", + "fileName": "cmd.exe", + "filePath": "C:\\Windows\\System32", + "processId": 5500, + "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674565222.7012053 2>&1", + "processCreationTime": "2023-01-24T13:02:50.4661885Z", + "parentProcessId": 756, + "parentProcessCreationTime": "2023-01-24T13:00:35.0107475Z", + "parentProcessFileName": "WmiPrvSE.exe", + "parentProcessFilePath": "C:\\Windows\\System32\\wbem", + "ipAddress": null, + "url": null, + "registryKey": null, + "registryHive": null, + "registryValueType": null, + "registryValue": null, + "registryValueName": null, + "accountName": "User1", + "domainName": "DIYTESTMACHINE", + "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002", + "aadUserId": null, + "userPrincipalName": null, + "detectionStatus": "Detected" + }, + { + "entityType": "Process", + "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z", + "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d", + "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450", + "fileName": "cmd.exe", + "filePath": "C:\\Windows\\System32", + "processId": 8964, + "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538248.357367 2>&1", + "processCreationTime": "2023-01-24T05:31:04.0743902Z", + "parentProcessId": 7824, + "parentProcessCreationTime": "2023-01-24T05:30:50.8649791Z", + "parentProcessFileName": "WmiPrvSE.exe", + "parentProcessFilePath": "C:\\Windows\\System32\\wbem", + "ipAddress": null, + "url": null, + "registryKey": null, + "registryHive": null, + "registryValueType": null, + "registryValue": null, + "registryValueName": null, + "accountName": "User1", + "domainName": "DIYTESTMACHINE", + "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002", + "aadUserId": null, + "userPrincipalName": null, + "detectionStatus": "Detected" + }, + { + "entityType": "Process", + "evidenceCreationTime": "2023-01-24T05:39:47.1733333Z", + "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d", + "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450", + "fileName": "cmd.exe", + "filePath": "C:\\Windows\\System32", + "processId": 884, + "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538583.8648584 2>&1", + "processCreationTime": "2023-01-24T05:36:38.826505Z", + "parentProcessId": 7736, + "parentProcessCreationTime": "2023-01-24T05:36:26.0524655Z", + "parentProcessFileName": "WmiPrvSE.exe", + "parentProcessFilePath": "C:\\Windows\\System32\\wbem", + "ipAddress": null, + "url": null, + "registryKey": null, + "registryHive": null, + "registryValueType": null, + "registryValue": null, + "registryValueName": null, + "accountName": "User1", + "domainName": "DIYTESTMACHINE", + "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002", + "aadUserId": null, + "userPrincipalName": null, + "detectionStatus": "Detected" + }, + { + "entityType": "Process", + "evidenceCreationTime": "2023-01-24T13:07:13.2233333Z", + "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c", + "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3", + "fileName": "WmiPrvSE.exe", + "filePath": "C:\\Windows\\System32\\wbem", + "processId": 756, + "processCommandLine": "wmiprvse.exe -secured -Embedding", + "processCreationTime": "2023-01-24T13:00:35.0107475Z", + "parentProcessId": 908, + "parentProcessCreationTime": "2023-01-24T08:20:44.6877667Z", + "parentProcessFileName": "svchost.exe", + "parentProcessFilePath": "C:\\Windows\\System32", + "ipAddress": null, + "url": null, + "registryKey": null, + "registryHive": null, + "registryValueType": null, + "registryValue": null, + "registryValueName": null, + "accountName": "NETWORK SERVICE", + "domainName": "NT AUTHORITY", + "userSid": "S-1-5-20", + "aadUserId": null, + "userPrincipalName": null, + "detectionStatus": "Detected" + }, + { + "entityType": "Process", + "evidenceCreationTime": "2023-01-24T05:45:51.6833333Z", + "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d", + "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450", + "fileName": "cmd.exe", + "filePath": "C:\\Windows\\System32", + "processId": 1140, + "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538878.1586335 2>&1", + "processCreationTime": "2023-01-24T05:43:49.9375398Z", + "parentProcessId": 4476, + "parentProcessCreationTime": "2023-01-24T05:43:32.4631151Z", + "parentProcessFileName": "WmiPrvSE.exe", + "parentProcessFilePath": "C:\\Windows\\System32\\wbem", + "ipAddress": null, + "url": null, + "registryKey": null, + "registryHive": null, + "registryValueType": null, + "registryValue": null, + "registryValueName": null, + "accountName": "User1", + "domainName": "DIYTESTMACHINE", + "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002", + "aadUserId": null, + "userPrincipalName": null, + "detectionStatus": "Detected" + }, + { + "entityType": "Process", + "evidenceCreationTime": "2023-01-24T05:39:47.1733333Z", + "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c", + "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3", + "fileName": "WmiPrvSE.exe", + "filePath": "C:\\Windows\\System32\\wbem", + "processId": 7736, + "processCommandLine": "wmiprvse.exe -secured -Embedding", + "processCreationTime": "2023-01-24T05:36:26.0524655Z", + "parentProcessId": 896, + "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z", + "parentProcessFileName": "svchost.exe", + "parentProcessFilePath": "C:\\Windows\\System32", + "ipAddress": null, + "url": null, + "registryKey": null, + "registryHive": null, + "registryValueType": null, + "registryValue": null, + "registryValueName": null, + "accountName": "NETWORK SERVICE", + "domainName": "NT AUTHORITY", + "userSid": "S-1-5-20", + "aadUserId": null, + "userPrincipalName": null, + "detectionStatus": "Detected" + } + ], + "domains": [] + } diff --git a/data_sources/nginx_access.yml b/data_sources/nginx_access.yml index 052bfc81e4..e24bb4163c 100644 --- a/data_sources/nginx_access.yml +++ b/data_sources/nginx_access.yml @@ -1,78 +1,79 @@ name: Nginx Access id: c716a418-eab3-4df5-9dff-5420174e3068 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs HTTP/S access events on an Nginx server, including details such as client IP, request method, URI, response status, and user agent. +description: Logs HTTP/S access events on an Nginx server, including details such + as client IP, request method, URI, response status, and user agent. mitre_components: -- Network Traffic Content -- Network Traffic Flow -- Response Metadata -- Application Log Content -- User Account Metadata + - Network Traffic Content + - Network Traffic Flow + - Response Metadata + - Application Log Content + - User Account Metadata source: /var/log/nginx/access.log sourcetype: nginx:plus:kv supported_TA: [] fields: -- _time -- action -- app -- bytes -- bytes_in -- bytes_out -- category -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_ip -- dest_port -- eventtype -- host -- http_content_type -- http_method -- http_referer -- http_user_agent -- http_user_agent_length -- http_x_forwarded_for -- http_x_header -- https -- index -- linecount -- nginx_version -- product -- protocol -- punct -- request_time -- response_time -- server -- site -- source -- sourcetype -- splunk_server -- src -- src_ip -- status -- status_description -- status_type -- tag -- tag::eventtype -- time_local -- timeendpos -- timestartpos -- uri_path -- url -- url_domain -- url_length -- vendor -- vendor_product -- version -- web_server + - _time + - action + - app + - bytes + - bytes_in + - bytes_out + - category + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_ip + - dest_port + - eventtype + - host + - http_content_type + - http_method + - http_referer + - http_user_agent + - http_user_agent_length + - http_x_forwarded_for + - http_x_header + - https + - index + - linecount + - nginx_version + - product + - protocol + - punct + - request_time + - response_time + - server + - site + - source + - sourcetype + - splunk_server + - src + - src_ip + - status + - status_description + - status_type + - tag + - tag::eventtype + - time_local + - timeendpos + - timestartpos + - uri_path + - url + - url_domain + - url_length + - vendor + - vendor_product + - version + - web_server example_log: site="www.example.com" server="www.example.com" dest_port="443" dest_ip="192.0.2.1" src="198.51.100.1" src_ip="198.51.100.1" user="-" time_local="22/Feb/2024:13:00:00 -0500" protocol="HTTP/1.1" status="200" bytes_out="1073741000" bytes_in="234" http_referer="-" diff --git a/data_sources/o365.yml b/data_sources/o365.yml index efbfc3ee05..3bda514d41 100644 --- a/data_sources/o365.yml +++ b/data_sources/o365.yml @@ -1,19 +1,20 @@ name: O365 id: b32de97d-0074-4cca-853c-db22c392b6c0 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs management activities in Microsoft 365, including administrative actions, user activities, and configuration changes across various services. +description: Logs management activities in Microsoft 365, including administrative + actions, user activities, and configuration changes across various services. mitre_components: -- User Account Metadata -- Cloud Service Modification -- Application Log Content -- Configuration Modification -- Active Directory Object Modification + - User Account Metadata + - Cloud Service Modification + - Application Log Content + - Configuration Modification + - Active Directory Object Modification source: o365 sourcetype: o365:management:activity separator: Operation supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 diff --git a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml index 4c64614e57..a6e90c409a 100644 --- a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml +++ b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml @@ -1,92 +1,93 @@ name: O365 Add app role assignment grant to user. id: ce1d7849-a1d2-47fd-b6eb-d7ef854a860c -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the assignment of an application role grant to a user in Microsoft 365, including details about the role, user, and application involved. +description: Logs the assignment of an application role grant to a user in Microsoft + 365, including details about the role, user, and application involved. mitre_components: -- User Account Modification -- Group Modification -- Cloud Service Modification -- Cloud Service Metadata + - User Account Modification + - Group Modification + - Cloud Service Modification + - Cloud Service Metadata source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add app role assignment grant to user. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- ActorIpAddress -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- ClientIP -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ModifiedProperties{}.Name -- ModifiedProperties{}.NewValue -- ModifiedProperties{}.OldValue -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- additionalDetails -- app -- authentication_service -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- extendedAuditEventCategory -- extended_properties -- host -- index -- linecount -- object -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- src -- src_ip -- src_user -- status -- timeendpos -- timestartpos -- user -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - ActorIpAddress + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - ClientIP + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ModifiedProperties{}.Name + - ModifiedProperties{}.NewValue + - ModifiedProperties{}.OldValue + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - additionalDetails + - app + - authentication_service + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - extendedAuditEventCategory + - extended_properties + - host + - index + - linecount + - object + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - src + - src_ip + - src_user + - status + - timeendpos + - timestartpos + - user + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"Actor": [{"ID": "rodsoto@rodsoto.onmicrosoft.com", "Type": 5}, {"ID": "10037FFEA938FB92", "Type": 3}, {"ID": "74658136-14ec-4630-ad9b-26e160ff0fc6", "Type": 2}, {"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484", "Type": 2}, {"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484", diff --git a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml index 1549f8b091..720652a539 100644 --- a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml +++ b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml @@ -1,91 +1,93 @@ name: O365 Add app role assignment to service principal. id: 785ba57a-ba7b-474e-97c8-9474e6e00b3a -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the assignment of an application role to a service principal in Microsoft 365, including details about the role, service principal, and application involved. +description: Logs the assignment of an application role to a service principal in + Microsoft 365, including details about the role, service principal, and application + involved. mitre_components: -- Cloud Service Modification -- Cloud Service Metadata -- User Account Metadata -- Group Modification + - Cloud Service Modification + - Cloud Service Metadata + - User Account Metadata + - Group Modification source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add app role assignment to service principal. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ModifiedProperties{}.Name -- ModifiedProperties{}.NewValue -- ModifiedProperties{}.OldValue -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- additionalDetails -- app -- authentication_service -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- eventtype -- extendedAuditEventCategory -- host -- index -- linecount -- object -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_agent -- user_agent_change -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ModifiedProperties{}.Name + - ModifiedProperties{}.NewValue + - ModifiedProperties{}.OldValue + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - additionalDetails + - app + - authentication_service + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - eventtype + - extendedAuditEventCategory + - host + - index + - linecount + - object + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_agent + - user_agent_change + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2024-02-08T21:49:53", "Id": "a6bee61d-8b3f-42e1-b4fa-778fb05c43ac", "Operation": "Add app role assignment to service principal.", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "RecordType": 8, "ResultStatus": "Success", diff --git a/data_sources/o365_add_mailboxpermission.yml b/data_sources/o365_add_mailboxpermission.yml index e98765f07b..09a36817fe 100644 --- a/data_sources/o365_add_mailboxpermission.yml +++ b/data_sources/o365_add_mailboxpermission.yml @@ -1,83 +1,85 @@ name: O365 Add-MailboxPermission id: 9c0babdb-bb15-449e-abba-0a9cdb3fc061 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the addition of mailbox permissions in Microsoft 365, including details about the mailbox, granted permissions, and the user or administrator performing the action. +description: Logs the addition of mailbox permissions in Microsoft 365, including + details about the mailbox, granted permissions, and the user or administrator performing + the action. mitre_components: -- User Account Modification -- User Account Metadata -- Active Directory Object Modification -- Application Log Content + - User Account Modification + - User Account Metadata + - Active Directory Object Modification + - Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add-MailboxPermission supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- AccessRights -- AppId -- ClientAppId -- ClientIP -- CreationTime -- ExternalAccess -- Id -- Identity -- InheritanceType -- ObjectId -- Operation -- OrganizationId -- OrganizationName -- OriginatingServer -- Parameters{}.Name -- Parameters{}.Value -- RecordType -- ResultStatus -- SessionId -- User -- UserId -- UserKey -- UserType -- Version -- Workload -- app -- authentication_service -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- host -- index -- linecount -- object -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- src -- src_ip -- status -- timeendpos -- timestartpos -- user -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - AccessRights + - AppId + - ClientAppId + - ClientIP + - CreationTime + - ExternalAccess + - Id + - Identity + - InheritanceType + - ObjectId + - Operation + - OrganizationId + - OrganizationName + - OriginatingServer + - Parameters{}.Name + - Parameters{}.Value + - RecordType + - ResultStatus + - SessionId + - User + - UserId + - UserKey + - UserType + - Version + - Workload + - app + - authentication_service + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - host + - index + - linecount + - object + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - src + - src_ip + - status + - timeendpos + - timestartpos + - user + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"AppId": "", "ClientAppId": "", "ClientIP": "18.159.234.121:30395", "CreationTime": "2020-12-15T10:18:53", "ExternalAccess": false, "Id": "bb6e31a3-e98f-493d-bbff-08d8a0e2d2b0", "ObjectId": "jhernan", "Operation": "Add-MailboxPermission", "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08", diff --git a/data_sources/o365_add_member_to_role_.yml b/data_sources/o365_add_member_to_role_.yml index 3fc466dba1..7a6ea65406 100644 --- a/data_sources/o365_add_member_to_role_.yml +++ b/data_sources/o365_add_member_to_role_.yml @@ -1,94 +1,95 @@ name: O365 Add member to role. id: 8b949f7c-4b5d-404f-9694-d7403c4ec096 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the addition of a member to a role in Microsoft 365, including details about the role, the added member, and the user or administrator performing the action. +description: Logs the addition of a member to a role in Microsoft 365, including details + about the role, the added member, and the user or administrator performing the action. mitre_components: -- Group Modification -- Group Metadata -- User Account Metadata -- Cloud Service Modification + - Group Modification + - Group Metadata + - User Account Metadata + - Cloud Service Modification source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add member to role. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ModifiedProperties{}.Name -- ModifiedProperties{}.NewValue -- ModifiedProperties{}.OldValue -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- action -- additionalDetails -- app -- authentication_service -- change_type -- command -- dataset_name -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- eventtype -- extendedAuditEventCategory -- host -- index -- linecount -- object -- object_attrs -- object_category -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ModifiedProperties{}.Name + - ModifiedProperties{}.NewValue + - ModifiedProperties{}.OldValue + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - action + - additionalDetails + - app + - authentication_service + - change_type + - command + - dataset_name + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - eventtype + - extendedAuditEventCategory + - host + - index + - linecount + - object + - object_attrs + - object_category + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2023-10-20T16:50:46", "Id": "30a8b107-b190-406c-9b80-c3f5c3a29129", "Operation": "Add member to role.", "OrganizationId": "d8211c86-3244-409b-8c4f-ae27ed34b4a5", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com", diff --git a/data_sources/o365_add_owner_to_application_.yml b/data_sources/o365_add_owner_to_application_.yml index 71caf3f806..5c3b3c7f4b 100644 --- a/data_sources/o365_add_owner_to_application_.yml +++ b/data_sources/o365_add_owner_to_application_.yml @@ -1,96 +1,98 @@ name: O365 Add owner to application. id: da012cbf-af6e-40ee-a1ba-32a5f8da8f8a -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the addition of an owner to an application in Microsoft 365, including details about the application, the new owner, and the user or administrator performing the action. +description: Logs the addition of an owner to an application in Microsoft 365, including + details about the application, the new owner, and the user or administrator performing + the action. mitre_components: -- User Account Modification -- Group Modification -- Cloud Service Modification -- Cloud Service Metadata + - User Account Modification + - Group Modification + - Cloud Service Modification + - Cloud Service Metadata source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add owner to application. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ModifiedProperties{}.Name -- ModifiedProperties{}.NewValue -- ModifiedProperties{}.OldValue -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- action -- additionalDetails -- app -- authentication_service -- change_type -- command -- dataset_name -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- eventtype -- extendedAuditEventCategory -- host -- index -- linecount -- object -- object_attrs -- object_category -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_agent -- user_agent_change -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ModifiedProperties{}.Name + - ModifiedProperties{}.NewValue + - ModifiedProperties{}.OldValue + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - action + - additionalDetails + - app + - authentication_service + - change_type + - command + - dataset_name + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - eventtype + - extendedAuditEventCategory + - host + - index + - linecount + - object + - object_attrs + - object_category + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_agent + - user_agent_change + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2023-09-07T13:42:04", "Id": "6e2c723b-8f6e-47f4-8c60-fa23ef3fccee", "Operation": "Add owner to application.", "OrganizationId": "48203edf-5d2c-45f2-8123-a368cc8b0e51", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com", diff --git a/data_sources/o365_add_service_principal_.yml b/data_sources/o365_add_service_principal_.yml index 8511ac4c76..806ce7eda5 100644 --- a/data_sources/o365_add_service_principal_.yml +++ b/data_sources/o365_add_service_principal_.yml @@ -1,96 +1,97 @@ name: O365 Add service principal. id: 9c1ef9f5-bc30-4a47-a1bd-cb34484ee778 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the addition of a new service principal in Microsoft 365, including details about the associated application and the action initiator. +description: Logs the addition of a new service principal in Microsoft 365, including + details about the associated application and the action initiator. mitre_components: -- Cloud Service Creation -- Cloud Service Metadata -- User Account Metadata -- Active Directory Object Creation + - Cloud Service Creation + - Cloud Service Metadata + - User Account Metadata + - Active Directory Object Creation source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add service principal. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ModifiedProperties{}.Name -- ModifiedProperties{}.NewValue -- ModifiedProperties{}.OldValue -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- action -- additionalDetails -- app -- authentication_service -- change_type -- command -- dataset_name -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- eventtype -- extendedAuditEventCategory -- host -- index -- linecount -- object_attrs -- object_category -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- src_user -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_agent -- user_agent_change -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ModifiedProperties{}.Name + - ModifiedProperties{}.NewValue + - ModifiedProperties{}.OldValue + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - action + - additionalDetails + - app + - authentication_service + - change_type + - command + - dataset_name + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - eventtype + - extendedAuditEventCategory + - host + - index + - linecount + - object_attrs + - object_category + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - src_user + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_agent + - user_agent_change + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2024-02-07T22:31:14", "Id": "f624ed92-b4a2-4d42-aa8b-20a261d06b7f", "Operation": "Add service principal.", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com", diff --git a/data_sources/o365_change_user_license_.yml b/data_sources/o365_change_user_license_.yml index 2cceff2f8a..cec6ea1cc1 100644 --- a/data_sources/o365_change_user_license_.yml +++ b/data_sources/o365_change_user_license_.yml @@ -1,92 +1,93 @@ name: O365 Change user license. id: 1029a20d-3d0d-4fb9-b5e2-22ac5380b20a -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs changes to user licenses in Microsoft 365, including additions, removals, or updates to service plans associated with a user account. +description: Logs changes to user licenses in Microsoft 365, including additions, + removals, or updates to service plans associated with a user account. mitre_components: -- User Account Modification -- User Account Metadata -- Cloud Service Modification -- Configuration Modification + - User Account Modification + - User Account Metadata + - Cloud Service Modification + - Configuration Modification source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Change user license. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- action -- additionalDetails -- app -- authentication_service -- change_type -- command -- dataset_name -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- eventtype -- extendedAuditEventCategory -- host -- index -- linecount -- object -- object_attrs -- object_category -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- src_user -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - action + - additionalDetails + - app + - authentication_service + - change_type + - command + - dataset_name + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - eventtype + - extendedAuditEventCategory + - host + - index + - linecount + - object + - object_attrs + - object_category + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - src_user + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2023-09-11T15:55:46", "Id": "1e39f32d-081d-4494-994a-533b57f91df7", "Operation": "Change user license.", "OrganizationId": "bbad9541-eb53-4533-bcef-2b76182c3b75", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com", diff --git a/data_sources/o365_consent_to_application_.yml b/data_sources/o365_consent_to_application_.yml index a5df3bc9f2..9a8aacafcd 100644 --- a/data_sources/o365_consent_to_application_.yml +++ b/data_sources/o365_consent_to_application_.yml @@ -1,88 +1,90 @@ name: O365 Consent to application. id: 0a15a464-ef51-4614-9a07-a216eb9817db -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs user or administrator consent to an application's permissions in Microsoft 365, including details about the application, granted permissions, and the consenting user or process. +description: Logs user or administrator consent to an application's permissions in + Microsoft 365, including details about the application, granted permissions, and + the consenting user or process. mitre_components: -- User Account Modification -- Cloud Service Modification -- Cloud Service Metadata -- Configuration Modification + - User Account Modification + - Cloud Service Modification + - Cloud Service Metadata + - Configuration Modification source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Consent to application. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ModifiedProperties{}.Name -- ModifiedProperties{}.NewValue -- ModifiedProperties{}.OldValue -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- additionalDetails -- app -- authentication_service -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- extendedAuditEventCategory -- host -- index -- linecount -- object -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- status -- timeendpos -- timestartpos -- user -- user_agent -- user_agent_change -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ModifiedProperties{}.Name + - ModifiedProperties{}.NewValue + - ModifiedProperties{}.OldValue + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - additionalDetails + - app + - authentication_service + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - extendedAuditEventCategory + - host + - index + - linecount + - object + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - status + - timeendpos + - timestartpos + - user + - user_agent + - user_agent_change + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2023-09-05T21:05:31", "Id": "5822e126-1fbc-4269-9ad6-4c1879cdbcf3", "Operation": "Consent to application.", "OrganizationId": "9c00a473-1b2c-4bc2-9215-84df3f57aee5", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com", diff --git a/data_sources/o365_disable_strong_authentication_.yml b/data_sources/o365_disable_strong_authentication_.yml index ea3fb70491..bd40f2eca5 100644 --- a/data_sources/o365_disable_strong_authentication_.yml +++ b/data_sources/o365_disable_strong_authentication_.yml @@ -1,89 +1,91 @@ name: O365 Disable Strong Authentication. id: 235381c4-382a-4183-b818-a51c3ce12187 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the disabling of strong authentication (e.g., multi-factor authentication) for a user or group in Microsoft 365, including details about the affected accounts and the action initiator. +description: Logs the disabling of strong authentication (e.g., multi-factor authentication) + for a user or group in Microsoft 365, including details about the affected accounts + and the action initiator. mitre_components: -- User Account Modification -- Group Modification -- Configuration Modification -- Application Log Content + - User Account Modification + - Group Modification + - Configuration Modification + - Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Disable Strong Authentication. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- ActorIpAddress -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- ClientIP -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ModifiedProperties{}.Name -- ModifiedProperties{}.NewValue -- ModifiedProperties{}.OldValue -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- additionalDetails -- app -- authentication_service -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- extendedAuditEventCategory -- extended_properties -- host -- index -- linecount -- object -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- status -- timeendpos -- timestartpos -- user -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - ActorIpAddress + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - ClientIP + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ModifiedProperties{}.Name + - ModifiedProperties{}.NewValue + - ModifiedProperties{}.OldValue + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - additionalDetails + - app + - authentication_service + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - extendedAuditEventCategory + - extended_properties + - host + - index + - linecount + - object + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - status + - timeendpos + - timestartpos + - user + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"Actor": [{"ID": "rodsoto@rodsoto.onmicrosoft.com", "Type": 5}, {"ID": "10037FFEA938FB92", "Type": 3}, {"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484", "Type": 2}, {"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484", "Type": 2}, {"ID": "User", diff --git a/data_sources/o365_mailitemsaccessed.yml b/data_sources/o365_mailitemsaccessed.yml index bc03fd713a..49429c5898 100644 --- a/data_sources/o365_mailitemsaccessed.yml +++ b/data_sources/o365_mailitemsaccessed.yml @@ -1,85 +1,86 @@ name: O365 MailItemsAccessed id: 3d5188eb-341a-4b46-9caa-aade4047d027 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs access to mailbox items in Microsoft 365, including details about the user accessing the items, the accessed content, and the method of access. +description: Logs access to mailbox items in Microsoft 365, including details about + the user accessing the items, the accessed content, and the method of access. mitre_components: -- File Access -- User Account Metadata -- Application Log Content -- Active Directory Object Access + - File Access + - User Account Metadata + - Application Log Content + - Active Directory Object Access source: o365 sourcetype: o365:management:activity separator: Operation separator_value: MailItemsAccessed supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- AppId -- ClientAppId -- ClientIPAddress -- ClientInfoString -- CreationTime -- ExternalAccess -- Folders{}.FolderItems{}.InternetMessageId -- Folders{}.FolderItems{}.SizeInBytes -- Folders{}.Id -- Folders{}.Path -- Id -- InternalLogonType -- IsThrottled -- LogonType -- LogonUserSid -- MailAccessType -- MailboxGuid -- MailboxOwnerSid -- MailboxOwnerUPN -- Operation -- OperationCount -- OperationProperties{}.Name -- OperationProperties{}.Value -- OrganizationId -- OrganizationName -- OriginatingServer -- RecordType -- ResultStatus -- UserId -- UserKey -- UserType -- Version -- Workload -- app -- authentication_service -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dvc -- host -- index -- linecount -- punct -- signature -- source -- sourcetype -- splunk_server -- status -- timeendpos -- timestartpos -- user -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - AppId + - ClientAppId + - ClientIPAddress + - ClientInfoString + - CreationTime + - ExternalAccess + - Folders{}.FolderItems{}.InternetMessageId + - Folders{}.FolderItems{}.SizeInBytes + - Folders{}.Id + - Folders{}.Path + - Id + - InternalLogonType + - IsThrottled + - LogonType + - LogonUserSid + - MailAccessType + - MailboxGuid + - MailboxOwnerSid + - MailboxOwnerUPN + - Operation + - OperationCount + - OperationProperties{}.Name + - OperationProperties{}.Value + - OrganizationId + - OrganizationName + - OriginatingServer + - RecordType + - ResultStatus + - UserId + - UserKey + - UserType + - Version + - Workload + - app + - authentication_service + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dvc + - host + - index + - linecount + - punct + - signature + - source + - sourcetype + - splunk_server + - status + - timeendpos + - timestartpos + - user + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2024-02-01T16:07:34", "Id": "9cef02e9-4bfa-4c73-be7d-9dad68b9cea8", "Operation": "MailItemsAccessed", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "RecordType": 50, "ResultStatus": "Succeeded", "UserKey": "100320030DF47B14", "UserType": diff --git a/data_sources/o365_modifyfolderpermissions.yml b/data_sources/o365_modifyfolderpermissions.yml index 76c4e10d20..aca4f79957 100644 --- a/data_sources/o365_modifyfolderpermissions.yml +++ b/data_sources/o365_modifyfolderpermissions.yml @@ -1,103 +1,104 @@ name: O365 ModifyFolderPermissions id: 0a8c1080-68c2-46d7-8324-2e7d97bb6e2f -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs modifications to folder permissions in Microsoft 365, including updates to access levels, user assignments, and sharing settings. +description: Logs modifications to folder permissions in Microsoft 365, including + updates to access levels, user assignments, and sharing settings. mitre_components: -- User Account Modification -- File Access -- Active Directory Object Modification -- Application Log Content + - User Account Modification + - File Access + - Active Directory Object Modification + - Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: ModifyFolderPermissions supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- AppId -- ClientIP -- ClientIPAddress -- ClientInfoString -- CreationTime -- ExternalAccess -- Id -- InternalLogonType -- Item.Id -- Item.ParentFolder.Id -- Item.ParentFolder.MemberRights -- Item.ParentFolder.MemberSid -- Item.ParentFolder.MemberUpn -- Item.ParentFolder.Name -- Item.ParentFolder.Path -- LogonType -- LogonUserSid -- MailboxGuid -- MailboxOwnerSid -- MailboxOwnerUPN -- Operation -- OrganizationId -- OrganizationName -- OriginatingServer -- RecordType -- ResultStatus -- SessionId -- UserId -- UserKey -- UserType -- Version -- Workload -- action -- app -- authentication_service -- change_type -- client_info_str -- command -- dataset_name -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- eventtype -- host -- index -- linecount -- object -- object_attrs -- object_category -- object_id -- punct -- record_type -- result -- signature -- source -- sourcetype -- splunk_server -- src -- src_ip -- status -- tag -- tag::eventtype -- tenant_id -- timeendpos -- timestartpos -- user -- user_agent -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - AppId + - ClientIP + - ClientIPAddress + - ClientInfoString + - CreationTime + - ExternalAccess + - Id + - InternalLogonType + - Item.Id + - Item.ParentFolder.Id + - Item.ParentFolder.MemberRights + - Item.ParentFolder.MemberSid + - Item.ParentFolder.MemberUpn + - Item.ParentFolder.Name + - Item.ParentFolder.Path + - LogonType + - LogonUserSid + - MailboxGuid + - MailboxOwnerSid + - MailboxOwnerUPN + - Operation + - OrganizationId + - OrganizationName + - OriginatingServer + - RecordType + - ResultStatus + - SessionId + - UserId + - UserKey + - UserType + - Version + - Workload + - action + - app + - authentication_service + - change_type + - client_info_str + - command + - dataset_name + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - eventtype + - host + - index + - linecount + - object + - object_attrs + - object_category + - object_id + - punct + - record_type + - result + - signature + - source + - sourcetype + - splunk_server + - src + - src_ip + - status + - tag + - tag::eventtype + - tenant_id + - timeendpos + - timestartpos + - user + - user_agent + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2023-09-07T18:19:07", "Id": "ff065c17-e638-4013-20ab-08dbafceeca1", "Operation": "ModifyFolderPermissions", "OrganizationId": "e17879dd-24ec-44a6-be92-9dcbf6969220", "RecordType": 2, "ResultStatus": "Succeeded", "UserKey": "10032002CC029AE9", "UserType": diff --git a/data_sources/o365_set_company_information_.yml b/data_sources/o365_set_company_information_.yml index 5fab124138..e3da9d7ddd 100644 --- a/data_sources/o365_set_company_information_.yml +++ b/data_sources/o365_set_company_information_.yml @@ -1,97 +1,98 @@ name: O365 Set Company Information. id: 06c6d576-f032-41e3-b15d-80a434ce13d8 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs updates to organizational settings and company information in Microsoft 365, including changes to contact details, branding, and configuration policies. +description: Logs updates to organizational settings and company information in Microsoft + 365, including changes to contact details, branding, and configuration policies. mitre_components: -- Cloud Service Modification -- Configuration Modification -- Cloud Service Metadata -- Application Log Content + - Cloud Service Modification + - Configuration Modification + - Cloud Service Metadata + - Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Set Company Information. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- ActorIpAddress -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- ClientIP -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ModifiedProperties{}.Name -- ModifiedProperties{}.NewValue -- ModifiedProperties{}.OldValue -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- action -- additionalDetails -- app -- authentication_service -- change_type -- command -- dataset_name -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- eventtype -- extendedAuditEventCategory -- extended_properties -- host -- index -- linecount -- object -- object_attrs -- object_category -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - ActorIpAddress + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - ClientIP + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ModifiedProperties{}.Name + - ModifiedProperties{}.NewValue + - ModifiedProperties{}.OldValue + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - action + - additionalDetails + - app + - authentication_service + - change_type + - command + - dataset_name + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - eventtype + - extendedAuditEventCategory + - extended_properties + - host + - index + - linecount + - object + - object_attrs + - object_category + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"Actor": [{"ID": "bpatel@rodsoto.onmicrosoft.com", "Type": 5}, {"ID": "100320010208B5DC", "Type": 3}, {"ID": "User_425b75db-38be-4c7b-a474-5f0709247370", "Type": 2}, {"ID": "425b75db-38be-4c7b-a474-5f0709247370", "Type": 2}, {"ID": "User", diff --git a/data_sources/o365_set_mailbox.yml b/data_sources/o365_set_mailbox.yml index 6849ce100a..9da03f53f4 100644 --- a/data_sources/o365_set_mailbox.yml +++ b/data_sources/o365_set_mailbox.yml @@ -1,93 +1,94 @@ name: O365 Set-Mailbox id: db798c5c-928c-4972-bb42-e5f90e35865f -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs changes to mailbox properties in Microsoft 365, including updates to permissions, storage quotas, and configuration settings. +description: Logs changes to mailbox properties in Microsoft 365, including updates + to permissions, storage quotas, and configuration settings. mitre_components: -- User Account Modification -- Active Directory Object Modification -- User Account Metadata -- Application Log Content + - User Account Modification + - Active Directory Object Modification + - User Account Metadata + - Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Set-Mailbox supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- AppId -- ClientAppId -- ClientIP -- CreationTime -- ExternalAccess -- Id -- Identity -- ObjectId -- Operation -- OrganizationId -- OrganizationName -- OriginatingServer -- Parameters{}.Name -- Parameters{}.Value -- Params -- RecordType -- ResultStatus -- SessionId -- UserId -- UserKey -- UserType -- Version -- Workload -- action -- app -- authentication_service -- change_type -- command -- dataset_name -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- eventtype -- host -- index -- linecount -- object -- object_attrs -- object_category -- object_id -- punct -- record_type -- result -- signature -- source -- sourcetype -- splunk_server -- src -- src_ip -- src_user -- src_user_type -- status -- tag -- tag::eventtype -- tenant_id -- timeendpos -- timestartpos -- user -- user_id -- vendor_account -- vendor_product + - _time + - AppId + - ClientAppId + - ClientIP + - CreationTime + - ExternalAccess + - Id + - Identity + - ObjectId + - Operation + - OrganizationId + - OrganizationName + - OriginatingServer + - Parameters{}.Name + - Parameters{}.Value + - Params + - RecordType + - ResultStatus + - SessionId + - UserId + - UserKey + - UserType + - Version + - Workload + - action + - app + - authentication_service + - change_type + - command + - dataset_name + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - eventtype + - host + - index + - linecount + - object + - object_attrs + - object_category + - object_id + - punct + - record_type + - result + - signature + - source + - sourcetype + - splunk_server + - src + - src_ip + - src_user + - src_user_type + - status + - tag + - tag::eventtype + - tenant_id + - timeendpos + - timestartpos + - user + - user_id + - vendor_account + - vendor_product example_log: '{"AppId": "", "ClientAppId": "", "ClientIP": "18.192.200.190:52816", "CreationTime": "2020-12-16T12:32:28", "ExternalAccess": false, "Id": "a6a52406-0912-448d-36eb-08d8a1bea6be", "ObjectId": "bpatel", "Operation": "Set-Mailbox", "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08", diff --git a/data_sources/o365_update_application_.yml b/data_sources/o365_update_application_.yml index 155f1353ca..2b04a3230b 100644 --- a/data_sources/o365_update_application_.yml +++ b/data_sources/o365_update_application_.yml @@ -1,96 +1,97 @@ name: O365 Update application. id: 62159133-911b-4c63-9e30-a6a8c89195ca -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs updates made to applications in Microsoft 365, including changes to configurations, permissions, and role assignments. +description: Logs updates made to applications in Microsoft 365, including changes + to configurations, permissions, and role assignments. mitre_components: -- Cloud Service Modification -- Configuration Modification -- Cloud Service Metadata -- Application Log Content + - Cloud Service Modification + - Configuration Modification + - Cloud Service Metadata + - Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Update application. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ModifiedProperties{}.Name -- ModifiedProperties{}.NewValue -- ModifiedProperties{}.OldValue -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- action -- additionalDetails -- app -- authentication_service -- change_type -- command -- dataset_name -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- eventtype -- extendedAuditEventCategory -- host -- index -- linecount -- object -- object_attrs -- object_category -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_agent -- user_agent_change -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ModifiedProperties{}.Name + - ModifiedProperties{}.NewValue + - ModifiedProperties{}.OldValue + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - action + - additionalDetails + - app + - authentication_service + - change_type + - command + - dataset_name + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - eventtype + - extendedAuditEventCategory + - host + - index + - linecount + - object + - object_attrs + - object_category + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_agent + - user_agent_change + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2023-09-01T17:16:20", "Id": "c428c85c-4fa0-4e97-9033-6a76d9dee45d", "Operation": "Update application.", "OrganizationId": "58aee3b9-7433-46a0-b54e-2429487992a0", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com", diff --git a/data_sources/o365_update_authorization_policy_.yml b/data_sources/o365_update_authorization_policy_.yml index 2438a25b16..90825eca41 100644 --- a/data_sources/o365_update_authorization_policy_.yml +++ b/data_sources/o365_update_authorization_policy_.yml @@ -1,88 +1,89 @@ name: O365 Update authorization policy. id: d40e6a20-4d64-404c-8351-2caae8228d34 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs changes to authorization policies in Microsoft 365, including updates to access controls, permissions, and security settings. +description: Logs changes to authorization policies in Microsoft 365, including updates + to access controls, permissions, and security settings. mitre_components: -- Cloud Service Modification -- Configuration Modification -- User Account Metadata -- Application Log Content + - Cloud Service Modification + - Configuration Modification + - User Account Metadata + - Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Update authorization policy. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ModifiedProperties{}.Name -- ModifiedProperties{}.NewValue -- ModifiedProperties{}.OldValue -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- additionalDetails -- app -- authentication_service -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- extendedAuditEventCategory -- host -- index -- linecount -- object -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- status -- timeendpos -- timestartpos -- user -- user_agent -- user_agent_change -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ModifiedProperties{}.Name + - ModifiedProperties{}.NewValue + - ModifiedProperties{}.OldValue + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - additionalDetails + - app + - authentication_service + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - extendedAuditEventCategory + - host + - index + - linecount + - object + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - status + - timeendpos + - timestartpos + - user + - user_agent + - user_agent_change + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2023-10-26T19:22:20", "Id": "83774e72-313f-4d1f-8609-7d0c7bb3b4ff", "Operation": "Update authorization policy.", "OrganizationId": "a417c578-c7ee-480d-a225-d48057e74df5", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com", diff --git a/data_sources/o365_update_user_.yml b/data_sources/o365_update_user_.yml index 308a4ac7a4..f733a674a4 100644 --- a/data_sources/o365_update_user_.yml +++ b/data_sources/o365_update_user_.yml @@ -1,95 +1,96 @@ name: O365 Update user. id: a05fd01e-34d9-4233-9089-11272416b531 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs updates to user account properties in Microsoft 365, including changes to roles, permissions, and profile information. +description: Logs updates to user account properties in Microsoft 365, including changes + to roles, permissions, and profile information. mitre_components: -- User Account Modification -- User Account Metadata -- Active Directory Object Modification -- Application Log Content + - User Account Modification + - User Account Metadata + - Active Directory Object Modification + - Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Update user. supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- Actor{}.ID -- Actor{}.Type -- AzureActiveDirectoryEventType -- CreationTime -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- ModifiedProperties{}.Name -- ModifiedProperties{}.NewValue -- ModifiedProperties{}.OldValue -- ObjectId -- Operation -- OrganizationId -- RecordType -- ResultStatus -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserId -- UserKey -- UserType -- Version -- Workload -- action -- additionalDetails -- app -- authentication_service -- change_type -- command -- dataset_name -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- eventtype -- extendedAuditEventCategory -- host -- index -- linecount -- object -- object_attrs -- object_category -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- src_user -- status -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_id -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - Actor{}.ID + - Actor{}.Type + - AzureActiveDirectoryEventType + - CreationTime + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - ModifiedProperties{}.Name + - ModifiedProperties{}.NewValue + - ModifiedProperties{}.OldValue + - ObjectId + - Operation + - OrganizationId + - RecordType + - ResultStatus + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserId + - UserKey + - UserType + - Version + - Workload + - action + - additionalDetails + - app + - authentication_service + - change_type + - command + - dataset_name + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - eventtype + - extendedAuditEventCategory + - host + - index + - linecount + - object + - object_attrs + - object_category + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - src_user + - status + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_id + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2023-10-20T19:32:59", "Id": "d06df1c6-b3f2-4595-90b9-99b8f91811c3", "Operation": "Update user.", "OrganizationId": "99825d50-9544-4061-8e46-68923805cbf2", "RecordType": 8, "ResultStatus": "Success", "UserKey": "10032002CC029AE9@splunkresearch1.onmicrosoft.com", diff --git a/data_sources/o365_userloggedin.yml b/data_sources/o365_userloggedin.yml index 3296cb188a..f9169deaee 100644 --- a/data_sources/o365_userloggedin.yml +++ b/data_sources/o365_userloggedin.yml @@ -1,95 +1,96 @@ name: O365 UserLoggedIn id: ed29c8c4-4053-419c-b133-16abf2a1c4c9 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs successful login events by users in Microsoft 365, including details about the user account, IP address, and session metadata. +description: Logs successful login events by users in Microsoft 365, including details + about the user account, IP address, and session metadata. mitre_components: -- User Account Authentication -- Logon Session Creation -- User Account Metadata -- Logon Session Metadata + - User Account Authentication + - Logon Session Creation + - User Account Metadata + - Logon Session Metadata source: o365 sourcetype: o365:management:activity separator: Operation separator_value: UserLoggedIn supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- ActorIpAddress -- Actor{}.ID -- Actor{}.Type -- ApplicationId -- AzureActiveDirectoryEventType -- BrowserType -- ClientIP -- CreationTime -- DeviceProperties{}.Name -- DeviceProperties{}.Value -- ErrorNumber -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- OS -- ObjectId -- Operation -- OrganizationId -- RecordType -- RequestType -- ResultStatus -- ResultStatusDetail -- SessionId -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserAgent -- UserId -- UserKey -- UserType -- Version -- Workload -- app -- authentication_service -- command -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- host -- index -- linecount -- object -- punct -- record_type -- signature -- source -- sourcetype -- splunk_server -- src -- src_ip -- status -- timeendpos -- timestartpos -- user -- user_agent -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - ActorIpAddress + - Actor{}.ID + - Actor{}.Type + - ApplicationId + - AzureActiveDirectoryEventType + - BrowserType + - ClientIP + - CreationTime + - DeviceProperties{}.Name + - DeviceProperties{}.Value + - ErrorNumber + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - OS + - ObjectId + - Operation + - OrganizationId + - RecordType + - RequestType + - ResultStatus + - ResultStatusDetail + - SessionId + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserAgent + - UserId + - UserKey + - UserType + - Version + - Workload + - app + - authentication_service + - command + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - host + - index + - linecount + - object + - punct + - record_type + - signature + - source + - sourcetype + - splunk_server + - src + - src_ip + - status + - timeendpos + - timestartpos + - user + - user_agent + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2023-12-04T20:42:05", "Id": "52d72a62-132b-487b-bb7f-c4c119f90700", "Operation": "UserLoggedIn", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "RecordType": 15, "ResultStatus": "Success", "UserKey": "2d2f9e2c-8350-4d98-852e-3f06daaf7185", diff --git a/data_sources/o365_userloginfailed.yml b/data_sources/o365_userloginfailed.yml index dfea247775..8f3df80a3f 100644 --- a/data_sources/o365_userloginfailed.yml +++ b/data_sources/o365_userloginfailed.yml @@ -1,104 +1,105 @@ name: O365 UserLoginFailed id: 6099b33d-d581-43ed-8401-911862590361 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs failed login attempts by users in Microsoft 365, including details about the user account, IP address, and reason for failure. +description: Logs failed login attempts by users in Microsoft 365, including details + about the user account, IP address, and reason for failure. mitre_components: -- User Account Authentication -- Logon Session Metadata -- User Account Metadata -- Application Log Content + - User Account Authentication + - Logon Session Metadata + - User Account Metadata + - Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: UserLoginFailed supported_TA: -- name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 + - name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: -- _time -- ActorContextId -- ActorIpAddress -- Actor{}.ID -- Actor{}.Type -- ApplicationId -- AzureActiveDirectoryEventType -- BrowserType -- ClientIP -- CreationTime -- DeviceProperties{}.Name -- DeviceProperties{}.Value -- ErrorNumber -- ExtendedProperties{}.Name -- ExtendedProperties{}.Value -- Id -- InterSystemsId -- IntraSystemId -- IsCompliantAndManaged -- LogonError -- OS -- ObjectId -- Operation -- OrganizationId -- RecordType -- RequestType -- ResultStatus -- ResultStatusDetail -- SupportTicketId -- TargetContextId -- Target{}.ID -- Target{}.Type -- UserAgent -- UserAuthenticationMethod -- UserId -- UserKey -- UserType -- Version -- Workload -- action -- app -- authentication_method -- authentication_service -- command -- dataset_name -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_name -- dvc -- event_type -- eventtype -- host -- index -- linecount -- object -- punct -- reason -- record_type -- result -- signature -- source -- sourcetype -- splunk_server -- src -- src_ip -- status -- tag -- tag::action -- tag::eventtype -- user -- user_agent -- user_type -- vendor_account -- vendor_product + - _time + - ActorContextId + - ActorIpAddress + - Actor{}.ID + - Actor{}.Type + - ApplicationId + - AzureActiveDirectoryEventType + - BrowserType + - ClientIP + - CreationTime + - DeviceProperties{}.Name + - DeviceProperties{}.Value + - ErrorNumber + - ExtendedProperties{}.Name + - ExtendedProperties{}.Value + - Id + - InterSystemsId + - IntraSystemId + - IsCompliantAndManaged + - LogonError + - OS + - ObjectId + - Operation + - OrganizationId + - RecordType + - RequestType + - ResultStatus + - ResultStatusDetail + - SupportTicketId + - TargetContextId + - Target{}.ID + - Target{}.Type + - UserAgent + - UserAuthenticationMethod + - UserId + - UserKey + - UserType + - Version + - Workload + - action + - app + - authentication_method + - authentication_service + - command + - dataset_name + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_name + - dvc + - event_type + - eventtype + - host + - index + - linecount + - object + - punct + - reason + - record_type + - result + - signature + - source + - sourcetype + - splunk_server + - src + - src_ip + - status + - tag + - tag::action + - tag::eventtype + - user + - user_agent + - user_type + - vendor_account + - vendor_product example_log: '{"CreationTime": "2023-10-10T17:08:65", "Id": "4593aac8-855f-4341-9d2a-4289146eb800", "Operation": "UserLoginFailed", "OrganizationId": "d541aae6-6b73-4a7c-aaf0-a4de30c872bc", "RecordType": 15, "ResultStatus": "Failed", "UserKey": "57e4bd36-9722-4a4a-9729-7203d8e00b72", diff --git a/data_sources/okta.yml b/data_sources/okta.yml index 27417c8961..4c4de15b28 100644 --- a/data_sources/okta.yml +++ b/data_sources/okta.yml @@ -1,18 +1,19 @@ name: Okta id: ec26febe-e760-4981-bbee-72e107c7b9d2 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs authentication and administrative activities captured by Okta, including user login attempts, session management, and configuration changes. +description: Logs authentication and administrative activities captured by Okta, including + user login attempts, session management, and configuration changes. mitre_components: -- User Account Authentication -- Logon Session Creation -- User Account Metadata -- Configuration Modification -- Application Log Content + - User Account Authentication + - Logon Session Creation + - User Account Metadata + - Configuration Modification + - Application Log Content source: Okta sourcetype: OktaIM2:log supported_TA: -- name: Splunk Add-on for Okta Identity Cloud - url: https://splunkbase.splunk.com/app/6553 - version: 3.0.0 + - name: Splunk Add-on for Okta Identity Cloud + url: https://splunkbase.splunk.com/app/6553 + version: 3.0.0 diff --git a/data_sources/osquery.yml b/data_sources/osquery.yml index bd8cb58790..b2b1828e0f 100644 --- a/data_sources/osquery.yml +++ b/data_sources/osquery.yml @@ -1,72 +1,73 @@ name: osquery id: 7ec4d7c8-c1d0-423a-9169-261f6adb74c0 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs system queries performed using osquery, including details about processes, file access, network activity, and system configurations. +description: Logs system queries performed using osquery, including details about + processes, file access, network activity, and system configurations. mitre_components: -- Process Metadata -- File Access -- Network Traffic Content -- Host Status -- Application Log Content + - Process Metadata + - File Access + - Network Traffic Content + - Host Status + - Application Log Content source: osquery sourcetype: osquery:results supported_TA: [] fields: -- _time -- calendarTime -- columns.cdhash -- columns.child_pid -- columns.cmdline -- columns.cmdline_count -- columns.cwd -- columns.egid -- columns.env -- columns.env_count -- columns.euid -- columns.event_type -- columns.exit_code -- columns.gid -- columns.global_seq_num -- columns.original_parent -- columns.parent -- columns.path -- columns.pid -- columns.platform_binary -- columns.seq_num -- columns.signing_id -- columns.team_id -- columns.time -- columns.uid -- columns.username -- columns.version -- counter -- dest -- epoch -- eventtype -- host -- hostIdentifier -- index -- linecount -- name -- numerics -- parent_process_id -- process_current_directory -- process_id -- process_path -- punct -- source -- sourcetype -- splunk_server -- src -- subject -- tag -- tag::eventtype -- timestamp -- unixTime -- user_id -- vendor_product + - _time + - calendarTime + - columns.cdhash + - columns.child_pid + - columns.cmdline + - columns.cmdline_count + - columns.cwd + - columns.egid + - columns.env + - columns.env_count + - columns.euid + - columns.event_type + - columns.exit_code + - columns.gid + - columns.global_seq_num + - columns.original_parent + - columns.parent + - columns.path + - columns.pid + - columns.platform_binary + - columns.seq_num + - columns.signing_id + - columns.team_id + - columns.time + - columns.uid + - columns.username + - columns.version + - counter + - dest + - epoch + - eventtype + - host + - hostIdentifier + - index + - linecount + - name + - numerics + - parent_process_id + - process_current_directory + - process_id + - process_path + - punct + - source + - sourcetype + - splunk_server + - src + - subject + - tag + - tag::eventtype + - timestamp + - unixTime + - user_id + - vendor_product example_log: '{"name":"es_process_events","hostIdentifier":"HackBook.local","calendarTime":"Tue Mar 29 13:03:51 2022 UTC","unixTime":1648559031,"epoch":0,"counter":82,"numerics":false,"columns":{"cdhash":"f63c5fbfcf1484b20aa4407a26e087fe3fe28146","child_pid":"","cmdline":"plutil --help ","cmdline_count":"2","cwd":"/Users/patrick","egid":"20","env":"TERM_SESSION_ID=w0t1p0:93AA9D79-7028-49F1-A93D-4EAEFB7BA6E3 diff --git a/data_sources/palo_alto_network_threat.yml b/data_sources/palo_alto_network_threat.yml index d9c2937be9..48d799c14e 100644 --- a/data_sources/palo_alto_network_threat.yml +++ b/data_sources/palo_alto_network_threat.yml @@ -1,43 +1,45 @@ name: Palo Alto Network Threat id: 375c2b0e-d216-41ad-9406-200464595209 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs detected threats identified by Palo Alto Networks devices, including details about malware, intrusion attempts, and malicious network activity. +description: Logs detected threats identified by Palo Alto Networks devices, including + details about malware, intrusion attempts, and malicious network activity. mitre_components: -- Malware Metadata -- Network Traffic Content -- Network Traffic Flow -- Application Log Content -- Host Status + - Malware Metadata + - Network Traffic Content + - Network Traffic Flow + - Application Log Content + - Host Status source: pan:threat sourcetype: pan:threat supported_TA: -- name: Palo Alto Networks Add-on - url: https://splunkbase.splunk.com/app/2757 - version: 8.1.3 + - name: Palo Alto Networks Add-on + url: https://splunkbase.splunk.com/app/2757 + version: 8.1.3 fields: -- _time -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- host -- index -- linecount -- punct -- source -- sourcetype -- splunk_server -- timeendpos -- timestartpos + - _time + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - host + - index + - linecount + - punct + - source + - sourcetype + - splunk_server + - timeendpos + - timestartpos example_log: May 10 11:08:39 sjc.example.com 1,2022/05/10 11:08:38,013201004583,THREAT,url,2305,2022/05/10 11:08:38,2.18.4.7,1.2.3.4,2.18.4.7,1.2.3.4,service-globalprotect,,,web-browsing,vsys1,UNTRUST,UNTRUST,ethernet1/20,loopback.1,Zero,2022/05/10 11:08:38,1535535,1,32880,443,32880,20077,0x1403000,tcp,allow,"sr.example.com/mgmt/tm/util/bash",(9999),allow-URL,informational,client-to-server,7081856864553612091,0xa000000000000000,United States,United States,0,,0,,,1,"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 - (KHTML, like Gecko) Chrome/36.0.1944.0 Safari/537.36",,,,,,,0,177,204,178,382,,sjc1-fw-01,,,,post,0,,0,,N/A,unknown,AppThreat-0-0,0x0,0,4294967295,," + (KHTML, like Gecko) Chrome/36.0.1944.0 + Safari/537.36",,,,,,,0,177,204,178,382,,sjc1-fw-01,,,,post,0,,0,,N/A,unknown,AppThreat-0-0,0x0,0,4294967295,," allow-URL,computer-and-internet-info,low-risk",5283cb95-6902-41db-96c6-ef807361eba5,0, diff --git a/data_sources/palo_alto_network_traffic.yml b/data_sources/palo_alto_network_traffic.yml index 02afe2d863..c4673e3fe7 100644 --- a/data_sources/palo_alto_network_traffic.yml +++ b/data_sources/palo_alto_network_traffic.yml @@ -1,41 +1,44 @@ name: Palo Alto Network Traffic id: 182a83bc-c31a-4817-8c7a-263744cec52a -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs network traffic events captured by Palo Alto Networks devices, including details about sessions, protocols, and source and destination IPs. +description: Logs network traffic events captured by Palo Alto Networks devices, including + details about sessions, protocols, and source and destination IPs. mitre_components: -- Network Traffic Content -- Network Traffic Flow -- Network Connection Creation -- Response Metadata -- Application Log Content + - Network Traffic Content + - Network Traffic Flow + - Network Connection Creation + - Response Metadata + - Application Log Content source: screenconnect_palo_traffic sourcetype: pan:traffic supported_TA: -- name: Palo Alto Networks Add-on - url: https://splunkbase.splunk.com/app/2757 - version: 8.1.3 + - name: Palo Alto Networks Add-on + url: https://splunkbase.splunk.com/app/2757 + version: 8.1.3 fields: -- _time -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- host -- index -- linecount -- punct -- source -- sourcetype -- splunk_server -- timeendpos -- timestartpos + - _time + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - host + - index + - linecount + - punct + - source + - sourcetype + - splunk_server + - timeendpos + - timestartpos example_log: 577 <14>1 2024-02-22T12:33:50-05:00 PALO220.ATTACK_RANGE.LAN - - - - - 1,2024/02/22 12:33:50,012801036556,TRAFFIC,end,2305,2024/02/22 12:33:50,192.168.1.205,147.28.146.44,201.17.96.104,147.28.146.44,No_Vuln_Filtering_OUT,,,screenconnect,vsys1,Trust,Untrust,ethernet1/2,ethernet1/1,splunk_range,2024/02/22 + 1,2024/02/22 12:33:50,012801036556,TRAFFIC,end,2305,2024/02/22 + 12:33:50,192.168.1.205,147.28.146.44,201.17.96.104,147.28.146.44,No_Vuln_Filtering_OUT,,,screenconnect,vsys1,Trust,Untrust,ethernet1/2,ethernet1/1,splunk_range,2024/02/22 12:33:50,14740,1,50624,443,11024,443,0x40005e,tcp,allow,7419,6609,810,25,2024/02/22 - 12:32:29,65,any,0,376156893,0x0,192.168.0.0-192.168.255.255,United States,0,14,11,tcp-fin,0,0,0,0,,PALO220,from-policy,,,0,,0,,N/A,0,0,0,0,0862e58b-4a54-436b-b3ac-ea3eccf8403b,0,0,,,,,,, + 12:32:29,65,any,0,376156893,0x0,192.168.0.0-192.168.255.255,United + States,0,14,11,tcp-fin,0,0,0,0,,PALO220,from-policy,,,0,,0,,N/A,0,0,0,0,0862e58b-4a54-436b-b3ac-ea3eccf8403b,0,0,,,,,,, diff --git a/data_sources/pingid.yml b/data_sources/pingid.yml index 2b77686143..5b7648219f 100644 --- a/data_sources/pingid.yml +++ b/data_sources/pingid.yml @@ -1,45 +1,46 @@ name: PingID id: 17890675-61c1-40bd-a88e-6a8e9e246b43 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs authentication and multi-factor authentication (MFA) events managed by PingID, including user logins, device enrollments, and MFA challenges. +description: Logs authentication and multi-factor authentication (MFA) events managed + by PingID, including user logins, device enrollments, and MFA challenges. mitre_components: -- User Account Authentication -- Logon Session Metadata -- User Account Metadata -- Application Log Content -- Host Status + - User Account Authentication + - Logon Session Metadata + - User Account Metadata + - Application Log Content + - Host Status source: XmlWinEventLog:Security sourcetype: XmlWinEventLog supported_TA: [] fields: -- _time -- actors{}.name -- actors{}.type -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- extracted_source -- host -- id -- index -- linecount -- punct -- recorded -- resources{}.ipaddress -- resources{}.websession -- result.message -- result.status -- source -- sourcetype -- splunk_server -- timeendpos -- timestartpos + - _time + - actors{}.name + - actors{}.type + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - extracted_source + - host + - id + - index + - linecount + - punct + - recorded + - resources{}.ipaddress + - resources{}.websession + - result.message + - result.status + - source + - sourcetype + - splunk_server + - timeendpos + - timestartpos example_log: '{"source":"PINGID","id":"b2eb1fef-651b-11ee-b38b-0ac7a554ed19","recorded":"2023-10-05T14:10:53.538Z","actors":[{"type":"user","name":"victim_user"}],"resources":[{"ipaddress":"174.235.80.142","websession":"webs_ijkF-T_bAC_G3w2TfvdpAEQeC545KFlqVFOsolCXdjo"}],"result":{"status":"SUCCESS","message":"Device Paired SMS \"Mobile 1\""}}' diff --git a/data_sources/powershell_installed_iis_modules.yml b/data_sources/powershell_installed_iis_modules.yml index cf0b592d7b..3e466057a5 100644 --- a/data_sources/powershell_installed_iis_modules.yml +++ b/data_sources/powershell_installed_iis_modules.yml @@ -1,26 +1,27 @@ name: Powershell Installed IIS Modules id: 4f2ccf42-3503-4417-a684-bfccf7f0d7b4 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the list of installed IIS modules retrieved using PowerShell, including details about their names and statuses. +description: Logs the list of installed IIS modules retrieved using PowerShell, including + details about their names and statuses. mitre_components: -- Service Metadata -- Configuration Modification -- OS API Execution -- Application Log Content + - Service Metadata + - Configuration Modification + - OS API Execution + - Application Log Content source: powershell://AppCmdModules sourcetype: Pwsh:InstalledIISModules supported_TA: [] fields: -- _time -- Schema -- host -- index -- linecount -- punct -- source -- sourcetype -- splunk_server -- timestamp + - _time + - Schema + - host + - index + - linecount + - punct + - source + - sourcetype + - splunk_server + - timestamp example_log: Schema="Microsoft.IIs.PowerShell.Framework.ConfigurationElementSchema" diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index b5aba9d7f7..67794c1e47 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -1,95 +1,97 @@ name: Powershell Script Block Logging 4104 id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution. +description: Logs detailed content of PowerShell script blocks as they are executed, + including the full command text and context for the execution. mitre_components: -- Script Execution -- Command Execution -- Process Metadata -- OS API Execution -- Application Log Content + - Script Execution + - Command Execution + - Process Metadata + - OS API Execution + - Application Log Content source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 4104 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- ActivityID -- Channel -- Computer -- EventCode -- EventData_Xml -- EventID -- EventRecordID -- Guid -- Keywords -- Level -- MessageNumber -- MessageTotal -- Name -- Opcode -- Path -- ProcessID -- RecordNumber -- ScriptBlockId -- ScriptBlockText -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- UserID -- Version -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- punct -- signature_id -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user_id -- vendor_product + - _time + - ActivityID + - Channel + - Computer + - EventCode + - EventData_Xml + - EventID + - EventRecordID + - Guid + - Keywords + - Level + - MessageNumber + - MessageTotal + - Name + - Opcode + - Path + - ProcessID + - RecordNumber + - ScriptBlockId + - ScriptBlockText + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - UserID + - Version + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - punct + - signature_id + - source + - sourcetype + - splunk_server + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user_id + - vendor_product field_mappings: -- data_model: cim - data_set: Endpoint.Processes - mapping: - Computer: Processes.dest - Path: Processes.process_path - ScriptBlockId: Processes.process_id - ScriptBlockText: Processes.process - UserID: Processes.user_id -- data_model: ocsf - mapping: - Computer: device.hostname - Path: process.file.path - ScriptBlockId: process.uid - ScriptBlockText: process.cmd_line - UserID: actor.user.uid + - data_model: cim + data_set: Endpoint.Processes + mapping: + Computer: Processes.dest + Path: Processes.process_path + ScriptBlockId: Processes.process_id + ScriptBlockText: Processes.process + UserID: Processes.user_id + - data_model: ocsf + mapping: + Computer: device.hostname + Path: process.file.path + ScriptBlockId: process.uid + ScriptBlockText: process.cmd_line + UserID: actor.user.uid example_log: 4104152150x04104152150x0112748Microsoft-Windows-PowerShell/Operationalwin-dc-mhaag-attack-range-270.attackrange.local154100x80000000000000004522Microsoft-Windows-Sysmon/Operationalwin-dc-6764986.attackrange.local-2020-10-08\ - \ 11:03:46.615{96128EA2-F212-5F7E-E400-000000007F01}2296C:\\Windows\\System32\\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows\ - \ Command ProcessorMicrosoft\xAE Windows\xAE Operating\ - \ SystemMicrosoft CorporationCmd.Exe\"C:\\Windows\\system32\\cmd.exe\" /c \"reg save HKLM\\sam\ - \ %%temp%%\\sam & reg save HKLM\\system %%temp%%\\system & reg save HKLM\\\ - security %%temp%%\\security\" C:\\Users\\ADMINI~1\\\ - AppData\\Local\\Temp\\ATTACKRANGE\\Administrator{96128EA2-F210-5F7E-ACD4-080000000000}0x8d4ac0HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{96128EA2-F211-5F7E-DF00-000000007F01}4624C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbwBuAGYAaQByAG0AOgAkAGYAYQBsAHMAZQAgAC0AVABpAG0AZQBvAHUAdABTAGUAYwBvAG4AZABzACAAMwAwADAAIAAtAEUAeABlAGMAdQB0AGkAbwBuAEwAbwBnAFAAYQB0AGgAIABDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAYQB0AGMAXwBlAHgAZQBjAHUAdABpAG8AbgAuAGMAcwB2AA==" + - data_source: Windows Event Log Security 4688 + mapping: + ProcessId: NewProcessId + Image: NewProcessName + Image|endswith: NewProcessName|endswith + CommandLine: Process_Command_Line + User: SubjectUserSid + ParentProcessId: ProcessId + ParentImage: ParentProcessName + ParentImage|endswith: ParentProcessName|endswith + Computer: Computer + OriginalFileName: NewProcessName|endswith + - data_source: Crowdstrike Process + mapping: + ProcessId: RawProcessId + Image: ImageFileName + CommandLine: CommandLine + User: UserSid + ParentProcessId: ParentProcessId + ParentImage: ParentBaseFileName +example_log: 154100x80000000000000004522Microsoft-Windows-Sysmon/Operationalwin-dc-6764986.attackrange.local-2020-10-08 + 11:03:46.615{96128EA2-F212-5F7E-E400-000000007F01}2296C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows + Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.Exe"C:\Windows\system32\cmd.exe" /c "reg save HKLM\sam %%temp%%\sam + & reg save HKLM\system %%temp%%\system & reg save HKLM\security %%temp%%\security" + C:\Users\ADMINI~1\AppData\Local\Temp\ATTACKRANGE\Administrator{96128EA2-F210-5F7E-ACD4-080000000000}0x8d4ac0HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{96128EA2-F211-5F7E-DF00-000000007F01}4624C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"powershell.exe" -noninteractive -encodedcommand + WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbwBuAGYAaQByAG0AOgAkAGYAYQBsAHMAZQAgAC0AVABpAG0AZQBvAHUAdABTAGUAYwBvAG4AZABzACAAMwAwADAAIAAtAEUAeABlAGMAdQB0AGkAbwBuAEwAbwBnAFAAYQB0AGgAIABDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAYQB0AGMAXwBlAHgAZQBjAHUAdABpAG8AbgAuAGMAcwB2AA== diff --git a/data_sources/sysmon_eventid_10.yml b/data_sources/sysmon_eventid_10.yml index 80713f8dc3..6197a6a241 100644 --- a/data_sources/sysmon_eventid_10.yml +++ b/data_sources/sysmon_eventid_10.yml @@ -1,106 +1,109 @@ name: Sysmon EventID 10 id: 659cd5a8-148a-4c59-ade1-05f41ac1b096 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs events where one process accesses another process, typically for memory reads or injections, including details about the source and target processes. +description: Logs events where one process accesses another process, typically for + memory reads or injections, including details about the source and target processes. mitre_components: -- Process Access -- Process Metadata -- Application Log Content -- OS API Execution + - Process Access + - Process Metadata + - Application Log Content + - OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 10 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: -- name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 + - name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: -- _time -- CallTrace -- Channel -- Computer -- EventChannel -- EventCode -- EventData_Xml -- EventDescription -- EventID -- EventRecordID -- GrantedAccess -- Guid -- Keywords -- Level -- Name -- Opcode -- ProcessID -- RecordID -- RecordNumber -- RuleName -- SecurityID -- SourceImage -- SourceProcessGUID -- SourceProcessId -- SourceThreadId -- SystemTime -- System_Props_Xml -- TargetImage -- TargetProcessGUID -- TargetProcessId -- Task -- ThreadID -- TimeCreated -- UserID -- UtcTime -- Version -- action -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- dvc_nt_host -- event_id -- eventtype -- granted_access -- host -- id -- index -- linecount -- os -- parent_process_exec -- parent_process_guid -- parent_process_id -- parent_process_name -- parent_process_path -- process_exec -- process_guid -- process_id -- process_name -- process_path -- punct -- signature -- signature_id -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user_id -- vendor_product + - _time + - CallTrace + - Channel + - Computer + - EventChannel + - EventCode + - EventData_Xml + - EventDescription + - EventID + - EventRecordID + - GrantedAccess + - Guid + - Keywords + - Level + - Name + - Opcode + - ProcessID + - RecordID + - RecordNumber + - RuleName + - SecurityID + - SourceImage + - SourceProcessGUID + - SourceProcessId + - SourceThreadId + - SystemTime + - System_Props_Xml + - TargetImage + - TargetProcessGUID + - TargetProcessId + - Task + - ThreadID + - TimeCreated + - UserID + - UtcTime + - Version + - action + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - dvc_nt_host + - event_id + - eventtype + - granted_access + - host + - id + - index + - linecount + - os + - parent_process_exec + - parent_process_guid + - parent_process_id + - parent_process_name + - parent_process_path + - process_exec + - process_guid + - process_id + - process_name + - process_path + - punct + - signature + - signature_id + - source + - sourcetype + - splunk_server + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user_id + - vendor_product example_log: 10341000x800000000000000010341000x8000000000000000150624412Microsoft-Windows-Sysmon/Operationalwin-dc-128.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-128.attackrange.local-2022-02-01 21:01:44.670{3BF36828-9F6D-61F9-390A-02000000CF01}1272956C:\Tools\Rubeus.exe11241100x800000000000000011241100x80000000000000007712490Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-84.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-84.attackrange.localDownloads2023-02-08 13:01:11.053{0F9A6540-A70E-63E2-3091-00000000BD02}9332C:\Users\Administrator\Downloads\mimikatz_trunk\x64\mimikatz.exe9332C:\Users\Administrator\Downloads\mimikatz_trunk\x64\mimikatz.exeC:\Users\Administrator\Downloads\mimikatz_trunk\x64\CURRENT_USER_My_4_atomic@art2.local.pfx2023-02-08 13:01:11.053 diff --git a/data_sources/sysmon_eventid_12.yml b/data_sources/sysmon_eventid_12.yml index 665a69a98e..57e13fb712 100644 --- a/data_sources/sysmon_eventid_12.yml +++ b/data_sources/sysmon_eventid_12.yml @@ -1,103 +1,107 @@ name: Sysmon EventID 12 id: 3ef28798-8eaa-4fd2-b074-6f36d08a1b33 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of a new registry key, including details about the key name, registry path, and associated process metadata. +description: Logs the creation of a new registry key, including details about the + key name, registry path, and associated process metadata. mitre_components: -- Windows Registry Key Creation -- Process Metadata -- Application Log Content -- OS API Execution + - Windows Registry Key Creation + - Process Metadata + - Application Log Content + - OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 12 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: -- name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 + - name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: -- _time -- Channel -- Computer -- EventChannel -- EventCode -- EventData_Xml -- EventDescription -- EventID -- EventRecordID -- EventType -- Guid -- Image -- Keywords -- Level -- Name -- Opcode -- ProcessGuid -- ProcessID -- ProcessId -- RecordID -- RecordNumber -- RuleName -- SecurityID -- SystemTime -- System_Props_Xml -- TargetObject -- Task -- ThreadID -- TimeCreated -- UserID -- UtcTime -- Version -- action -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- object_category -- object_path -- process_exec -- process_guid -- process_id -- process_name -- process_path -- punct -- registry_hive -- registry_key_name -- registry_path -- severity_id -- signature -- signature_id -- source -- sourcetype -- splunk_server -- status -- tag -- tag::eventtype -- tag::object_category -- timeendpos -- timestartpos -- user_id -- vendor_product + - _time + - Channel + - Computer + - EventChannel + - EventCode + - EventData_Xml + - EventDescription + - EventID + - EventRecordID + - EventType + - Guid + - Image + - Keywords + - Level + - Name + - Opcode + - ProcessGuid + - ProcessID + - ProcessId + - RecordID + - RecordNumber + - RuleName + - SecurityID + - SystemTime + - System_Props_Xml + - TargetObject + - Task + - ThreadID + - TimeCreated + - UserID + - UtcTime + - Version + - action + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - object_category + - object_path + - process_exec + - process_guid + - process_id + - process_name + - process_path + - punct + - registry_hive + - registry_key_name + - registry_path + - severity_id + - signature + - signature_id + - source + - sourcetype + - splunk_server + - status + - tag + - tag::eventtype + - tag::object_category + - timeendpos + - timestartpos + - user_id + - vendor_product example_log: 12241200x800000000000000012241200x80000000000000001055579Microsoft-Windows-Sysmon/Operationalwin-dc-890.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-890.attackrange.local-DeleteKey2021-07-12 08:10:32.592{466BC892-F8F2-60EB-107E-00000000CF01}10188C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10188C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-2333072374-3391925831-3197092227-1112_Classes\exefile\shell\runas\command diff --git a/data_sources/sysmon_eventid_13.yml b/data_sources/sysmon_eventid_13.yml index d7ed659f74..d533ac7a5c 100644 --- a/data_sources/sysmon_eventid_13.yml +++ b/data_sources/sysmon_eventid_13.yml @@ -1,118 +1,121 @@ name: Sysmon EventID 13 id: 19cd00ee-f65f-48ca-bb08-64aac28638ce -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs changes to a registry key, including details about the modified key, value, and associated process. +description: Logs changes to a registry key, including details about the modified + key, value, and associated process. mitre_components: -- Windows Registry Key Modification -- Process Metadata -- Application Log Content -- OS API Execution + - Windows Registry Key Modification + - Process Metadata + - Application Log Content + - OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 13 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: -- name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 + - name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: -- _time -- Channel -- Computer -- Details -- EventChannel -- EventCode -- EventData_Xml -- EventDescription -- EventID -- EventRecordID -- EventType -- Guid -- Image -- Keywords -- Level -- Name -- Opcode -- ProcessGuid -- ProcessID -- ProcessId -- RecordID -- RecordNumber -- RegistryValueData -- RegistryValueType -- RuleName -- SecurityID -- SystemTime -- System_Props_Xml -- TargetObject -- Task -- ThreadID -- TimeCreated -- UserID -- UtcTime -- Version -- action -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- object_category -- object_path -- process_exec -- process_guid -- process_id -- process_name -- process_path -- punct -- registry_hive -- registry_key_name -- registry_path -- registry_value_data -- registry_value_name -- registry_value_type -- severity_id -- signature -- signature_id -- source -- sourcetype -- splunk_server -- status -- tag -- tag::eventtype -- tag::object_category -- timeendpos -- timestartpos -- user_id -- vendor_product + - _time + - Channel + - Computer + - Details + - EventChannel + - EventCode + - EventData_Xml + - EventDescription + - EventID + - EventRecordID + - EventType + - Guid + - Image + - Keywords + - Level + - Name + - Opcode + - ProcessGuid + - ProcessID + - ProcessId + - RecordID + - RecordNumber + - RegistryValueData + - RegistryValueType + - RuleName + - SecurityID + - SystemTime + - System_Props_Xml + - TargetObject + - Task + - ThreadID + - TimeCreated + - UserID + - UtcTime + - Version + - action + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - object_category + - object_path + - process_exec + - process_guid + - process_id + - process_name + - process_path + - punct + - registry_hive + - registry_key_name + - registry_path + - registry_value_data + - registry_value_name + - registry_value_type + - severity_id + - signature + - signature_id + - source + - sourcetype + - splunk_server + - status + - tag + - tag::eventtype + - tag::object_category + - timeendpos + - timestartpos + - user_id + - vendor_product field_mappings: -- data_model: cim - data_set: Endpoint.Registry - mapping: - Computer: Registry.dest - ProcessGuid: Registry.process_guid - ProcessId: Registry.process_id - TargetObject: Registry.registry_path - Details: Registry.registry_value_data + - data_model: cim + data_set: Endpoint.Registry + mapping: + Computer: Registry.dest + ProcessGuid: Registry.process_guid + ProcessId: Registry.process_id + TargetObject: Registry.registry_path + Details: Registry.registry_value_data example_log: 13241300x800000000000000013241300x8000000000000000810987Microsoft-Windows-Sysmon/Operationalwin-host-623.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-host-623.attackrange.local-SetValue2021-07-12 08:11:04.547{0C1E0330-048F-60E8-0B00-00000000D001}628C:\Windows\system32\lsass.exe15241500x800000000000000015241500x8000000000000000667860Microsoft-Windows-Sysmon/Operationalproject-mumbai-hostMicrosoft-Windows-Sysmon/Operationalproject-mumbai-host-2021-04-28 20:11:34.709{ED2ECF8A-C154-6089-F967-00000000BB01}7000C:\Users\DefaultAccount\AppData\Roaming\Telegram Desktop\Telegram.exeC:\Users\DefaultAccount\Downloads\Telegram Desktop\Good(NLA).txt:Zone.Identifier2021-04-28 - 20:11:33.238MD5=C785C55D5FA3443A11B8417209C4B524,SHA256=D07777E0DC36EBECCE3FA9644F0F44DC4A0B7EDE0CBC1F5D33E8D6CB07AF5B5C,IMPHASH=00000000000000000000000000000000MD5=C785C55D5FA3443A11B8417209C4B524,SHA256=D07777E0DC36EBECCE3FA9644F0F44DC4A0B7EDE0CBC1F5D33E8D6CB07AF5B5C,IMPHASH=00000000000000000000000000000000[ZoneTransfer] ZoneId=3 diff --git a/data_sources/sysmon_eventid_17.yml b/data_sources/sysmon_eventid_17.yml index 221feadee2..17f9cba91f 100644 --- a/data_sources/sysmon_eventid_17.yml +++ b/data_sources/sysmon_eventid_17.yml @@ -1,94 +1,96 @@ name: Sysmon EventID 17 id: 08924246-c8e8-4c95-a9fc-633c43cc82df -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Sysmon EventID 17 logs details about the detection of a named pipe. mitre_components: -- Named Pipe Metadata + - Named Pipe Metadata source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 17 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: -- name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 + - name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: -- _time -- Channel -- Computer -- EventChannel -- EventCode -- EventData_Xml -- EventDescription -- EventID -- EventRecordID -- EventType -- Guid -- Image -- Keywords -- Level -- Name -- Opcode -- PipeName -- ProcessGuid -- ProcessID -- ProcessId -- RecordID -- RecordNumber -- RuleName -- SecurityID -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- TimeCreated -- UserID -- UtcTime -- Version -- action -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- os -- pipe_name -- process_exec -- process_guid -- process_id -- process_name -- process_path -- punct -- severity_id -- signature -- signature_id -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user_id -- vendor_product + - _time + - Channel + - Computer + - EventChannel + - EventCode + - EventData_Xml + - EventDescription + - EventID + - EventRecordID + - EventType + - Guid + - Image + - Keywords + - Level + - Name + - Opcode + - PipeName + - ProcessGuid + - ProcessID + - ProcessId + - RecordID + - RecordNumber + - RuleName + - SecurityID + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - TimeCreated + - UserID + - UtcTime + - Version + - action + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - os + - pipe_name + - process_exec + - process_guid + - process_id + - process_name + - process_path + - punct + - severity_id + - signature + - signature_id + - source + - sourcetype + - splunk_server + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user_id + - vendor_product example_log: 17141700x800000000000000017141700x8000000000000000162168Microsoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.local-CreatePipe2021-04-19 21:00:18.288{761B69BB-EF62-607D-B211-00000000BA01}6960\MSSE-1516-server18141800x800000000000000018141800x8000000000000000162173Microsoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.local-ConnectPipe2021-04-19 21:00:19.312{761B69BB-EF62-607D-B211-00000000BA01}6960\MSSE-1516-server20342000x800000000000000020342000x80000000000000006249Microsoft-Windows-Sysmon/Operationalwin-dc-935.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-935.attackrange.local-WmiConsumerEvent2020-12-08 13:54:48.514DeletedATTACKRANGE\Administrator "AtomicRedTeam-WMIPersistence-Example"21342100x800000000000000021342100x8000000000000000151644Microsoft-Windows-Sysmon/Operationalwin-host-14.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-host-14.attackrange.local-WmiBindingEvent2021-06-16 21:46:50.222ModifiedWIN-HOST-14\Administrator "CommandLineEventConsumer.Name=\"Evil diff --git a/data_sources/sysmon_eventid_22.yml b/data_sources/sysmon_eventid_22.yml index 5ed15373d4..a40a8dc863 100644 --- a/data_sources/sysmon_eventid_22.yml +++ b/data_sources/sysmon_eventid_22.yml @@ -1,96 +1,99 @@ name: Sysmon EventID 22 id: 911538b2-eba7-4d3e-85e8-d82d380c37bf -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs DNS query events, including details about the queried domain, source IP, query type, and response data. +description: Logs DNS query events, including details about the queried domain, source + IP, query type, and response data. mitre_components: -- Passive DNS -- Active DNS -- Network Traffic Content -- Network Traffic Flow -- Application Log Content + - Passive DNS + - Active DNS + - Network Traffic Content + - Network Traffic Flow + - Application Log Content source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 22 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: -- name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 + - name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: -- _time -- Channel -- Computer -- EventChannel -- EventCode -- EventData_Xml -- EventDescription -- EventID -- EventRecordID -- Guid -- Image -- Keywords -- Level -- Name -- Opcode -- ProcessGuid -- ProcessID -- ProcessId -- QueryName -- QueryResults -- QueryStatus -- RecordID -- RecordNumber -- RuleName -- SecurityID -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- TimeCreated -- UserID -- UtcTime -- Version -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- process_exec -- process_guid -- process_name -- punct -- query -- query_count -- reply_code_id -- signature -- signature_id -- source -- sourcetype -- splunk_server -- src -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user_id -- vendor_product + - _time + - Channel + - Computer + - EventChannel + - EventCode + - EventData_Xml + - EventDescription + - EventID + - EventRecordID + - Guid + - Image + - Keywords + - Level + - Name + - Opcode + - ProcessGuid + - ProcessID + - ProcessId + - QueryName + - QueryResults + - QueryStatus + - RecordID + - RecordNumber + - RuleName + - SecurityID + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - TimeCreated + - UserID + - UtcTime + - Version + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - process_exec + - process_guid + - process_name + - punct + - query + - query_count + - reply_code_id + - signature + - signature_id + - source + - sourcetype + - splunk_server + - src + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user_id + - vendor_product example_log: 22542200x800000000000000022542200x8000000000000000113892Microsoft-Windows-Sysmon/Operationalwin-dc-299.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-299.attackrange.local-2021-03-24 12:25:12.840{3CFDEE80-2F7D-605B-F50A-00000000AE01}717250.220.65.3.spam.dnsbl.sorbs.net23542300x800000000000000023542300x8000000000000000281771Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-865.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-865.attackrange.local-2023-02-01 10:57:09.814{F522A29C-446D-63DA-9F01-00000000BB02}2428ATTACKRANGE\Administrator354300x8000000000000000354300x8000000000000000156837Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-403.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-403.attackrange.local-2022-09-15 12:56:19.679{6820D070-1F1B-6323-E113-000000007402}5728C:\Temp\agent_tesla-deob.exe534500x8000000000000000534500x800000000000000039965Microsoft-Windows-Sysmon/Operationalwin-dc-654.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-654.attackrange.local-2021-03-16 14:01:44.004{26337912-BA32-6050-3506-00000000AE01}8672C:\Users\Public\steam.exe diff --git a/data_sources/sysmon_eventid_6.yml b/data_sources/sysmon_eventid_6.yml index 9cf7db46b6..d019cb51cf 100644 --- a/data_sources/sysmon_eventid_6.yml +++ b/data_sources/sysmon_eventid_6.yml @@ -1,98 +1,102 @@ name: Sysmon EventID 6 id: eadc297a-c20c-45a1-8fac-74ad54019767 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the loading of a driver into the kernel or user mode, including details about the driver name, file path, and associated process metadata. +description: Logs the loading of a driver into the kernel or user mode, including + details about the driver name, file path, and associated process metadata. mitre_components: -- Driver Load -- Process Metadata -- Application Log Content -- OS API Execution + - Driver Load + - Process Metadata + - Application Log Content + - OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 6 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: -- name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 + - name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: -- _time -- Channel -- Computer -- EventChannel -- EventCode -- EventData_Xml -- EventDescription -- EventID -- EventRecordID -- Guid -- Hashes -- ImageLoaded -- Keywords -- Level -- MD5 -- Name -- Opcode -- ProcessID -- RecordID -- RecordNumber -- RuleName -- SHA256 -- SecurityID -- Signature -- SignatureStatus -- Signed -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- TimeCreated -- UserID -- UtcTime -- Version -- action -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- os -- process_hash -- process_path -- punct -- service_signature_exists -- service_signature_verified -- signature -- signature_id -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user_id -- vendor_product + - _time + - Channel + - Computer + - EventChannel + - EventCode + - EventData_Xml + - EventDescription + - EventID + - EventRecordID + - Guid + - Hashes + - ImageLoaded + - Keywords + - Level + - MD5 + - Name + - Opcode + - ProcessID + - RecordID + - RecordNumber + - RuleName + - SHA256 + - SecurityID + - Signature + - SignatureStatus + - Signed + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - TimeCreated + - UserID + - UtcTime + - Version + - action + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - os + - process_hash + - process_path + - punct + - service_signature_exists + - service_signature_verified + - signature + - signature_id + - source + - sourcetype + - splunk_server + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user_id + - vendor_product example_log: 644600x8000000000000000644600x800000000000000015708989Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-702.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-702.attackrange.local-2022-04-04 - 17:37:04.640C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\npf.sysC:\Program + Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\npf.sysMD5=DE7FCC77F4A503AF4CA6A47D49B3713D,SHA256=4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6trueRiverbed Technology, Inc.Valid diff --git a/data_sources/sysmon_eventid_7.yml b/data_sources/sysmon_eventid_7.yml index 24d4800817..23a3dcf3a1 100644 --- a/data_sources/sysmon_eventid_7.yml +++ b/data_sources/sysmon_eventid_7.yml @@ -1,121 +1,125 @@ name: Sysmon EventID 7 id: 45512fa5-4d55-4088-9d51-f4dedc16fdff -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the loading of an image (module) into a process, including details about the image name, file path, and hash information. +description: Logs the loading of an image (module) into a process, including details + about the image name, file path, and hash information. mitre_components: -- Module Load -- Process Metadata -- File Metadata -- Application Log Content -- OS API Execution + - Module Load + - Process Metadata + - File Metadata + - Application Log Content + - OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 7 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: -- name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 + - name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: -- _time -- Channel -- Company -- Computer -- Description -- EventChannel -- EventCode -- EventData_Xml -- EventDescription -- EventID -- EventRecordID -- FileVersion -- Guid -- Hashes -- IMPHASH -- Image -- ImageLoaded -- Keywords -- Level -- MD5 -- Name -- Opcode -- OriginalFileName -- ProcessGuid -- ProcessID -- ProcessId -- Product -- RecordID -- RecordNumber -- RuleName -- SHA256 -- SecurityID -- Signature -- SignatureStatus -- Signed -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- TimeCreated -- User -- UserID -- UtcTime -- Version -- action -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- os -- parent_process_exec -- parent_process_guid -- parent_process_id -- parent_process_name -- parent_process_path -- process_exec -- process_hash -- process_name -- process_path -- punct -- service_dll_signature_exists -- service_dll_signature_verified -- signature -- signature_id -- source -- sourcetype -- splunk_server -- tag -- tag::action -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_id -- vendor_product + - _time + - Channel + - Company + - Computer + - Description + - EventChannel + - EventCode + - EventData_Xml + - EventDescription + - EventID + - EventRecordID + - FileVersion + - Guid + - Hashes + - IMPHASH + - Image + - ImageLoaded + - Keywords + - Level + - MD5 + - Name + - Opcode + - OriginalFileName + - ProcessGuid + - ProcessID + - ProcessId + - Product + - RecordID + - RecordNumber + - RuleName + - SHA256 + - SecurityID + - Signature + - SignatureStatus + - Signed + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - TimeCreated + - User + - UserID + - UtcTime + - Version + - action + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - os + - parent_process_exec + - parent_process_guid + - parent_process_id + - parent_process_name + - parent_process_path + - process_exec + - process_hash + - process_name + - process_path + - punct + - service_dll_signature_exists + - service_dll_signature_verified + - signature + - signature_id + - source + - sourcetype + - splunk_server + - tag + - tag::action + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_id + - vendor_product example_log: 734700x8000000000000000734700x800000000000000045273Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.localMicrosoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2023-09-12 08:06:31.433{8814F3F5-1C07-6500-9600-000000000E03}4440C:\Users\Administrator\AppData\Local\Temp\server.exeC:\Users\Administrator\AppData\Local\Temp\server.exe-----MD5=696CBE2CB6F7FAC5ED6262BCA51238BB,SHA256=43005D86607DC94C7D378AA1B8844947BAA03860652F2F2340266061AF12E524,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744--MD5=696CBE2CB6F7FAC5ED6262BCA51238BB,SHA256=43005D86607DC94C7D378AA1B8844947BAA03860652F2F2340266061AF12E524,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744false-UnavailableATTACKRANGE\Administrator diff --git a/data_sources/sysmon_eventid_8.yml b/data_sources/sysmon_eventid_8.yml index ff4dd0f046..086d972abf 100644 --- a/data_sources/sysmon_eventid_8.yml +++ b/data_sources/sysmon_eventid_8.yml @@ -1,108 +1,111 @@ name: Sysmon EventID 8 id: df7a786c-ade0-48f0-8596-26f10d169f7d -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of a new thread in a process, including details about the thread ID, start address, and source process. +description: Logs the creation of a new thread in a process, including details about + the thread ID, start address, and source process. mitre_components: -- Process Modification -- Process Metadata -- Application Log Content -- OS API Execution + - Process Modification + - Process Metadata + - Application Log Content + - OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 8 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: -- name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 + - name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: -- _time -- Channel -- Computer -- EventChannel -- EventCode -- EventData_Xml -- EventDescription -- EventID -- EventRecordID -- Guid -- Keywords -- Level -- Name -- NewThreadId -- Opcode -- ProcessID -- RecordID -- RecordNumber -- RuleName -- SecurityID -- SourceImage -- SourceProcessGuid -- SourceProcessId -- StartAddress -- StartFunction -- StartModule -- SystemTime -- System_Props_Xml -- TargetImage -- TargetProcessGuid -- TargetProcessId -- Task -- ThreadID -- TimeCreated -- UserID -- UtcTime -- Version -- action -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- os -- parent_process_exec -- parent_process_guid -- parent_process_id -- parent_process_name -- parent_process_path -- process_exec -- process_guid -- process_id -- process_name -- process_path -- punct -- signature -- signature_id -- source -- sourcetype -- splunk_server -- src_address -- src_function -- src_module -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user_id -- vendor_product + - _time + - Channel + - Computer + - EventChannel + - EventCode + - EventData_Xml + - EventDescription + - EventID + - EventRecordID + - Guid + - Keywords + - Level + - Name + - NewThreadId + - Opcode + - ProcessID + - RecordID + - RecordNumber + - RuleName + - SecurityID + - SourceImage + - SourceProcessGuid + - SourceProcessId + - StartAddress + - StartFunction + - StartModule + - SystemTime + - System_Props_Xml + - TargetImage + - TargetProcessGuid + - TargetProcessId + - Task + - ThreadID + - TimeCreated + - UserID + - UtcTime + - Version + - action + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - os + - parent_process_exec + - parent_process_guid + - parent_process_id + - parent_process_name + - parent_process_path + - process_exec + - process_guid + - process_id + - process_name + - process_path + - punct + - signature + - signature_id + - source + - sourcetype + - splunk_server + - src_address + - src_function + - src_module + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user_id + - vendor_product example_log: 824800x8000000000000000824800x8000000000000000362233Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-487.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-487.attackrange.local-2022-10-27 13:59:12.427{3381F800-8EB0-635A-1306-000000008A02}4864C:\Windows\SysWOW64\wermgr.exe924900x8000000000000000924900x8000000000000000190607Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-478.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-478.attackrange.local-2022-02-25 12:25:33.359{414E8EDF-CABB-6218-F103-000000003702}6068C:\Temp\c.exe\Device\HarddiskVolume1 diff --git a/data_sources/sysmon_for_linux_eventid_1.yml b/data_sources/sysmon_for_linux_eventid_1.yml index ac395956a2..5850fd83d6 100644 --- a/data_sources/sysmon_for_linux_eventid_1.yml +++ b/data_sources/sysmon_for_linux_eventid_1.yml @@ -1,115 +1,118 @@ name: Sysmon for Linux EventID 1 id: 93643652-30fe-4941-a1f7-6454f2948660 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs process creation events on Linux systems, including details about the process name, process ID, command line arguments, and parent process ID. +description: Logs process creation events on Linux systems, including details about + the process name, process ID, command line arguments, and parent process ID. mitre_components: -- Process Creation -- Command Execution -- Process Metadata -- OS API Execution -- Application Log Content + - Process Creation + - Command Execution + - Process Metadata + - OS API Execution + - Application Log Content source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux separator: EventID separator_value: 1 supported_TA: -- name: Splunk Add-on for Sysmon for Linux - url: https://splunkbase.splunk.com/app/6652 - version: 1.0.0 + - name: Splunk Add-on for Sysmon for Linux + url: https://splunkbase.splunk.com/app/6652 + version: 1.0.0 fields: -- _time -- Channel -- CommandLine -- Company -- Computer -- CurrentDirectory -- Description -- EventChannel -- EventCode -- EventData_Xml -- EventDescription -- EventID -- EventRecordID -- FileVersion -- Guid -- Hashes -- Image -- IntegrityLevel -- Keywords -- Level -- LogonGuid -- LogonId -- Name -- Opcode -- OriginalFileName -- ParentCommandLine -- ParentImage -- ParentProcessGuid -- ParentProcessId -- ParentUser -- ProcessGuid -- ProcessID -- ProcessId -- Product -- RecordID -- RuleName -- SystemTime -- System_Props_Xml -- Task -- TerminalSessionId -- ThreadID -- User -- UserId -- UtcTime -- Version -- action -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- eventtype -- host -- index -- linecount -- original_file_name -- os -- parent_process -- parent_process_exec -- parent_process_guid -- parent_process_id -- parent_process_name -- parent_process_path -- process -- process_current_directory -- process_exec -- process_guid -- process_hash -- process_id -- process_integrity_level -- process_name -- process_path -- punct -- signature -- signature_id -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- vendor_product -example_log: 154100x8000000000000000154100x80000000000000001926574Linux-Sysmon/Operationalar-linuxLinux-Sysmon/Operationalar-linux-2022-08-09 10:42:47.757{ec23eae3-3a27-62f2-085e-16549b550000}10268/usr/bin/sudo-11241100x800000000000000011241100x8000000000000000792913Linux-Sysmon/Operationalsysmonlinux-tcontreras-attack-range-4134Linux-Sysmon/Operationalsysmonlinux-tcontreras-attack-range-4134-2021-12-20 16:07:17.929{ec2c97d1-6aa9-61c0-3038-618238560000}5256/opt/splunkforwarder/bin/splunkd4688201331200x80200000000000004688201331200x8020000000000000362027Securityar-win-2.attackrange.localSecurityar-win-2.attackrange.localNT AUTHORITY\SYSTEMAR-WIN-2$ATTACKRANGE0x3e70xa44C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe228202000x80000000000000228202000x800000000000001001307Applicationwin-dc-exch01.attackrange.localc:\temp\msf.dllAMD64C1000000 + ProcessID='0' + ThreadID='0'/>Applicationwin-dc-exch01.attackrange.localc:\temp\msf.dllAMD64C1000000 diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index 9ec681c407..f7588b104a 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -1,72 +1,75 @@ name: Windows Event Log Application 3000 id: 3911945d-9222-408d-b851-9b1bce4c2d24 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the termination of a process, including details about the process, its termination code, and timestamp. +description: Logs the termination of a process, including details about the process, + its termination code, and timestamp. mitre_components: -- Process Termination -- Process Metadata -- Application Log Content -- OS API Execution + - Process Termination + - Process Metadata + - Application Log Content + - OS API Execution source: XmlWinEventLog:Application sourcetype: XmlWinEventLog separator: EventCode separator_value: 3000 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- Channel -- Computer -- Error_Code -- EventCode -- EventData_Xml -- EventRecordID -- EventSourceName -- Guid -- Keywords -- Level -- Name -- Opcode -- ProcessID -- Qualifiers -- RecordNumber -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- UserID -- Version -- dest -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- param1 -- param2 -- param3 -- punct -- signature_id -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- timestamp -- user_id -- vendor_product + - _time + - Channel + - Computer + - Error_Code + - EventCode + - EventData_Xml + - EventRecordID + - EventSourceName + - Guid + - Keywords + - Level + - Name + - Opcode + - ProcessID + - Qualifiers + - RecordNumber + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - UserID + - Version + - dest + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - param1 + - param2 + - param3 + - punct + - signature_id + - source + - sourcetype + - splunk_server + - tag + - tag::eventtype + - timestamp + - user_id + - vendor_product example_log: 300004000x80000000000000300004000x8000000000000021334Applicationwin-host-mhaag-attack-range-117Applicationwin-host-mhaag-attack-range-117C:\Windows\System32\klist.exe001d8c3afcf370d13 diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index 0ac0455e60..1ace202695 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -1,75 +1,78 @@ name: Windows Event Log CAPI2 70 id: 821de0a6-c5b4-491b-a27e-187552792817 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: This event log records events related to cryptographic operations, including the deletion and export of certificates. +description: This event log records events related to cryptographic operations, including + the deletion and export of certificates. mitre_components: -- Certificate Registration -- Process Metadata -- Application Log Content -- OS API Execution -- Host Status + - Certificate Registration + - Process Metadata + - Application Log Content + - OS API Execution + - Host Status source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational sourcetype: xmlwineventlog separator: EventCode separator_value: 70 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- Channel -- Computer -- EventCode -- EventID -- EventRecordID -- Guid -- Keywords -- Level -- Name -- Opcode -- ProcessID -- RecordNumber -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- UserData_Xml -- UserID -- Version -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- punct -- signature_id -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user_id -- vendor_product + - _time + - Channel + - Computer + - EventCode + - EventID + - EventRecordID + - Guid + - Keywords + - Level + - Name + - Opcode + - ProcessID + - RecordNumber + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - UserData_Xml + - UserID + - Version + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - punct + - signature_id + - source + - sourcetype + - splunk_server + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user_id + - vendor_product example_log: 70047000x400000000000008070047000x4000000000000080308332Microsoft-Windows-CAPI2/Operationalwin-dc-mhaag-attack-range-84.attackrange.localMicrosoft-Windows-CAPI2/Operationalwin-dc-mhaag-attack-range-84.attackrange.local81028020x400000000000004081028020x40000000000000402400597Microsoft-Windows-CAPI2/Operationalmswin-server.attackrange.localMicrosoft-Windows-CAPI2/Operationalmswin-server.attackrange.local{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}WTD_UI_NONEWTD_STATEACTION_VERIFY2021-01-07T23:21:42.655Z2021-01-07T23:21:42.655ZThe digital signature of the object did not verify.100704000x8000000000000000100704000x80000000000000002Microsoft-Windows-CertificateServicesClient-Lifecycle-System/OperationalDESKTOP-92OQLA1112103000x8000000000000000112103000x80000000000000002975Microsoft-Windows-Windows Defender/Operationalresearchvmhaa112204000x8000000000000000112204000x80000000000000003701Microsoft-Windows-Windows Defender/Operationalresearchvmhaa500704000x8000000000000000500704000x80000000000000003726Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender diff --git a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml index 22e591d7a7..66a21053dc 100644 --- a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml +++ b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml @@ -1,64 +1,55 @@ name: Windows Event Log Microsoft Windows TerminalServices RDPClient 1024 id: 2490537e-5e0c-46f7-9209-f56f852aa217 -version: 1 -date: '2024-11-21' +version: 2 +date: '2025-01-23' author: Michael Haag, Splunk -description: Logs an event when a Remote Desktop Protocol (RDP) client successfully connects to a remote host. +description: Logs an event when a Remote Desktop Protocol (RDP) client successfully + connects to a remote host. mitre_components: -- Network Connection Creation -- Logon Session Creation + - Network Connection Creation + - Logon Session Creation source: WinEventLog:Microsoft-Windows-TerminalServices-RDPClient/Operational sourcetype: WinEventLog separator: EventCode supported_TA: [] fields: -- _time -- Channel -- Computer -- EventCode -- EventData -- EventID -- EventRecordID -- EventType -- Keywords -- Level -- Message -- Opcode -- ProcessID -- RecordNumber -- Security_ID -- Src -- Src_Host -- Src_NT_Domain -- Src_User -- System_TimeCreated -- Task -- ThreadID -- Type -- User -- UserID -- Version -- dest -- dvc -- event_id -- host -- source -- sourcetype -- tag -- user -example_log: - 11/21/2024 06:09:16 PM - LogName=Microsoft-Windows-TerminalServices-RDPClient/Operational - EventCode=1024 - EventType=4 - ComputerName=ar-win-5.attackrange.local - User=NOT_TRANSLATED - Sid=S-1-5-21-1731938146-2314223186-1848411941-500 - SidType=0 - SourceName=Microsoft-Windows-TerminalServices-ClientActiveXCore - Type=Information - RecordNumber=95 - Keywords=None - TaskCategory=Connection Sequence - OpCode=This event is raised during the connection process - Message=RDP ClientActiveX is trying to connect to the server (34.221.50.57) \ No newline at end of file + - _time + - Channel + - Computer + - EventCode + - EventData + - EventID + - EventRecordID + - EventType + - Keywords + - Level + - Message + - Opcode + - ProcessID + - RecordNumber + - Security_ID + - Src + - Src_Host + - Src_NT_Domain + - Src_User + - System_TimeCreated + - Task + - ThreadID + - Type + - User + - UserID + - Version + - dest + - dvc + - event_id + - host + - source + - sourcetype + - tag + - user +example_log: 11/21/2024 06:09:16 PM LogName=Microsoft-Windows-TerminalServices-RDPClient/Operational + EventCode=1024 EventType=4 ComputerName=ar-win-5.attackrange.local User=NOT_TRANSLATED + Sid=S-1-5-21-1731938146-2314223186-1848411941-500 SidType=0 SourceName=Microsoft-Windows-TerminalServices-ClientActiveXCore + Type=Information RecordNumber=95 Keywords=None TaskCategory=Connection Sequence + OpCode=This event is raised during the connection process Message=RDP ClientActiveX + is trying to connect to the server (34.221.50.57) diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index 507a925e5d..74eecb2f6a 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -1,63 +1,63 @@ name: Windows Event Log Printservice 316 id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when printer drivers are installed or updated on the system. mitre_components: -- Driver Load -- Driver Metadata + - Driver Load + - Driver Metadata source: WinEventLog:Microsoft-Windows-PrintService/Admin sourcetype: WinEventLog separator: EventCode separator_value: 316 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- ComputerName -- EventCode -- EventType -- Keywords -- LogName -- Message -- OpCode -- RecordNumber -- Sid -- SidType -- SourceName -- TaskCategory -- Type -- User -- category -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- punct -- severity -- severity_id -- signature_id -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- timeendpos -- timestartpos -- vendor_product + - _time + - ComputerName + - EventCode + - EventType + - Keywords + - LogName + - Message + - OpCode + - RecordNumber + - Sid + - SidType + - SourceName + - TaskCategory + - Type + - User + - category + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - punct + - severity + - severity_id + - signature_id + - source + - sourcetype + - splunk_server + - tag + - tag::eventtype + - timeendpos + - timestartpos + - vendor_product example_log: 07/01/2021 04:20:47 PM diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index ef717b2d20..3f73b548be 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -1,67 +1,68 @@ name: Windows Event Log Printservice 808 id: e3a26785-4389-4830-8d7b-3dad4252719e -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when the print spooler service fails to load a printer plug-in module. +description: Logs an event when the print spooler service fails to load a printer + plug-in module. mitre_components: -- Module Load -- Application Log Content -- Service Metadata + - Module Load + - Application Log Content + - Service Metadata source: WinEventLog:Microsoft-Windows-PrintService/Admin sourcetype: WinEventLog separator: EventCode separator_value: 808 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- ComputerName -- EventCode -- EventType -- Keywords -- LogName -- Message -- OpCode -- RecordNumber -- Sid -- SidType -- SourceName -- TaskCategory -- Type -- User -- category -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- name -- punct -- severity -- severity_id -- signature -- signature_id -- source -- sourcetype -- splunk_server -- subject -- tag -- tag::eventtype -- timeendpos -- timestartpos -- vendor_product + - _time + - ComputerName + - EventCode + - EventType + - Keywords + - LogName + - Message + - OpCode + - RecordNumber + - Sid + - SidType + - SourceName + - TaskCategory + - Type + - User + - category + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - name + - punct + - severity + - severity_id + - signature + - signature_id + - source + - sourcetype + - splunk_server + - subject + - tag + - tag::eventtype + - timeendpos + - timestartpos + - vendor_product example_log: 07/01/2021 04:20:47 PM diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index 14c3a6bc1a..00eb66eec2 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -1,64 +1,67 @@ name: Windows Event Log RemoteConnectionManager 1149 id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a Remote Desktop Service session is initialized. mitre_components: -- Network Connection Creation -- Logon Session Creation -- Logon Session Metadata -source: WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational + - Network Connection Creation + - Logon Session Creation + - Logon Session Metadata +source: + WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational sourcetype: wineventlog separator: EventCode separator_value: 1149 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- ActivityID -- Channel -- Computer -- EventCode -- EventID -- EventRecordID -- Guid -- Keywords -- Level -- Name -- Opcode -- ProcessID -- RecordNumber -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- UserData_Xml -- UserID -- Version -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- punct -- signature_id -- source -- sourcetype -- splunk_server -- tag -- tag::eventtype -- timestamp -- user_id -- vendor_product + - _time + - ActivityID + - Channel + - Computer + - EventCode + - EventID + - EventRecordID + - Guid + - Keywords + - Level + - Name + - Opcode + - ProcessID + - RecordNumber + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - UserData_Xml + - UserID + - Version + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - punct + - signature_id + - source + - sourcetype + - splunk_server + - tag + - tag::eventtype + - timestamp + - user_id + - vendor_product example_log: 114904000x1000000000000000114904000x10000000000000002064Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operationalar-win-1.attackrange.localAdministratorATTACKRANGE10.0.1.14 + UserID='S-1-5-20'/>AdministratorATTACKRANGE10.0.1.14 diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index 41e0c3fced..3c118a5dfc 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -1,84 +1,86 @@ name: Windows Event Log Security 1100 id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when the event logging service has shut down. mitre_components: -- Host Status -- System Configuration Changes + - Host Status + - System Configuration Changes source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 1100 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- Channel -- Computer -- Error_Code -- EventCode -- EventID -- EventRecordID -- Guid -- Keywords -- Level -- Name -- Opcode -- ProcessID -- RecordNumber -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- UserData_Xml -- Version -- action -- app -- change_type -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- name -- object_attrs -- object_category -- product -- punct -- service -- service_name -- signature -- signature_id -- source -- sourcetype -- splunk_server -- status -- subject -- ta_windows_action -- tag -- tag::eventtype -- timeendpos -- timestartpos -- vendor -- vendor_product + - _time + - Channel + - Computer + - Error_Code + - EventCode + - EventID + - EventRecordID + - Guid + - Keywords + - Level + - Name + - Opcode + - ProcessID + - RecordNumber + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - UserData_Xml + - Version + - action + - app + - change_type + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - name + - object_attrs + - object_category + - product + - punct + - service + - service_name + - signature + - signature_id + - source + - sourcetype + - splunk_server + - status + - subject + - ta_windows_action + - tag + - tag::eventtype + - timeendpos + - timestartpos + - vendor + - vendor_product example_log: 11000410300x402000000000000011000410300x4020000000000000140874Securityar-win-2Securityar-win-2 diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index 50bcf53f6b..3e46c4323f 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -1,90 +1,92 @@ name: Windows Event Log Security 1102 id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when the audit log is cleared. mitre_components: -- User Account Modification -- Logon Session Metadata -- File Deletion + - User Account Modification + - Logon Session Metadata + - File Deletion source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 1102 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- Caller_User_Name -- Channel -- Computer -- Error_Code -- EventCode -- EventID -- EventRecordID -- Guid -- Keywords -- Level -- LogFileCleared_Xml -- Name -- Opcode -- ProcessID -- RecordNumber -- SubjectDomainName -- SubjectLogonId -- SubjectUserName -- SubjectUserSid -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- UserData_Xml -- Version -- action -- app -- change_type -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- name -- object_attrs -- object_category -- product -- punct -- signature -- signature_id -- source -- sourcetype -- splunk_server -- src_user -- status -- subject -- ta_windows_action -- tag -- tag::eventtype -- timeendpos -- timestartpos -- vendor -- vendor_product + - _time + - Caller_User_Name + - Channel + - Computer + - Error_Code + - EventCode + - EventID + - EventRecordID + - Guid + - Keywords + - Level + - LogFileCleared_Xml + - Name + - Opcode + - ProcessID + - RecordNumber + - SubjectDomainName + - SubjectLogonId + - SubjectUserName + - SubjectUserSid + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - UserData_Xml + - Version + - action + - app + - change_type + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - name + - object_attrs + - object_category + - product + - punct + - signature + - signature_id + - source + - sourcetype + - splunk_server + - src_user + - status + - subject + - ta_windows_action + - tag + - tag::eventtype + - timeendpos + - timestartpos + - vendor + - vendor_product example_log: 11020410400x402000000000000011020410400x40200000000000001826166Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localATTACKRANGE\AdministratorAdministratorATTACKRANGE0x34a3a27 diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index 0faba24352..62d69f0c10 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -1,128 +1,129 @@ name: Windows Event Log Security 4624 id: 08682968-0366-4882-9559-fe4fe018a846 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an account successfully logs on to a system. mitre_components: -- Logon Session Creation -- User Account Authentication -- Logon Session Metadata + - Logon Session Creation + - User Account Authentication + - Logon Session Metadata source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 4624 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- ActivityID -- AuthenticationPackageName -- Caller_Domain -- Caller_User_Name -- Channel -- Computer -- ElevatedToken -- Error_Code -- EventCode -- EventData_Xml -- EventID -- EventRecordID -- Guid -- ImpersonationLevel -- IpAddress -- IpPort -- KeyLength -- Keywords -- Level -- LmPackageName -- LogonGuid -- LogonProcessName -- LogonType -- Logon_ID -- Logon_Type -- Name -- Opcode -- ProcessID -- ProcessId -- ProcessName -- RecordNumber -- RestrictedAdminMode -- Source_Port -- Source_Workstation -- SubjectDomainName -- SubjectLogonId -- SubjectUserName -- SubjectUserSid -- SystemTime -- System_Props_Xml -- TargetDomainName -- TargetLinkedLogonId -- TargetLogonId -- TargetOutboundDomainName -- TargetOutboundUserName -- TargetUserName -- TargetUserSid -- Target_Domain -- Target_User_Name -- Task -- ThreadID -- TransmittedServices -- Version -- VirtualAccount -- WorkstationName -- action -- app -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_nt_domain -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- name -- process -- process_id -- process_name -- process_path -- product -- punct -- session_id -- signature -- signature_id -- source -- sourcetype -- splunk_server -- src_ip -- src_port -- status -- subject -- ta_windows_action -- tag -- tag::action -- tag::app -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_group -- vendor -- vendor_product + - _time + - ActivityID + - AuthenticationPackageName + - Caller_Domain + - Caller_User_Name + - Channel + - Computer + - ElevatedToken + - Error_Code + - EventCode + - EventData_Xml + - EventID + - EventRecordID + - Guid + - ImpersonationLevel + - IpAddress + - IpPort + - KeyLength + - Keywords + - Level + - LmPackageName + - LogonGuid + - LogonProcessName + - LogonType + - Logon_ID + - Logon_Type + - Name + - Opcode + - ProcessID + - ProcessId + - ProcessName + - RecordNumber + - RestrictedAdminMode + - Source_Port + - Source_Workstation + - SubjectDomainName + - SubjectLogonId + - SubjectUserName + - SubjectUserSid + - SystemTime + - System_Props_Xml + - TargetDomainName + - TargetLinkedLogonId + - TargetLogonId + - TargetOutboundDomainName + - TargetOutboundUserName + - TargetUserName + - TargetUserSid + - Target_Domain + - Target_User_Name + - Task + - ThreadID + - TransmittedServices + - Version + - VirtualAccount + - WorkstationName + - action + - app + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_nt_domain + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - name + - process + - process_id + - process_name + - process_path + - product + - punct + - session_id + - signature + - signature_id + - source + - sourcetype + - splunk_server + - src_ip + - src_port + - status + - subject + - ta_windows_action + - tag + - tag::action + - tag::app + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_group + - vendor + - vendor_product example_log: 4624201254400x80200000000000004624201254400x8020000000000000371886Securityar-win-7.attackrange.local4625001254400x80100000000000004625001254400x8010000000000000367348Securityar-win-8.attackrange.local4627001255400x80200000000000004627001255400x8020000000000000186260Securityar-win-dc.attackrange.local4648001254400x80200000000000004648001254400x8020000000000000336567Securitywin-host-mvelazco-02713-447.attackrange.local4662001408000x80100000000000004662001408000x801000000000000021623198276Securityattack_range_dc4663101280000x80200000000000004663101280000x802000000000000010525869Securityar-win-2.attackrange.localSecurityar-win-2.attackrange.localAR-WIN-2\AdministratorAdministratorAR-WIN-20x6cfe7SecurityFileC:\Program diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index 71facef2ee..9c507ba8bc 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -1,92 +1,94 @@ name: Windows Event Log Security 4672 id: 43f189b6-369d-4a32-a34c-57e0d38d92f1 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs an event when a user with administrative privileges logs on to a system. +description: Logs an event when a user with administrative privileges logs on to a + system. mitre_components: -- Logon Session Creation -- User Account Authentication + - Logon Session Creation + - User Account Authentication source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 4672 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- ActivityID -- Caller_Domain -- Caller_User_Name -- Channel -- Computer -- Error_Code -- EventCode -- EventData_Xml -- EventID -- EventRecordID -- Guid -- Keywords -- Level -- Logon_ID -- Name -- Opcode -- PrivilegeList -- ProcessID -- RecordNumber -- SubjectDomainName -- SubjectLogonId -- SubjectUserName -- SubjectUserSid -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- Version -- action -- app -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- name -- product -- punct -- session_id -- signature -- signature_id -- source -- sourcetype -- splunk_server -- src_nt_domain -- src_user -- status -- subject -- ta_windows_action -- tag -- tag::action -- tag::eventtype -- timeendpos -- timestartpos -- vendor -- vendor_product + - _time + - ActivityID + - Caller_Domain + - Caller_User_Name + - Channel + - Computer + - Error_Code + - EventCode + - EventData_Xml + - EventID + - EventRecordID + - Guid + - Keywords + - Level + - Logon_ID + - Name + - Opcode + - PrivilegeList + - ProcessID + - RecordNumber + - SubjectDomainName + - SubjectLogonId + - SubjectUserName + - SubjectUserSid + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - Version + - action + - app + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - name + - product + - punct + - session_id + - signature + - signature_id + - source + - sourcetype + - splunk_server + - src_nt_domain + - src_user + - status + - subject + - ta_windows_action + - tag + - tag::action + - tag::eventtype + - timeendpos + - timestartpos + - vendor + - vendor_product example_log: 4672001254800x80200000000000004672001254800x8020000000000000148946Securityar-win-6.attackrange.local4688201331200x80200000000000004688201331200x8020000000000000432820Securityar-win-1Securityar-win-1NT AUTHORITY\SYSTEMAR-WIN-1$WORKGROUP0x3e70xf84C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe4703001331700x80200000000000004703001331700x8020000000000000328761Securitywin-host-ctus-attack-range-115Securitywin-host-ctus-attack-range-115WIN-HOST-CTUS-A\AdministratorAdministratorWIN-HOST-CTUS-A0x288b91WIN-HOST-CTUS-A\AdministratorAdministrator4719001356800x80200000000000004719001356800x8020000000000000353597Securityar-win-dc.attackrange.local4724001382400x80200000000000004724001382400x8020000000000000276779Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localTRUMAN_CLEMENTSATTACKRANGEATTACKRANGE\TRUMAN_CLEMENTSATTACKRANGE\AdministratorAdministratorATTACKRANGE4725001382400x80200000000000004725001382400x8020000000000000278771Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localWILFORD_SUTTONATTACKRANGEATTACKRANGE\WILFORD_SUTTONATTACKRANGE\AdministratorAdministratorATTACKRANGE4726001382400x80200000000000004726001382400x8020000000000000279283Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localLYNN_WOLFATTACKRANGES-1-5-21-2851375338-1978525053-2422663219-2445ATTACKRANGE\AdministratorAdministratorATTACKRANGE4738001382400x80200000000000004738001382400x80200000000000006389713Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.local-unprivATTACKRANGES-1-5-21-945660386-2529346225-2932127451-1112S-1-5-21-945660386-2529346225-2932127451-500AdministratorATTACKRANGE4739001356900x80200000000000004739001356900x8020000000000000394176Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localLockout PolicyATTACKRANGEATTACKRANGE\NT AUTHORITY\SYSTEMAR-WIN-DC$ATTACKRANGE4741001382500x80200000000000004741001382500x8020000000000000143475Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localAR-WIN-2$ATTACKRANGEATTACKRANGE\AR-WIN-2$ATTACKRANGE\AdministratorAdministratorATTACKRANGE4742001382500x80200000000000004742001382500x8020000000000000901860Securitywin-dc-root-04195-428.attackrange.localSecuritywin-dc-root-04195-428.attackrange.local-WIN-HOST-ROOT-0$ATTACKRANGES-1-5-21-199921393-3534762603-6736986-1111S-1-5-21-199921393-3534762603-6736986-500Administrator4768001433900x80100000000000004768001433900x8010000000000000391562Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localRXETPKZHattackrange.localNULL SIDkrbtgt/attackrange.localNULL SID0x408100104769001433700x80200000000000004769001433700x8020000000000000148521Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localAR-WIN-2$@ATTACKRANGE.LOCALATTACKRANGE.LOCALAR-WIN-2$ATTACKRANGE\AR-WIN-2$0x408100000x174771001433900x80100000000000004771001433900x8010000000000000391511Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localALLISON_WATERSATTACKRANGE\ALLISON_WATERSkrbtgt/attackrange.local0x408100100x182::ffff:10.0.1.154776001433600x80100000000000004776001433600x8010000000000000391615Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0KSYLEFUAWIN-HOST-MVELAZ0xc0000064 diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index 453217cdd0..eee4c4c3f3 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -1,110 +1,112 @@ name: Windows Event Log Security 4781 id: 9732ffe7-ebce-4557-865c-1725a0f633cb -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action. +description: Logs changes made to the name of a computer account, including the old + and new names and the user performing the action. mitre_components: -- User Account Modification -- User Account Metadata -- Active Directory Object Modification -- Application Log Content + - User Account Modification + - User Account Metadata + - Active Directory Object Modification + - Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 4781 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- ActivityID -- Caller_Domain -- Caller_User_Name -- CategoryString -- Channel -- Computer -- Error_Code -- EventCode -- EventData_Xml -- EventID -- EventRecordID -- Guid -- Keywords -- Level -- Logon_ID -- Name -- NewTargetUserName -- OldTargetUserName -- Opcode -- PrivilegeList -- ProcessID -- RecordNumber -- SubjectDomainName -- SubjectLogonId -- SubjectUserName -- SubjectUserSid -- SystemTime -- System_Props_Xml -- TargetDomainName -- TargetSid -- Target_Domain -- Task -- ThreadID -- Version -- action -- app -- change_type -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dest_nt_domain -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- name -- object -- object_attrs -- object_category -- object_id -- product -- punct -- result -- session_id -- signature -- signature_id -- source -- sourcetype -- splunk_server -- src_nt_domain -- src_user -- src_user_name -- status -- subject -- ta_windows_action -- ta_windows_security_CategoryString -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user -- user_name -- vendor -- vendor_product + - _time + - ActivityID + - Caller_Domain + - Caller_User_Name + - CategoryString + - Channel + - Computer + - Error_Code + - EventCode + - EventData_Xml + - EventID + - EventRecordID + - Guid + - Keywords + - Level + - Logon_ID + - Name + - NewTargetUserName + - OldTargetUserName + - Opcode + - PrivilegeList + - ProcessID + - RecordNumber + - SubjectDomainName + - SubjectLogonId + - SubjectUserName + - SubjectUserSid + - SystemTime + - System_Props_Xml + - TargetDomainName + - TargetSid + - Target_Domain + - Task + - ThreadID + - Version + - action + - app + - change_type + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dest_nt_domain + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - name + - object + - object_attrs + - object_category + - object_id + - product + - punct + - result + - session_id + - signature + - signature_id + - source + - sourcetype + - splunk_server + - src_nt_domain + - src_user + - src_user_name + - status + - subject + - ta_windows_action + - ta_windows_security_CategoryString + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user + - user_name + - vendor + - vendor_product example_log: 4781001382400x80200000000000004781001382400x8020000000000000148763Securityar-win-dc.attackrange.local4794001382400x80200000000000004794001382400x8020000000000000821077Securitywin-dc-root-17044-552.attackrange.local4798001382400x80200000000000004798001382400x8020000000000000386860Securityar-win-2.attackrange.local4876001280500x80200000000000004876001280500x802000000000000015379961Securitywin-dc-mhaag-attack-range-84.attackrange.local4886001280500x80200000000000004886001280500x802000000000000015379925Securitywin-dc-mhaag-attack-range-84.attackrange.local4887001280500x80200000000000004887001280500x80200000000000001830974609Securitycert_authority.attack_range.local5136001408100x80200000000000005136001408100x80200000000000001997365Securitywin-dc-mvelazco-02713-392.attackrange.local{73C96723-504B-4F15-830A-F4DDB1C48F2E}-ATTACKRANGE\AdministratorAdministratorATTACKRANGE0x95675attackrange.local%%14676CN=DANNIE_CERVANTES,OU=ServiceAccounts,OU=OGC,OU=Stage,DC=attackrange,DC=localattackrange.local%%14676CN=DANNIE_CERVANTES,OU=ServiceAccounts,OU=OGC,OU=Stage,DC=attackrange,DC=local{15AFB68A-679C-4F5B-AC18-4D988B3B3E44}userservicePrincipalName2.5.5.12adm/srv1.attackrange.local%%14674 diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index 8787969fa8..9dc78ab362 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -1,103 +1,107 @@ name: Windows Event Log Security 5137 id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action. +description: Logs the creation of a new Active Directory object, including details + about the object name, type, and the user performing the action. mitre_components: -- Active Directory Object Creation -- Active Directory Object Modification -- User Account Metadata -- Application Log Content + - Active Directory Object Creation + - Active Directory Object Modification + - User Account Metadata + - Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 5137 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- AppCorrelationID -- Caller_Domain -- Caller_User_Name -- Channel -- Computer -- DSName -- DSType -- Error_Code -- EventCode -- EventData_Xml -- EventID -- EventRecordID -- Guid -- Keywords -- Level -- Logon_ID -- Name -- ObjectClass -- ObjectDN -- ObjectGUID -- OpCorrelationID -- Opcode -- ProcessID -- RecordNumber -- SubjectDomainName -- SubjectLogonId -- SubjectUserName -- SubjectUserSid -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- Version -- action -- app -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- name -- product -- punct -- session_id -- signature -- signature_id -- source -- sourcetype -- splunk_server -- src_nt_domain -- src_user -- status -- subject -- ta_windows_action -- tag -- tag::action -- tag::eventtype -- timeendpos -- timestartpos -- vendor -- vendor_product + - _time + - AppCorrelationID + - Caller_Domain + - Caller_User_Name + - Channel + - Computer + - DSName + - DSType + - Error_Code + - EventCode + - EventData_Xml + - EventID + - EventRecordID + - Guid + - Keywords + - Level + - Logon_ID + - Name + - ObjectClass + - ObjectDN + - ObjectGUID + - OpCorrelationID + - Opcode + - ProcessID + - RecordNumber + - SubjectDomainName + - SubjectLogonId + - SubjectUserName + - SubjectUserSid + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - Version + - action + - app + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - name + - product + - punct + - session_id + - signature + - signature_id + - source + - sourcetype + - splunk_server + - src_nt_domain + - src_user + - status + - subject + - ta_windows_action + - tag + - tag::action + - tag::eventtype + - timeendpos + - timestartpos + - vendor + - vendor_product example_log: 5137001408100x80200000000000005137001408100x8020000000000000170140Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.local{681cac8c-b5a4-48fd-be93-4339996bd94d}-ATTACKRANGE\AdministratorAdministratorATTACKRANGE0x8561aattackrange.local%%14676CN={2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4},CN=Policies,CN=System,DC=attackrange,DC=localattackrange.local%%14676CN={2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4},CN=Policies,CN=System,DC=attackrange,DC=local{3e7ae4de-29a6-41c1-b27c-bf9548b0444c}groupPolicyContainer diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index 8d1883d26c..4fb8bf8cc6 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -1,121 +1,124 @@ name: Windows Event Log Security 5140 id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs access to a network share, including details about the user, share path, and the access type. +description: Logs access to a network share, including details about the user, share + path, and the access type. mitre_components: -- Network Share Access -- File Access -- User Account Metadata -- Application Log Content + - Network Share Access + - File Access + - User Account Metadata + - Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 5140 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- AccessList -- AccessMask -- Caller_Domain -- Caller_User_Name -- Channel -- Computer -- Error_Code -- EventCode -- EventData_Xml -- EventID -- EventRecordID -- Guid -- IpAddress -- IpPort -- Keywords -- Level -- Logon_ID -- Name -- ObjectType -- Opcode -- ProcessID -- RecordNumber -- ShareName -- Source_Port -- Source_Workstation -- SubjectDomainName -- SubjectLogonId -- SubjectUserName -- SubjectUserSid -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- Version -- action -- app -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- dvc_nt_host -- event_id -- eventtype -- file_name -- host -- id -- index -- linecount -- name -- product -- punct -- session_id -- signature -- signature_id -- source -- sourcetype -- splunk_server -- src -- src_ip -- src_nt_domain -- src_nt_host -- src_port -- src_user -- status -- subject -- ta_windows_action -- tag -- tag::action -- tag::eventtype -- timeendpos -- timestartpos -- vendor -- vendor_product + - _time + - AccessList + - AccessMask + - Caller_Domain + - Caller_User_Name + - Channel + - Computer + - Error_Code + - EventCode + - EventData_Xml + - EventID + - EventRecordID + - Guid + - IpAddress + - IpPort + - Keywords + - Level + - Logon_ID + - Name + - ObjectType + - Opcode + - ProcessID + - RecordNumber + - ShareName + - Source_Port + - Source_Workstation + - SubjectDomainName + - SubjectLogonId + - SubjectUserName + - SubjectUserSid + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - Version + - action + - app + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - dvc_nt_host + - event_id + - eventtype + - file_name + - host + - id + - index + - linecount + - name + - product + - punct + - session_id + - signature + - signature_id + - source + - sourcetype + - splunk_server + - src + - src_ip + - src_nt_domain + - src_nt_host + - src_port + - src_user + - status + - subject + - ta_windows_action + - tag + - tag::action + - tag::eventtype + - timeendpos + - timestartpos + - vendor + - vendor_product field_mappings: -- data_model: ocsf - mapping: - AccessList: access_list - AccessMask: access_mask - AccessReason: access_result - ShareLocalPath: file - ObjectType: file.type - IpAddress: src_endpoint.ip - IpPort: src_endpoint.port - SubjectDomainName: actor.user.domain - SubjectUserName: actor.user.name - SubjectLogonId: actor.session.uid - SubjectUserSid: actor.user.uid + - data_model: ocsf + mapping: + AccessList: access_list + AccessMask: access_mask + AccessReason: access_result + ShareLocalPath: file + ObjectType: file.type + IpAddress: src_endpoint.ip + IpPort: src_endpoint.port + SubjectDomainName: actor.user.domain + SubjectUserName: actor.user.name + SubjectLogonId: actor.session.uid + SubjectUserSid: actor.user.uid example_log: 5140101280800x80200000000000005140101280800x8020000000000000138541Securityar-win-66.attackrange.localSecurityar-win-66.attackrange.localATTACKRANGE\ELMER_SALASELMER_SALASATTACKRANGE0x2f259bFile10.0.1.16498645141001408100x80200000000000005141001408100x8020000000000000670908Securitywin-dc-range-02713-392.attackrange.local5145001281100x80200000000000005145001281100x80200000000000002018939Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localANONYMOUS LOGONANONYMOUS LOGONATTACKRANGE0x13ef1bFile10.0.1.1550160703604000x8080000000000000703604000x8080000000000000168530Systemar-win-dc.attackrange.localsppsvcstopped7300700070007300760063002F0031000000 + ProcessID='588' + ThreadID='2272'/>Systemar-win-dc.attackrange.localsppsvcstopped7300700070007300760063002F0031000000 diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index e1d08e67e4..3a5f943ee0 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -1,88 +1,91 @@ name: Windows Event Log System 7040 id: 91738e9e-d112-41c9-b91b-e5868d8993d9 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type. +description: Logs changes to the start type of a Windows service, including details + about the service name, old start type, and new start type. mitre_components: -- Service Modification -- Service Metadata -- OS API Execution -- Application Log Content + - Service Modification + - Service Metadata + - OS API Execution + - Application Log Content source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode separator_value: 7040 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- Channel -- Computer -- Error_Code -- EventCode -- EventData_Xml -- EventRecordID -- EventSourceName -- Guid -- Keywords -- Level -- Name -- Opcode -- ProcessID -- Qualifiers -- RecordNumber -- ServiceName -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- UserID -- Version -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- param1 -- param2 -- param3 -- param4 -- product -- punct -- service -- service_name -- signature_id -- source -- sourcetype -- splunk_server -- start_mode -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user_id -- vendor -- vendor_product + - _time + - Channel + - Computer + - Error_Code + - EventCode + - EventData_Xml + - EventRecordID + - EventSourceName + - Guid + - Keywords + - Level + - Name + - Opcode + - ProcessID + - Qualifiers + - RecordNumber + - ServiceName + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - UserID + - Version + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - param1 + - param2 + - param3 + - param4 + - product + - punct + - service + - service_name + - signature_id + - source + - sourcetype + - splunk_server + - start_mode + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user_id + - vendor + - vendor_product example_log: 704004000x8080000000000000704004000x8080000000000000168231Systemar-win-dc.attackrange.localSystemar-win-dc.attackrange.localPrint Spoolerdemand startdisabledSpooler diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index b7e8511470..a3f5ce006a 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -1,88 +1,91 @@ name: Windows Event Log System 7045 id: 614dedc8-8a14-4393-ba9b-6f093cbcd293 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type. +description: Logs the successful installation of a new Windows service, including + details about the service name, executable path, and service type. mitre_components: -- Service Creation -- Service Metadata -- OS API Execution -- Process Metadata + - Service Creation + - Service Metadata + - OS API Execution + - Process Metadata source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode separator_value: 7045 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- AccountName -- Channel -- Computer -- Error_Code -- EventCode -- EventData_Xml -- EventRecordID -- EventSourceName -- Guid -- ImagePath -- Keywords -- Level -- Name -- Opcode -- ProcessID -- Qualifiers -- RecordNumber -- ServiceName -- ServiceType -- StartType -- SystemTime -- System_Props_Xml -- Task -- ThreadID -- UserID -- Version -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- product -- punct -- service -- service_name -- signature_id -- source -- sourcetype -- splunk_server -- start_mode -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user_id -- vendor -- vendor_product + - _time + - AccountName + - Channel + - Computer + - Error_Code + - EventCode + - EventData_Xml + - EventRecordID + - EventSourceName + - Guid + - ImagePath + - Keywords + - Level + - Name + - Opcode + - ProcessID + - Qualifiers + - RecordNumber + - ServiceName + - ServiceType + - StartType + - SystemTime + - System_Props_Xml + - Task + - ThreadID + - UserID + - Version + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - product + - punct + - service + - service_name + - signature_id + - source + - sourcetype + - splunk_server + - start_mode + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user_id + - vendor + - vendor_product example_log: 704504000x8080000000000000704504000x8080000000000000168145Systemar-win-dc.attackrange.localSystemar-win-dc.attackrange.localKrbSCMpowershell.exe -WindowStyle Hiddenestno' diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index c7af8fd33b..4a29c55df5 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -1,83 +1,85 @@ name: Windows Event Log TaskScheduler 200 id: f8c777f8-e88a-4bba-ae8a-79b250212f23 -version: 1 -date: '2024-07-18' +version: 2 +date: '2025-01-23' author: Patrick Bareiss, Splunk -description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations. +description: Logs the successful registration of a new scheduled task in Windows Task + Scheduler, including task details and configurations. mitre_components: -- Scheduled Job Creation -- Scheduled Job Metadata -- Service Creation -- OS API Execution + - Scheduled Job Creation + - Scheduled Job Metadata + - Service Creation + - OS API Execution source: WinEventLog:Microsoft-Windows-TaskScheduler/Operational sourcetype: wineventlog separator: EventCode separator_value: 200 supported_TA: -- name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 + - name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: -- _time -- ActionName -- ActivityID -- Channel -- Computer -- EnginePID -- Error_Code -- EventCode -- EventData_Xml -- EventID -- EventRecordID -- Guid -- Keywords -- Level -- Name -- Opcode -- ProcessID -- RecordNumber -- SystemTime -- System_Props_Xml -- Task -- TaskInstanceId -- TaskName -- ThreadID -- UserID -- Version -- app -- date_hour -- date_mday -- date_minute -- date_month -- date_second -- date_wday -- date_year -- date_zone -- dest -- dvc -- dvc_nt_host -- event_id -- eventtype -- host -- id -- index -- linecount -- product -- punct -- signature_id -- source -- sourcetype -- splunk_server -- ta_windows_action -- tag -- tag::eventtype -- timeendpos -- timestartpos -- user_id -- vendor -- vendor_product + - _time + - ActionName + - ActivityID + - Channel + - Computer + - EnginePID + - Error_Code + - EventCode + - EventData_Xml + - EventID + - EventRecordID + - Guid + - Keywords + - Level + - Name + - Opcode + - ProcessID + - RecordNumber + - SystemTime + - System_Props_Xml + - Task + - TaskInstanceId + - TaskName + - ThreadID + - UserID + - Version + - app + - date_hour + - date_mday + - date_minute + - date_month + - date_second + - date_wday + - date_year + - date_zone + - dest + - dvc + - dvc_nt_host + - event_id + - eventtype + - host + - id + - index + - linecount + - product + - punct + - signature_id + - source + - sourcetype + - splunk_server + - ta_windows_action + - tag + - tag::eventtype + - timeendpos + - timestartpos + - user_id + - vendor + - vendor_product example_log: 2001420010x80000000000000002001420010x80000000000000004323Microsoft-Windows-TaskScheduler/Operationalar-win-dc.attackrange.local Date: Thu, 23 Jan 2025 10:09:09 -0700 Subject: [PATCH 03/67] Fix unintended spacing updates --- data_sources/asl_aws_cloudtrail.yml | 30 +- data_sources/aws_cloudfront.yml | 176 +- .../aws_cloudtrail_assumerolewithsaml.yml | 194 +- data_sources/aws_cloudtrail_consolelogin.yml | 170 +- data_sources/aws_cloudtrail_copyobject.yml | 180 +- .../aws_cloudtrail_createaccesskey.yml | 168 +- data_sources/aws_cloudtrail_createkey.yml | 204 +- .../aws_cloudtrail_createloginprofile.yml | 166 +- .../aws_cloudtrail_createnetworkaclentry.yml | 198 +- .../aws_cloudtrail_createpolicyversion.yml | 168 +- .../aws_cloudtrail_createsnapshot.yml | 186 +- data_sources/aws_cloudtrail_createtask.yml | 184 +- .../aws_cloudtrail_createvirtualmfadevice.yml | 164 +- .../aws_cloudtrail_deactivatemfadevice.yml | 164 +- ...cloudtrail_deleteaccountpasswordpolicy.yml | 162 +- data_sources/aws_cloudtrail_deletealarms.yml | 232 +-- .../aws_cloudtrail_deletedetector.yml | 158 +- data_sources/aws_cloudtrail_deletegroup.yml | 168 +- data_sources/aws_cloudtrail_deleteipset.yml | 158 +- .../aws_cloudtrail_deleteloggroup.yml | 162 +- .../aws_cloudtrail_deletelogstream.yml | 164 +- .../aws_cloudtrail_deletenetworkaclentry.yml | 176 +- data_sources/aws_cloudtrail_deletepolicy.yml | 164 +- data_sources/aws_cloudtrail_deleterule.yml | 164 +- .../aws_cloudtrail_deletesnapshot.yml | 246 +-- data_sources/aws_cloudtrail_deletetrail.yml | 160 +- .../aws_cloudtrail_deletevirtualmfadevice.yml | 160 +- data_sources/aws_cloudtrail_deletewebacl.yml | 160 +- ...aws_cloudtrail_describeeventaggregates.yml | 152 +- ...s_cloudtrail_describeimagescanfindings.yml | 1826 ++++++++--------- ...ws_cloudtrail_getaccountpasswordpolicy.yml | 158 +- data_sources/aws_cloudtrail_getobject.yml | 176 +- .../aws_cloudtrail_getpassworddata.yml | 178 +- data_sources/aws_cloudtrail_jobcreated.yml | 130 +- .../aws_cloudtrail_modifydbinstance.yml | 276 +-- .../aws_cloudtrail_modifyimageattribute.yml | 166 +- ...aws_cloudtrail_modifysnapshotattribute.yml | 156 +- data_sources/aws_cloudtrail_putbucketacl.yml | 184 +- .../aws_cloudtrail_putbucketlifecycle.yml | 186 +- .../aws_cloudtrail_putbucketreplication.yml | 210 +- .../aws_cloudtrail_putbucketversioning.yml | 192 +- data_sources/aws_cloudtrail_putimage.yml | 172 +- data_sources/aws_cloudtrail_putkeypolicy.yml | 172 +- .../aws_cloudtrail_replacenetworkaclentry.yml | 188 +- ...aws_cloudtrail_setdefaultpolicyversion.yml | 158 +- data_sources/aws_cloudtrail_stoplogging.yml | 148 +- ...cloudtrail_updateaccountpasswordpolicy.yml | 172 +- .../aws_cloudtrail_updateloginprofile.yml | 156 +- .../aws_cloudtrail_updatesamlprovider.yml | 339 ++- data_sources/aws_cloudtrail_updatetrail.yml | 166 +- data_sources/aws_cloudwatchlogs_vpcflow.yml | 116 +- data_sources/aws_security_hub.yml | 220 +- ...p_role_assignment_to_service_principal.yml | 162 +- ...re_active_directory_add_member_to_role.yml | 114 +- ...ive_directory_add_owner_to_application.yml | 124 +- ...active_directory_add_service_principal.yml | 114 +- ...active_directory_add_unverified_domain.yml | 114 +- ...ctive_directory_consent_to_application.yml | 124 +- ...irectory_disable_strong_authentication.yml | 110 +- .../azure_active_directory_enable_account.yml | 112 +- ..._active_directory_invite_external_user.yml | 110 +- ...ve_directory_reset_password_(by_admin).yml | 112 +- ...ve_directory_set_domain_authentication.yml | 112 +- ...zure_active_directory_sign_in_activity.yml | 212 +- ...re_active_directory_update_application.yml | 112 +- ..._directory_update_authorization_policy.yml | 114 +- .../azure_active_directory_update_user.yml | 114 +- ...irectory_user_registered_security_info.yml | 106 +- ..._or_update_an_azure_automation_account.yml | 188 +- ..._or_update_an_azure_automation_runbook.yml | 186 +- ..._or_update_an_azure_automation_webhook.yml | 206 +- data_sources/bro_conn.yml | 9 +- data_sources/bro_dns.yml | 10 +- data_sources/bro_files.yml | 10 +- data_sources/bro_http.yml | 10 +- data_sources/bro_loaded_scripts.yml | 8 +- data_sources/bro_ntp.yml | 8 +- data_sources/bro_ocsp.yml | 10 +- data_sources/bro_ssl.yml | 10 +- data_sources/bro_weird.yml | 10 +- data_sources/bro_x509.yml | 10 +- data_sources/circleci.yml | 120 +- data_sources/crowdstrike_processrollup2.yml | 192 +- data_sources/crushftp.yml | 14 +- data_sources/g_suite_drive.yml | 78 +- data_sources/g_suite_gmail.yml | 154 +- data_sources/github.yml | 394 ++-- .../google_workspace_login_failure.yml | 84 +- .../google_workspace_login_success.yml | 80 +- data_sources/ivanti_vtm_audit.yml | 26 +- data_sources/kubernetes_audit.yml | 104 +- data_sources/kubernetes_falco.yml | 80 +- data_sources/linux_auditd_add_user.yml | 56 +- data_sources/linux_auditd_execve.yml | 24 +- data_sources/linux_auditd_path.yml | 52 +- data_sources/linux_auditd_proctitle.yml | 20 +- data_sources/linux_auditd_service_stop.yml | 52 +- data_sources/linux_auditd_syscall.yml | 92 +- data_sources/linux_secure.yml | 80 +- .../ms365_defender_incident_alerts.yml | 407 ++-- data_sources/ms_defender_atp_alerts.yml | 684 +++--- data_sources/nginx_access.yml | 128 +- data_sources/o365.yml | 16 +- ...add_app_role_assignment_grant_to_user_.yml | 152 +- ..._role_assignment_to_service_principal_.yml | 150 +- data_sources/o365_add_mailboxpermission.yml | 134 +- data_sources/o365_add_member_to_role_.yml | 156 +- .../o365_add_owner_to_application_.yml | 160 +- data_sources/o365_add_service_principal_.yml | 160 +- data_sources/o365_change_user_license_.yml | 152 +- data_sources/o365_consent_to_application_.yml | 144 +- .../o365_disable_strong_authentication_.yml | 146 +- data_sources/o365_mailitemsaccessed.yml | 138 +- data_sources/o365_modifyfolderpermissions.yml | 174 +- .../o365_set_company_information_.yml | 162 +- data_sources/o365_set_mailbox.yml | 154 +- data_sources/o365_update_application_.yml | 160 +- .../o365_update_authorization_policy_.yml | 144 +- data_sources/o365_update_user_.yml | 158 +- data_sources/o365_userloggedin.yml | 158 +- data_sources/o365_userloginfailed.yml | 176 +- data_sources/okta.yml | 16 +- data_sources/osquery.yml | 116 +- data_sources/palo_alto_network_threat.yml | 55 +- data_sources/palo_alto_network_traffic.yml | 58 +- data_sources/pingid.yml | 64 +- .../powershell_installed_iis_modules.yml | 28 +- .../powershell_script_block_logging_4104.yml | 155 +- data_sources/powershell_sip_inventory.yml | 8 +- data_sources/splunk.yml | 56 +- data_sources/splunk_stream_http.yml | 106 +- data_sources/splunk_stream_ip.yml | 139 +- data_sources/splunk_stream_tcp.yml | 16 +- data_sources/suricata.yml | 102 +- data_sources/sysmon_eventid_1.yml | 293 ++- data_sources/sysmon_eventid_10.yml | 176 +- data_sources/sysmon_eventid_11.yml | 181 +- data_sources/sysmon_eventid_12.yml | 171 +- data_sources/sysmon_eventid_13.yml | 198 +- data_sources/sysmon_eventid_15.yml | 177 +- data_sources/sysmon_eventid_17.yml | 152 +- data_sources/sysmon_eventid_18.yml | 158 +- data_sources/sysmon_eventid_20.yml | 164 +- data_sources/sysmon_eventid_21.yml | 168 +- data_sources/sysmon_eventid_22.yml | 156 +- data_sources/sysmon_eventid_23.yml | 180 +- data_sources/sysmon_eventid_3.yml | 208 +- data_sources/sysmon_eventid_5.yml | 152 +- data_sources/sysmon_eventid_6.yml | 159 +- data_sources/sysmon_eventid_7.yml | 199 +- data_sources/sysmon_eventid_8.yml | 180 +- data_sources/sysmon_eventid_9.yml | 154 +- data_sources/sysmon_for_linux_eventid_1.yml | 198 +- data_sources/sysmon_for_linux_eventid_11.yml | 154 +- .../windows_active_directory_admon.yml | 96 +- data_sources/windows_defender_alerts.yml | 100 +- .../windows_event_log_application_2282.yml | 123 +- .../windows_event_log_application_3000.yml | 108 +- data_sources/windows_event_log_capi2_70.yml | 116 +- data_sources/windows_event_log_capi2_81.yml | 122 +- ...ent_log_certificateservicesclient_1007.yml | 118 +- .../windows_event_log_defender_1121.yml | 125 +- .../windows_event_log_defender_1122.yml | 119 +- .../windows_event_log_defender_1129.yml | 104 +- .../windows_event_log_defender_5007.yml | 97 +- ...indows_terminalservices_rdpclient_1024.yml | 72 +- .../windows_event_log_printservice_316.yml | 98 +- .../windows_event_log_printservice_808.yml | 106 +- ...event_log_remoteconnectionmanager_1149.yml | 99 +- .../windows_event_log_security_1100.yml | 138 +- .../windows_event_log_security_1102.yml | 150 +- .../windows_event_log_security_4624.yml | 223 +- .../windows_event_log_security_4625.yml | 213 +- .../windows_event_log_security_4627.yml | 171 +- .../windows_event_log_security_4648.yml | 197 +- .../windows_event_log_security_4662.yml | 171 +- .../windows_event_log_security_4663.yml | 184 +- .../windows_event_log_security_4672.yml | 151 +- .../windows_event_log_security_4688.yml | 235 ++- .../windows_event_log_security_4698.yml | 154 +- .../windows_event_log_security_4699.yml | 152 +- .../windows_event_log_security_4703.yml | 192 +- .../windows_event_log_security_4719.yml | 163 +- .../windows_event_log_security_4720.yml | 198 +- .../windows_event_log_security_4724.yml | 182 +- .../windows_event_log_security_4725.yml | 182 +- .../windows_event_log_security_4726.yml | 184 +- .../windows_event_log_security_4732.yml | 174 +- .../windows_event_log_security_4738.yml | 222 +- .../windows_event_log_security_4739.yml | 198 +- .../windows_event_log_security_4741.yml | 224 +- .../windows_event_log_security_4742.yml | 226 +- .../windows_event_log_security_4768.yml | 186 +- .../windows_event_log_security_4769.yml | 186 +- .../windows_event_log_security_4771.yml | 174 +- .../windows_event_log_security_4776.yml | 156 +- .../windows_event_log_security_4781.yml | 187 +- .../windows_event_log_security_4794.yml | 171 +- .../windows_event_log_security_4798.yml | 167 +- .../windows_event_log_security_4876.yml | 155 +- .../windows_event_log_security_4886.yml | 139 +- .../windows_event_log_security_4887.yml | 145 +- .../windows_event_log_security_5136.yml | 178 +- .../windows_event_log_security_5137.yml | 171 +- .../windows_event_log_security_5140.yml | 206 +- .../windows_event_log_security_5141.yml | 167 +- .../windows_event_log_security_5145.yml | 246 ++- .../windows_event_log_system_4720.yml | 204 +- .../windows_event_log_system_4726.yml | 184 +- .../windows_event_log_system_4728.yml | 184 +- .../windows_event_log_system_7036.yml | 135 +- .../windows_event_log_system_7040.yml | 140 +- .../windows_event_log_system_7045.yml | 140 +- .../windows_event_log_taskscheduler_200.yml | 133 +- data_sources/windows_iis.yml | 14 +- data_sources/windows_iis_29.yml | 46 +- 216 files changed, 16448 insertions(+), 16889 deletions(-) diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml index 05767f098b..440735d18e 100644 --- a/data_sources/asl_aws_cloudtrail.yml +++ b/data_sources/asl_aws_cloudtrail.yml @@ -5,22 +5,22 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Represents AWS API dataset data collection from Amazon Security Lake. mitre_components: - - Cloud Service Metadata - - Cloud Service Modification - - Cloud Storage Access - - Instance Creation - - Instance Deletion - - Instance Start - - Instance Stop - - Instance Modification - - Cloud Storage Creation - - Cloud Storage Deletion - - Cloud Service Enumeration - - Cloud Storage Enumeration +- Cloud Service Metadata +- Cloud Service Modification +- Cloud Storage Access +- Instance Creation +- Instance Deletion +- Instance Start +- Instance Stop +- Instance Modification +- Cloud Storage Creation +- Cloud Storage Deletion +- Cloud Service Enumeration +- Cloud Storage Enumeration source: aws_asl sourcetype: aws:asl separator: api.operation supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 diff --git a/data_sources/aws_cloudfront.yml b/data_sources/aws_cloudfront.yml index b8eb8a416b..f6df73faea 100644 --- a/data_sources/aws_cloudfront.yml +++ b/data_sources/aws_cloudfront.yml @@ -6,98 +6,98 @@ author: Patrick Bareiss, Splunk description: Logs requests made to AWS CloudFront distributions, including details on client access, response data, and performance metrics. mitre_components: - - Network Traffic Content - - Network Traffic Flow - - Response Metadata - - Response Content - - Logon Session Metadata - - Cloud Service Metadata +- Network Traffic Content +- Network Traffic Flow +- Response Metadata +- Response Content +- Logon Session Metadata +- Cloud Service Metadata source: aws sourcetype: aws:cloudfront:accesslogs supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - bytes - - bytes_in - - bytes_out - - c_ip - - c_port - - cached - - category - - client_ip - - cs_bytes - - cs_cookie - - cs_host - - cs_method - - cs_protocol - - cs_protocol_version - - cs_referer - - cs_uri_query - - cs_uri_stem - - cs_user_agent - - date - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - duration - - edge_location_name - - eventtype - - fle_encrypted_fields - - fle_status - - host - - http_content_type - - http_method - - http_user_agent - - http_user_agent_length - - index - - linecount - - punct - - response_time - - sc_bytes - - sc_content_len - - sc_content_type - - sc_range_end - - sc_range_start - - sc_status - - source - - sourcetype - - splunk_server - - src - - src_ip - - src_port - - ssl_cipher - - ssl_protocol - - status - - tag - - tag::eventtype - - time - - time_taken - - time_to_first_byte - - timeendpos - - timestartpos - - uri_path - - url - - url_domain - - url_length - - vendor_product - - x_edge_detail_result_type - - x_edge_location - - x_edge_request_id - - x_edge_response_result_type - - x_edge_result_type - - x_forwarded_for - - x_host_header +- _time +- action +- app +- bytes +- bytes_in +- bytes_out +- c_ip +- c_port +- cached +- category +- client_ip +- cs_bytes +- cs_cookie +- cs_host +- cs_method +- cs_protocol +- cs_protocol_version +- cs_referer +- cs_uri_query +- cs_uri_stem +- cs_user_agent +- date +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- duration +- edge_location_name +- eventtype +- fle_encrypted_fields +- fle_status +- host +- http_content_type +- http_method +- http_user_agent +- http_user_agent_length +- index +- linecount +- punct +- response_time +- sc_bytes +- sc_content_len +- sc_content_type +- sc_range_end +- sc_range_start +- sc_status +- source +- sourcetype +- splunk_server +- src +- src_ip +- src_port +- ssl_cipher +- ssl_protocol +- status +- tag +- tag::eventtype +- time +- time_taken +- time_to_first_byte +- timeendpos +- timestartpos +- uri_path +- url +- url_domain +- url_length +- vendor_product +- x_edge_detail_result_type +- x_edge_location +- x_edge_request_id +- x_edge_response_result_type +- x_edge_result_type +- x_forwarded_for +- x_host_header example_log: "2023-11-07\t16:58:21\tIAD55-P5\t921\t44.192.78.55\tGET\td3u5aue66f5ui4.cloudfront.net\t\ /plugins/servlet/com.jsos.shell/ShellServlet\t200\t-\tSlackbot-LinkExpanding%201.0%20(+https://api.slack.com/robots)\t\ -\t-\tLambdaGeneratedResponse\tsGwvFCkFU4qlMxatCoJRgW87P7Ee8bKQor3U6lRt6I6jaFvLC7vcPA==\t\ diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml index c9823cd2d7..c8b978c277 100644 --- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml +++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml @@ -6,109 +6,109 @@ author: Patrick Bareiss, Splunk description: Logs attempts to assume roles via SAML authentication in AWS, including details of identity provider and role mapping. mitre_components: - - User Account Authentication - - Logon Session Creation - - User Account Metadata - - Cloud Service Metadata - - Instance Modification +- User Account Authentication +- Logon Session Creation +- User Account Metadata +- Cloud Service Metadata +- Instance Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: AssumeRoleWithSAML supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.durationSeconds - - requestParameters.principalArn - - requestParameters.roleArn - - requestParameters.roleSessionName - - requestParameters.sAMLAssertionID - - resources{}.ARN - - resources{}.accountId - - resources{}.type - - responseElements.assumedRoleUser.arn - - responseElements.assumedRoleUser.assumedRoleId - - responseElements.audience - - responseElements.credentials.accessKeyId - - responseElements.credentials.expiration - - responseElements.credentials.sessionToken - - responseElements.issuer - - responseElements.nameQualifier - - responseElements.subject - - responseElements.subjectType - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - src_user - - src_user_id - - src_user_type - - start_time - - status - - tag - - tag::action - - tag::eventtype - - temp_access_key - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.identityProvider - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - user_agent - - user_arn - - user_id - - user_name - - user_role - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.durationSeconds +- requestParameters.principalArn +- requestParameters.roleArn +- requestParameters.roleSessionName +- requestParameters.sAMLAssertionID +- resources{}.ARN +- resources{}.accountId +- resources{}.type +- responseElements.assumedRoleUser.arn +- responseElements.assumedRoleUser.assumedRoleId +- responseElements.audience +- responseElements.credentials.accessKeyId +- responseElements.credentials.expiration +- responseElements.credentials.sessionToken +- responseElements.issuer +- responseElements.nameQualifier +- responseElements.subject +- responseElements.subjectType +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- src_user +- src_user_id +- src_user_type +- start_time +- status +- tag +- tag::action +- tag::eventtype +- temp_access_key +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.identityProvider +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- user_agent +- user_arn +- user_id +- user_name +- user_role +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "principalId": "ZRu9MRAjiG9tvi1QBNfdI664G5A=:rodsoto@rodsoto.onmicrosoft.com", "userName": "rodsoto@rodsoto.onmicrosoft.com", "identityProvider": "ZRu9MRAjiG9tvi1QBNfdI664G5A="}, "eventTime": "2021-01-22T03:44:16Z", diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml index 0d05cff28d..441afb6cea 100644 --- a/data_sources/aws_cloudtrail_consolelogin.yml +++ b/data_sources/aws_cloudtrail_consolelogin.yml @@ -6,97 +6,97 @@ author: Patrick Bareiss, Splunk description: Logs attempts to sign in to the AWS Management Console, including successful and failed login events. mitre_components: - - User Account Authentication - - Logon Session Creation - - User Account Metadata - - Logon Session Metadata - - Cloud Service Metadata +- User Account Authentication +- Logon Session Creation +- User Account Metadata +- Logon Session Metadata +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: ConsoleLogin supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - additionalEventData.LoginTo - - additionalEventData.MFAUsed - - additionalEventData.MobileVersion - - app - - authentication_method - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - desc - - dest - - dvc - - errorCode - - errorMessage - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - reason - - recipientAccountId - - region - - requestParameters - - responseElements.ConsoleLogin - - result - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::action - - tag::eventtype - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.type - - userIdentity.userName - - user_access_key - - user_agent - - user_group_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- additionalEventData.LoginTo +- additionalEventData.MFAUsed +- additionalEventData.MobileVersion +- app +- authentication_method +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- desc +- dest +- dvc +- errorCode +- errorMessage +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- reason +- recipientAccountId +- region +- requestParameters +- responseElements.ConsoleLogin +- result +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::action +- tag::eventtype +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.type +- userIdentity.userName +- user_access_key +- user_agent +- user_group_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "accountId": "140429656527", "accessKeyId": "", "userName": "HIDDEN_DUE_TO_SECURITY_REASONS"}, "eventTime": "2022-10-19T20:33:38Z", "eventSource": "signin.amazonaws.com", "eventName": diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml index 9edd40bb4d..93ea12c92f 100644 --- a/data_sources/aws_cloudtrail_copyobject.yml +++ b/data_sources/aws_cloudtrail_copyobject.yml @@ -6,102 +6,102 @@ author: Patrick Bareiss, Splunk description: Logs operations that copy objects within or between AWS S3 buckets, including details of source and destination. mitre_components: - - Cloud Storage Access - - Cloud Storage Modification - - Cloud Storage Metadata - - Instance Modification +- Cloud Storage Access +- Cloud Storage Modification +- Cloud Storage Metadata +- Instance Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_values: CopyObject supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - additionalEventData.AuthenticationMethod - - additionalEventData.CipherSuite - - additionalEventData.SSEApplied - - additionalEventData.SignatureVersion - - additionalEventData.bytesTransferredIn - - additionalEventData.bytesTransferredOut - - additionalEventData.x-amz-id-2 - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.Host - - requestParameters.bucketName - - requestParameters.key - - requestParameters.x-amz-copy-source - - requestParameters.x-amz-server-side-encryption - - requestParameters.x-amz-server-side-encryption-aws-kms-key-id - - resources{}.ARN - - resources{}.accountId - - resources{}.type - - responseElements.x-amz-server-side-encryption - - responseElements.x-amz-server-side-encryption-aws-kms-key-id - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- additionalEventData.AuthenticationMethod +- additionalEventData.CipherSuite +- additionalEventData.SSEApplied +- additionalEventData.SignatureVersion +- additionalEventData.bytesTransferredIn +- additionalEventData.bytesTransferredOut +- additionalEventData.x-amz-id-2 +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.Host +- requestParameters.bucketName +- requestParameters.key +- requestParameters.x-amz-copy-source +- requestParameters.x-amz-server-side-encryption +- requestParameters.x-amz-server-side-encryption-aws-kms-key-id +- resources{}.ARN +- resources{}.accountId +- resources{}.type +- responseElements.x-amz-server-side-encryption +- responseElements.x-amz-server-side-encryption-aws-kms-key-id +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"}, diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml index d72354f779..e32d68ce5f 100644 --- a/data_sources/aws_cloudtrail_createaccesskey.yml +++ b/data_sources/aws_cloudtrail_createaccesskey.yml @@ -6,96 +6,96 @@ author: Patrick Bareiss, Splunk description: Logs the creation of new AWS access keys, including details of the associated user and permissions. mitre_components: - - User Account Creation - - User Account Metadata - - Cloud Service Modification - - Cloud Service Metadata +- User Account Creation +- User Account Metadata +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateAccessKey supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.userName - - responseElements.accessKey.accessKeyId - - responseElements.accessKey.createDate - - responseElements.accessKey.status - - responseElements.accessKey.userName - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - src_user_name - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.userName +- responseElements.accessKey.accessKeyId +- responseElements.accessKey.createDate +- responseElements.accessKey.status +- responseElements.accessKey.userName +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- src_user_name +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121521347698:user/bhavin_cli", "accountId": "121521347698", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml index 293ecba3cd..c6c31a41a3 100644 --- a/data_sources/aws_cloudtrail_createkey.yml +++ b/data_sources/aws_cloudtrail_createkey.yml @@ -6,114 +6,114 @@ author: Patrick Bareiss, Splunk description: Logs the creation of new AWS KMS keys, including details of key properties and associated metadata. mitre_components: - - Cloud Service Creation - - Cloud Service Metadata - - Instance Creation - - Volume Metadata +- Cloud Service Creation +- Cloud Service Metadata +- Instance Creation +- Volume Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateKey supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.bypassPolicyLockoutSafetyCheck - - requestParameters.customerMasterKeySpec - - requestParameters.description - - requestParameters.keyUsage - - requestParameters.origin - - requestParameters.policy - - resources{}.ARN - - resources{}.accountId - - resources{}.type - - responseElements.keyMetadata.aWSAccountId - - responseElements.keyMetadata.arn - - responseElements.keyMetadata.creationDate - - responseElements.keyMetadata.customerMasterKeySpec - - responseElements.keyMetadata.description - - responseElements.keyMetadata.enabled - - responseElements.keyMetadata.encryptionAlgorithms{} - - responseElements.keyMetadata.keyId - - responseElements.keyMetadata.keyManager - - responseElements.keyMetadata.keyState - - responseElements.keyMetadata.keyUsage - - responseElements.keyMetadata.origin - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.bypassPolicyLockoutSafetyCheck +- requestParameters.customerMasterKeySpec +- requestParameters.description +- requestParameters.keyUsage +- requestParameters.origin +- requestParameters.policy +- resources{}.ARN +- resources{}.accountId +- resources{}.type +- responseElements.keyMetadata.aWSAccountId +- responseElements.keyMetadata.arn +- responseElements.keyMetadata.creationDate +- responseElements.keyMetadata.customerMasterKeySpec +- responseElements.keyMetadata.description +- responseElements.keyMetadata.enabled +- responseElements.keyMetadata.encryptionAlgorithms{} +- responseElements.keyMetadata.keyId +- responseElements.keyMetadata.keyManager +- responseElements.keyMetadata.keyState +- responseElements.keyMetadata.keyUsage +- responseElements.keyMetadata.origin +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext": diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml index df6b04e40d..243ad0b5c5 100644 --- a/data_sources/aws_cloudtrail_createloginprofile.yml +++ b/data_sources/aws_cloudtrail_createloginprofile.yml @@ -6,95 +6,95 @@ author: Patrick Bareiss, Splunk description: Logs the creation of login profiles for IAM users, including associated metadata and authentication settings. mitre_components: - - User Account Creation - - User Account Metadata - - Logon Session Metadata - - Cloud Service Metadata +- User Account Creation +- User Account Metadata +- Logon Session Metadata +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateLoginProfile supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.passwordResetRequired - - requestParameters.userName - - responseElements.loginProfile.createDate - - responseElements.loginProfile.passwordResetRequired - - responseElements.loginProfile.userName - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.passwordResetRequired +- requestParameters.userName +- responseElements.loginProfile.createDate +- responseElements.loginProfile.passwordResetRequired +- responseElements.loginProfile.userName +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml index 993b03197a..3f98c6329c 100644 --- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml @@ -6,111 +6,111 @@ author: Patrick Bareiss, Splunk description: Logs the creation of new entries in a network ACL, including rules to allow or deny specific network traffic. mitre_components: - - Firewall Rule Modification - - Network Connection Creation - - Cloud Service Modification - - Cloud Service Metadata +- Firewall Rule Modification +- Network Connection Creation +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateNetworkAclEntry supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - direction - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object - - object_category - - object_id - - product - - protocol - - protocol_code - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.aclProtocol - - requestParameters.cidrBlock - - requestParameters.egress - - requestParameters.networkAclId - - requestParameters.ruleAction - - requestParameters.ruleNumber - - responseElements._return - - responseElements.requestId - - rule_action - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - src_ip_range - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- direction +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object +- object_category +- object_id +- product +- protocol +- protocol_code +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.aclProtocol +- requestParameters.cidrBlock +- requestParameters.egress +- requestParameters.networkAclId +- requestParameters.ruleAction +- requestParameters.ruleNumber +- responseElements._return +- responseElements.requestId +- rule_action +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- src_ip_range +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext": diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml index 2973c651b0..88b3b2aeb7 100644 --- a/data_sources/aws_cloudtrail_createpolicyversion.yml +++ b/data_sources/aws_cloudtrail_createpolicyversion.yml @@ -6,96 +6,96 @@ author: Patrick Bareiss, Splunk description: Logs the creation of new versions of IAM policies, including changes to permissions and attached roles or resources. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata - - User Account Metadata - - Group Modification +- Cloud Service Modification +- Cloud Service Metadata +- User Account Metadata +- Group Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreatePolicyVersion supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.policyArn - - requestParameters.policyDocument - - requestParameters.setAsDefault - - responseElements.policyVersion.createDate - - responseElements.policyVersion.isDefaultVersion - - responseElements.policyVersion.versionId - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.policyArn +- requestParameters.policyDocument +- requestParameters.setAsDefault +- responseElements.policyVersion.createDate +- responseElements.policyVersion.isDefaultVersion +- responseElements.policyVersion.versionId +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLNMCDVJZAY", "arn": "arn:aws:iam::111111111111:user/rhino_escalate", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLHSQZPZFZ", "userName": diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml index ae5c392552..0d724bfada 100644 --- a/data_sources/aws_cloudtrail_createsnapshot.yml +++ b/data_sources/aws_cloudtrail_createsnapshot.yml @@ -6,105 +6,105 @@ author: Patrick Bareiss, Splunk description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon EBS volume, including details about the snapshot ID and resource type. mitre_components: - - Snapshot Creation - - Snapshot Metadata - - Volume Metadata - - Cloud Service Metadata +- Snapshot Creation +- Snapshot Metadata +- Volume Metadata +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateSnapshot supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.tagSpecificationSet.items{}.resourceType - - requestParameters.tagSpecificationSet.items{}.tags{}.key - - requestParameters.tagSpecificationSet.items{}.tags{}.value - - requestParameters.volumeId - - responseElements.encrypted - - responseElements.ownerId - - responseElements.requestId - - responseElements.snapshotId - - responseElements.startTime - - responseElements.status - - responseElements.tagSet.items{}.key - - responseElements.tagSet.items{}.value - - responseElements.volumeId - - responseElements.volumeSize - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.tagSpecificationSet.items{}.resourceType +- requestParameters.tagSpecificationSet.items{}.tags{}.key +- requestParameters.tagSpecificationSet.items{}.tags{}.value +- requestParameters.volumeId +- responseElements.encrypted +- responseElements.ownerId +- responseElements.requestId +- responseElements.snapshotId +- responseElements.startTime +- responseElements.status +- responseElements.tagSet.items{}.key +- responseElements.tagSet.items{}.value +- responseElements.volumeId +- responseElements.volumeSize +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml index 7808c2b9cc..3db15c7370 100644 --- a/data_sources/aws_cloudtrail_createtask.yml +++ b/data_sources/aws_cloudtrail_createtask.yml @@ -6,104 +6,104 @@ author: Patrick Bareiss, Splunk description: Logs the creation of a new task in AWS services, such as ECS, including details about the task definition and resource allocation. mitre_components: - - Scheduled Job Creation - - Scheduled Job Metadata - - Cloud Service Metadata - - Instance Creation +- Scheduled Job Creation +- Scheduled Job Metadata +- Cloud Service Metadata +- Instance Creation source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_name: CreateTask supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.cloudWatchLogGroupArn - - requestParameters.destinationLocationArn - - requestParameters.options.logLevel - - requestParameters.options.verifyMode - - requestParameters.schedule.scheduleExpression - - requestParameters.sourceLocationArn - - responseElements.taskArn - - sessionCredentialFromConsole - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.cloudWatchLogGroupArn +- requestParameters.destinationLocationArn +- requestParameters.options.logLevel +- requestParameters.options.verifyMode +- requestParameters.schedule.scheduleExpression +- requestParameters.sourceLocationArn +- responseElements.taskArn +- sessionCredentialFromConsole +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WQQQQQ:abc@acme.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/abc@acme.com", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLOB2GM111", "sessionContext": diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml index 7b6b181672..f76f14d9c1 100644 --- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml @@ -6,94 +6,94 @@ author: Patrick Bareiss, Splunk description: Logs the creation of a new virtual multi-factor authentication (MFA) device, including details about the associated user and configuration. mitre_components: - - User Account Creation - - User Account Metadata - - Cloud Service Creation - - Cloud Service Metadata +- User Account Creation +- User Account Metadata +- Cloud Service Creation +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: CreateVirtualMFADevice supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.path - - requestParameters.virtualMFADeviceName - - responseElements.virtualMFADevice.serialNumber - - sessionCredentialFromConsole - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.path +- requestParameters.virtualMFADeviceName +- responseElements.virtualMFADevice.serialNumber +- sessionCredentialFromConsole +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527", "accessKeyId": "ASIASBMSCQHH2YXNXJBU", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml index e53018b544..06d7103bfe 100644 --- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml +++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml @@ -6,94 +6,94 @@ author: Patrick Bareiss, Splunk description: Logs the deactivation of a multi-factor authentication (MFA) device, including details about the associated user and the device. mitre_components: - - User Account Modification - - User Account Metadata - - Cloud Service Modification - - Cloud Service Metadata +- User Account Modification +- User Account Metadata +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeactivateMFADevice supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.serialNumber - - requestParameters.userName - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.serialNumber +- requestParameters.userName +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111", "accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml index 9d10c7443a..feeaa4fd66 100644 --- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml @@ -6,93 +6,93 @@ author: Patrick Bareiss, Splunk description: Logs the deletion of an account-level password policy in AWS, including details about the account and policy being removed. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteAccountPasswordPolicy supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - desc - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters - - responseElements - - sessionCredentialFromConsole - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- desc +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters +- responseElements +- sessionCredentialFromConsole +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111", "accessKeyId": "ASIASBMSCQHHWMDJXSE6", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml index 7babfa595c..8b11625dfe 100644 --- a/data_sources/aws_cloudtrail_deletealarms.yml +++ b/data_sources/aws_cloudtrail_deletealarms.yml @@ -6,128 +6,128 @@ author: Bhavin Patel, Splunk description: Logs the deletion of CloudWatch alarms, including details about the alarm names and associated monitoring configurations. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata - - Application Log Content - - Host Status +- Cloud Service Modification +- Cloud Service Metadata +- Application Log Content +- Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteAlarms supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - authentication_method - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - desc - - dest - - dest_ip_range - - dest_port_range - - direction - - dvc - - errorCode - - errorMessage - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - image_id - - index - - instance_type - - linecount - - managementEvent - - msg - - object - - object_attrs - - object_category - - object_id - - product - - protocol - - protocol_code - - punct - - readOnly - - reason - - recipientAccountId - - region - - requestID - - requestParameters.alarmNames{} - - responseElements - - result - - result_id - - rule_action - - sessionCredentialFromConsole - - signature - - source - - sourceIPAddress - - splunk_server - - splunk_server_group - - src - - src_ip - - src_ip_range - - src_port_range - - src_user - - src_user_id - - src_user_name - - src_user_role - - src_user_type - - start_time - - status - - tag - - tag::action - - tag::eventtype - - tag::object_category - - temp_access_key - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.invokedBy - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_role - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- authentication_method +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- desc +- dest +- dest_ip_range +- dest_port_range +- direction +- dvc +- errorCode +- errorMessage +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- image_id +- index +- instance_type +- linecount +- managementEvent +- msg +- object +- object_attrs +- object_category +- object_id +- product +- protocol +- protocol_code +- punct +- readOnly +- reason +- recipientAccountId +- region +- requestID +- requestParameters.alarmNames{} +- responseElements +- result +- result_id +- rule_action +- sessionCredentialFromConsole +- signature +- source +- sourceIPAddress +- splunk_server +- splunk_server_group +- src +- src_ip +- src_ip_range +- src_port_range +- src_user +- src_user_id +- src_user_name +- src_user_role +- src_user_type +- start_time +- status +- tag +- tag::action +- tag::eventtype +- tag::object_category +- temp_access_key +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.invokedBy +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_role +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLKZK7JIDWN:AutoScaling-ManageAlarms", "arn": "arn:aws:sts::111111111111:assumed-role/AWSServiceRoleForApplicationAutoScaling_DynamoDBTable/AutoScaling-ManageAlarms", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLJ7ZZZZZZZ", "sessionContext": diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml index f20cba230e..1046a8b7db 100644 --- a/data_sources/aws_cloudtrail_deletedetector.yml +++ b/data_sources/aws_cloudtrail_deletedetector.yml @@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk description: Logs the deletion of an Amazon GuardDuty detector, including details about the detector ID and associated configurations. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata - - Host Status - - Application Log Content +- Cloud Service Modification +- Cloud Service Metadata +- Host Status +- Application Log Content source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteDetector supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.detectorId - - responseElements.__type - - responseElements.message - - result_id - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.detectorId +- responseElements.__type +- responseElements.message +- result_id +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml index e2bd256da6..e8e98628b6 100644 --- a/data_sources/aws_cloudtrail_deletegroup.yml +++ b/data_sources/aws_cloudtrail_deletegroup.yml @@ -6,96 +6,96 @@ author: Patrick Bareiss, Splunk description: Logs the deletion of an IAM group in AWS, including details about the group name and its associated policies or members. mitre_components: - - Group Modification - - Group Metadata - - User Account Metadata - - Cloud Service Modification +- Group Modification +- Group Metadata +- User Account Metadata +- Cloud Service Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteGroup supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - errorMessage - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - reason - - recipientAccountId - - region - - requestID - - requestParameters.groupName - - responseElements - - result - - result_id - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- errorMessage +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- reason +- recipientAccountId +- region +- requestID +- requestParameters.groupName +- responseElements +- result +- result_id +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121522247101:user/bhavin_cli", "accountId": "121522247101", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml index ce670c3006..3f00e45f4d 100644 --- a/data_sources/aws_cloudtrail_deleteipset.yml +++ b/data_sources/aws_cloudtrail_deleteipset.yml @@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details about the IP set ID and its associated configurations. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata - - Firewall Rule Modification +- Cloud Service Modification +- Cloud Service Metadata +- Firewall Rule Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteIPSet supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.detectorId - - requestParameters.ipSetId - - responseElements.__type - - responseElements.message - - result_id - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.detectorId +- requestParameters.ipSetId +- responseElements.__type +- responseElements.message +- result_id +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml index 3aafeff30a..8e4206a1fb 100644 --- a/data_sources/aws_cloudtrail_deleteloggroup.yml +++ b/data_sources/aws_cloudtrail_deleteloggroup.yml @@ -6,93 +6,93 @@ author: Patrick Bareiss, Splunk description: Logs the deletion of a CloudWatch log group, including details about the log group name and associated resources. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata - - Application Log Content - - Host Status +- Cloud Service Modification +- Cloud Service Metadata +- Application Log Content +- Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteLogGroup supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - apiVersion - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.logGroupName - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- apiVersion +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.logGroupName +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml index 7f4805833e..66ce8c87ec 100644 --- a/data_sources/aws_cloudtrail_deletelogstream.yml +++ b/data_sources/aws_cloudtrail_deletelogstream.yml @@ -6,94 +6,94 @@ author: Patrick Bareiss, Splunk description: Logs the deletion of a log stream within a CloudWatch log group, including details about the stream name and associated log group. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata - - Application Log Content - - Host Status +- Cloud Service Modification +- Cloud Service Metadata +- Application Log Content +- Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteLogStream supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - apiVersion - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.logGroupName - - requestParameters.logStreamName - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- apiVersion +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.logGroupName +- requestParameters.logStreamName +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml index deca786012..860acf5cb3 100644 --- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml @@ -6,100 +6,100 @@ author: Patrick Bareiss, Splunk description: Logs the deletion of a network ACL entry in AWS, including details about the rule number and associated network ACL. mitre_components: - - Firewall Rule Modification - - Cloud Service Modification - - Cloud Service Metadata +- Firewall Rule Modification +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteNetworkAclEntry supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - direction - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.egress - - requestParameters.networkAclId - - requestParameters.ruleNumber - - responseElements._return - - responseElements.requestId - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- direction +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.egress +- requestParameters.networkAclId +- requestParameters.ruleNumber +- responseElements._return +- responseElements.requestId +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext": diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml index 62fa46bbd0..1eb13dccc6 100644 --- a/data_sources/aws_cloudtrail_deletepolicy.yml +++ b/data_sources/aws_cloudtrail_deletepolicy.yml @@ -6,94 +6,94 @@ author: Patrick Bareiss, Splunk description: Logs the deletion of an IAM policy in AWS, including details about the policy name and its associated roles or users. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeletePolicy supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - errorMessage - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - reason - - recipientAccountId - - region - - requestID - - requestParameters.policyArn - - responseElements - - result - - result_id - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- errorMessage +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- reason +- recipientAccountId +- region +- requestID +- requestParameters.policyArn +- responseElements +- result +- result_id +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::151521547504:user/bhavin_cli", "accountId": "151521547504", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml index b5f3c819fa..8cc54b2ae9 100644 --- a/data_sources/aws_cloudtrail_deleterule.yml +++ b/data_sources/aws_cloudtrail_deleterule.yml @@ -6,94 +6,94 @@ author: Patrick Bareiss, Splunk description: Logs the deletion of an event rule in AWS EventBridge, including details about the rule name and its associated targets or schedules. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata - - Scheduled Job Modification - - Application Log Content +- Cloud Service Modification +- Cloud Service Metadata +- Scheduled Job Modification +- Application Log Content source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteRule supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - apiVersion - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.changeToken - - requestParameters.ruleId - - responseElements.changeToken - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- apiVersion +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.changeToken +- requestParameters.ruleId +- responseElements.changeToken +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml index 62a075237d..6d802d417f 100644 --- a/data_sources/aws_cloudtrail_deletesnapshot.yml +++ b/data_sources/aws_cloudtrail_deletesnapshot.yml @@ -6,135 +6,135 @@ author: Bhavin Patel, Splunk description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS snapshot, including details about the snapshot ID and associated resource. mitre_components: - - Snapshot Deletion - - Snapshot Metadata - - Cloud Service Modification - - Cloud Service Metadata +- Snapshot Deletion +- Snapshot Metadata +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteSnapshot supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - authentication_method - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - desc - - dest - - dest_ip_range - - dest_port_range - - direction - - dvc - - errorCode - - errorMessage - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - image_id - - index - - instance_type - - linecount - - managementEvent - - msg - - object - - object_attrs - - object_category - - object_id - - product - - protocol - - protocol_code - - punct - - readOnly - - reason - - recipientAccountId - - region - - requestID - - requestParameters.force - - requestParameters.snapshotId - - responseElements - - responseElements._return - - responseElements.requestId - - result - - result_id - - rule_action - - sessionCredentialFromConsole - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - splunk_server_group - - src - - src_ip - - src_ip_range - - src_port_range - - src_user - - src_user_id - - src_user_name - - src_user_role - - src_user_type - - start_time - - status - - tag - - tag::action - - tag::eventtype - - tag::object_category - - temp_access_key - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_role - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- authentication_method +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- desc +- dest +- dest_ip_range +- dest_port_range +- direction +- dvc +- errorCode +- errorMessage +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- image_id +- index +- instance_type +- linecount +- managementEvent +- msg +- object +- object_attrs +- object_category +- object_id +- product +- protocol +- protocol_code +- punct +- readOnly +- reason +- recipientAccountId +- region +- requestID +- requestParameters.force +- requestParameters.snapshotId +- responseElements +- responseElements._return +- responseElements.requestId +- result +- result_id +- rule_action +- sessionCredentialFromConsole +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- splunk_server_group +- src +- src_ip +- src_ip_range +- src_port_range +- src_user +- src_user_id +- src_user_name +- src_user_role +- src_user_type +- start_time +- status +- tag +- tag::action +- tag::eventtype +- tag::object_category +- temp_access_key +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_role +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.09", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WPXXXX:daftpunk@splunk.com", "arn": "arn:aws:sts::11111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/daftpunk@splunk.com", "accountId": "11111111111111", "accessKeyId": "AAAAAAAAAAAAAAAAAA", "sessionContext": diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml index 2d077d3400..1ab9032017 100644 --- a/data_sources/aws_cloudtrail_deletetrail.yml +++ b/data_sources/aws_cloudtrail_deletetrail.yml @@ -6,92 +6,92 @@ author: Patrick Bareiss, Splunk description: Logs the deletion of an AWS CloudTrail trail, including details about the trail name and its associated logging configurations. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata - - Application Log Content - - Host Status +- Cloud Service Modification +- Cloud Service Metadata +- Application Log Content +- Host Status source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteTrail supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.name - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.name +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml index ba7bd9f0b0..4a7caa655b 100644 --- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml @@ -6,92 +6,92 @@ author: Patrick Bareiss, Splunk description: Logs an event when a virtual Multi-Factor Authentication (MFA) device is deleted in AWS CloudTrail. mitre_components: - - User Account Authentication - - User Account Deletion +- User Account Authentication +- User Account Deletion source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteVirtualMFADevice supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.serialNumber - - responseElements - - sessionCredentialFromConsole - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.serialNumber +- responseElements +- sessionCredentialFromConsole +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111", "accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml index dad7353b3b..8386aa1d15 100644 --- a/data_sources/aws_cloudtrail_deletewebacl.yml +++ b/data_sources/aws_cloudtrail_deletewebacl.yml @@ -6,92 +6,92 @@ author: Patrick Bareiss, Splunk description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS CloudTrail. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DeleteWebACL supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - apiVersion - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.changeToken - - requestParameters.webACLId - - responseElements.changeToken - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- apiVersion +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.changeToken +- requestParameters.webACLId +- responseElements.changeToken +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml index 51c3b5464a..4ad39a0e97 100644 --- a/data_sources/aws_cloudtrail_describeeventaggregates.yml +++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml @@ -6,88 +6,88 @@ author: Patrick Bareiss, Splunk description: Logs an event when aggregate details about AWS events are queried, often for analysis. mitre_components: - - Cloud Service Enumeration - - Cloud Service Metadata +- Cloud Service Enumeration +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DescribeEventAggregates supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.aggregateField - - requestParameters.filter.eventStatusCodes{} - - requestParameters.filter.startTimes{}.from - - responseElements - - sessionCredentialFromConsole - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.aggregateField +- requestParameters.filter.eventStatusCodes{} +- requestParameters.filter.startTimes{}.from +- responseElements +- sessionCredentialFromConsole +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527", "accessKeyId": "ASIASBMSCQHHQQ6LB24V", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml index fab3a5b39f..e91321536e 100644 --- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml +++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml @@ -6,980 +6,896 @@ author: Patrick Bareiss, Splunk description: Logs an event when findings from an image vulnerability scan are described using the DescribeImageScanFindings operation in AWS CloudTrail. mitre_components: - - Image Metadata - - Image Modification - - Malware Metadata +- Image Metadata +- Image Modification +- Malware Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: DescribeImageScanFindings supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.imageId.imageDigest - - requestParameters.maxResults - - requestParameters.repositoryName - - responseElements.imageId.imageDigest - - responseElements.imageScanFindings.findingSeverityCounts.HIGH - - responseElements.imageScanFindings.findingSeverityCounts.INFORMATIONAL - - responseElements.imageScanFindings.findingSeverityCounts.LOW - - responseElements.imageScanFindings.findingSeverityCounts.MEDIUM - - responseElements.imageScanFindings.findingSeverityCounts.UNDEFINED - - responseElements.imageScanFindings.findings{}.attributes{}.key - - responseElements.imageScanFindings.findings{}.attributes{}.value - - responseElements.imageScanFindings.findings{}.description - - responseElements.imageScanFindings.findings{}.name - - responseElements.imageScanFindings.findings{}.severity - - responseElements.imageScanFindings.findings{}.uri - - responseElements.imageScanFindings.imageScanCompletedAt - - responseElements.imageScanFindings.vulnerabilitySourceUpdatedAt - - responseElements.imageScanStatus.description - - responseElements.imageScanStatus.status - - responseElements.registryId - - responseElements.repositoryName - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region -example_log: "{\"eventVersion\": \"1.08\", \"userIdentity\": {\"type\": \"AssumedRole\"\ - , \"principalId\": \"AAAAAAAAAAAAAAAAAAAAA:test@test.com\", \"arn\": \"arn:aws:sts::111111111111:assumed-role/role_name/test@test.com\"\ - , \"accountId\": \"111111111111\", \"accessKeyId\": \"AKIAIOSFODNN7EXAMPLE\", \"\ - sessionContext\": {\"sessionIssuer\": {\"type\": \"Role\", \"principalId\": \"AKIAIOSFODNN7EXAMPLE\"\ - , \"arn\": \"arn:aws:iam::111111111111:role/aws-reserved/test/region/group\", \"\ - accountId\": \"111111111111\", \"userName\": \"test\"}, \"webIdFederationData\" - : {}, \"attributes\": {\"creationDate\": \"2021-08-11T09:42:53Z\", \"mfaAuthenticated\"\ - : \"false\"}}}, \"eventTime\": \"2021-08-11T11:52:27Z\", \"eventSource\": \"ecr.amazonaws.com\"\ - , \"eventName\": \"DescribeImageScanFindings\", \"awsRegion\": \"eu-central-1\" - , \"sourceIPAddress\": \"154.16.165.133\", \"userAgent\": \"aws-internal/3 aws-sdk-java/1.11.1030 - Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08 - java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy\", \"requestParameters\"\ - : {\"repositoryName\": \"devsecops/cat_dog_client\", \"imageId\": {\"imageDigest\"\ - : \"sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6\"}, - \"maxResults\": 1000}, \"responseElements\": {\"registryId\": \"111111111111\", - \"repositoryName\": \"devsecops/cat_dog_client\", \"imageId\": {\"imageDigest\" - : \"sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6\"}, - \"imageScanStatus\": {\"status\": \"COMPLETE\", \"description\": \"The scan was - completed successfully.\"}, \"imageScanFindings\": {\"imageScanCompletedAt\": \"\ - Aug 11, 2021, 11:30:16 AM\", \"vulnerabilitySourceUpdatedAt\": \"Aug 11, 2021, 1:17:52 - AM\", \"findings\": [{\"name\": \"CVE-2019-25013\", \"description\": \"The iconv - feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing - invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-25013\", \"severity\"\ - : \"HIGH\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\ - }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ - , \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:C\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ - : \"7.1\"}]}, {\"name\": \"CVE-2021-33574\", \"description\": \"The mq_notify function - in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It - may use the notification thread attributes object (passed through its struct sigevent - parameter) after it has been freed by the caller, leading to a denial of service - (application crash) or possibly unspecified other impact.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-33574\"\ - , \"severity\": \"HIGH\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-12886\", \"description\": \"stack_protect_prologue - in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection - (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences - when targeting ARM targets that spill the address of the stack protector guard, - which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, - -fstack-protector-strong, and -fstack-protector-explicit against stack overflow - by controlling what the stack canary is compared against.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-12886\"\ - , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"8.3.0-6\"}, {\"key\": \"package_name\", \"value\": \"gcc-8\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-1751\", \"description\": \"An out-of-bounds - write vulnerability was found in glibc before 2.31 when handling signal trampolines - on PowerPC. Specifically, the backtrace function did not properly check the array - bounds when storing the frame address, resulting in a denial of service or potential - code execution. The highest threat from this vulnerability is to system availability.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-1751\", \"severity\"\ - : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\ - }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ - , \"value\": \"AV:L/AC:M/Au:N/C:P/I:P/A:C\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ - : \"5.9\"}]}, {\"name\": \"CVE-2021-3326\", \"description\": \"The iconv function - in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid - input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path - and aborts the program, potentially resulting in a denial of service.\", \"uri\"\ - : \"https://security-tracker.debian.org/tracker/CVE-2021-3326\", \"severity\": \"\ - MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.28-10\"\ - }, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ - , \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ - : \"5\"}]}, {\"name\": \"CVE-2021-35942\", \"description\": \"The wordexp function - in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory - in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, - potentially resulting in a denial of service or disclosure of information. This - occurs because atoi was used but strtoul should have been used to ensure correct - calculations.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-35942\"\ - , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"6.4\"}]}, {\"name\": \"CVE-2019-12904\", \"description\": \"In Libgcrypt - 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel - attack because physical addresses are available to other processes. (The C implementation - is used on platforms where an assembly-language implementation is unavailable.)\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-12904\", \"severity\"\ - : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.4-5+deb10u1\"\ - }, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"}, {\"key\": \"CVSS2_VECTOR\"\ - , \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ - : \"4.3\"}]}, {\"name\": \"CVE-2017-6363\", \"description\": \"** DISPUTED ** In - the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer - over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says \\\"In my opinion this - issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, - and should only be used for development and testing purposes.'\\\"\", \"uri\": \"\ - https://security-tracker.debian.org/tracker/CVE-2017-6363\", \"severity\": \"MEDIUM\"\ - , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"}, {\"\ - key\": \"package_name\", \"value\": \"libgd2\"}, {\"key\": \"CVSS2_VECTOR\", \"\ - value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\": - \"5.8\"}]}, {\"name\": \"CVE-2019-12290\", \"description\": \"GNU libidn2 before - 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when - converting A-labels to U-labels. This makes it possible in some circumstances for - one domain to impersonate another. By creating a malicious domain that matches a - target domain except for the inclusion of certain punycoded Unicode characters (that - would be discarded when converted first to a Unicode label and then back to an ASCII - label), arbitrary domains can be impersonated.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-12290\"\ - , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.0.5-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libidn2\"}, {\"\ - key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"\ - CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-13115\", \"description\"\ - : \"In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.imageId.imageDigest +- requestParameters.maxResults +- requestParameters.repositoryName +- responseElements.imageId.imageDigest +- responseElements.imageScanFindings.findingSeverityCounts.HIGH +- responseElements.imageScanFindings.findingSeverityCounts.INFORMATIONAL +- responseElements.imageScanFindings.findingSeverityCounts.LOW +- responseElements.imageScanFindings.findingSeverityCounts.MEDIUM +- responseElements.imageScanFindings.findingSeverityCounts.UNDEFINED +- responseElements.imageScanFindings.findings{}.attributes{}.key +- responseElements.imageScanFindings.findings{}.attributes{}.value +- responseElements.imageScanFindings.findings{}.description +- responseElements.imageScanFindings.findings{}.name +- responseElements.imageScanFindings.findings{}.severity +- responseElements.imageScanFindings.findings{}.uri +- responseElements.imageScanFindings.imageScanCompletedAt +- responseElements.imageScanFindings.vulnerabilitySourceUpdatedAt +- responseElements.imageScanStatus.description +- responseElements.imageScanStatus.status +- responseElements.registryId +- responseElements.repositoryName +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region +example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": + "AAAAAAAAAAAAAAAAAAAAA:test@test.com", "arn": "arn:aws:sts::111111111111:assumed-role/role_name/test@test.com", + "accountId": "111111111111", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "sessionContext": + {"sessionIssuer": {"type": "Role", "principalId": "AKIAIOSFODNN7EXAMPLE", "arn": + "arn:aws:iam::111111111111:role/aws-reserved/test/region/group", "accountId": "111111111111", + "userName": "test"}, "webIdFederationData" : {}, "attributes": {"creationDate": + "2021-08-11T09:42:53Z", "mfaAuthenticated": "false"}}}, "eventTime": "2021-08-11T11:52:27Z", + "eventSource": "ecr.amazonaws.com", "eventName": "DescribeImageScanFindings", "awsRegion": + "eu-central-1" , "sourceIPAddress": "154.16.165.133", "userAgent": "aws-internal/3 + aws-sdk-java/1.11.1030 Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08 + java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy", "requestParameters": + {"repositoryName": "devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"}, + "maxResults": 1000}, "responseElements": {"registryId": "111111111111", "repositoryName": + "devsecops/cat_dog_client", "imageId": {"imageDigest" : "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"}, + "imageScanStatus": {"status": "COMPLETE", "description": "The scan was completed + successfully."}, "imageScanFindings": {"imageScanCompletedAt": "Aug 11, 2021, 11:30:16 + AM", "vulnerabilitySourceUpdatedAt": "Aug 11, 2021, 1:17:52 AM", "findings": [{"name": + "CVE-2019-25013", "description": "The iconv feature in the GNU C Library (aka glibc + or libc6) through 2.32, when processing invalid multi-byte input sequences in the + EUC-KR encoding, may have a buffer over-read.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-25013", + "severity": "HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"}, + {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"}, + {"key": "CVSS2_SCORE", "value": "7.1"}]}, {"name": "CVE-2021-33574", "description": + "The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 + has a use-after-free. It may use the notification thread attributes object (passed + through its struct sigevent parameter) after it has been freed by the caller, leading + to a denial of service (application crash) or possibly unspecified other impact.", + "uri": "https://security-tracker.debian.org/tracker/CVE-2021-33574", "severity": + "HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name", + "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-12886", "description": + "stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c + in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate + instruction sequences when targeting ARM targets that spill the address of the stack + protector guard, which allows an attacker to bypass the protection of -fstack-protector, + -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit + against stack overflow by controlling what the stack canary is compared against.", + "uri": "https://security-tracker.debian.org/tracker/CVE-2018-12886", "severity": + "MEDIUM", "attributes": [{"key": "package_version", "value": "8.3.0-6"}, {"key": + "package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-1751", "description": + "An out-of-bounds write vulnerability was found in glibc before 2.31 when handling + signal trampolines on PowerPC. Specifically, the backtrace function did not properly + check the array bounds when storing the frame address, resulting in a denial of + service or potential code execution. The highest threat from this vulnerability + is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1751", + "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"}, + {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:C"}, + {"key": "CVSS2_SCORE", "value": "5.9"}]}, {"name": "CVE-2021-3326", "description": + "The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, + when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an + assertion in the code path and aborts the program, potentially resulting in a denial + of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3326", + "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"}, + {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-35942", "description": + "The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or + read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, + crafted pattern, potentially resulting in a denial of service or disclosure of information. + This occurs because atoi was used but strtoul should have been used to ensure correct + calculations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-35942", + "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"}, + {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "6.4"}]}, {"name": "CVE-2019-12904", "description": + "In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload + side-channel attack because physical addresses are available to other processes. + (The C implementation is used on platforms where an assembly-language implementation + is unavailable.)", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12904", + "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"}, + {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value": + "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": + "CVE-2017-6363", "description": "** DISPUTED ** In the GD Graphics Library (aka + LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. + NOTE: the vendor says \"In my opinion this issue should not have a CVE, since the + GD and GD2 formats are documented to be ''obsolete, and should only be used for + development and testing purposes.''\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-6363", + "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"}, + {"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-12290", "description": + "GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 + Section 4.2 when converting A-labels to U-labels. This makes it possible in some + circumstances for one domain to impersonate another. By creating a malicious domain + that matches a target domain except for the inclusion of certain punycoded Unicode + characters (that would be discarded when converted first to a Unicode label and + then back to an ASCII label), arbitrary domains can be impersonated.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12290", + "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.0.5-1+deb10u1"}, + {"key": "package_name", "value": "libidn2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, + {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13115", "description": + "In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server. This is related to an _libssh2_check_length - mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-13115\", \"severity\"\ - : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.0-2.1\"\ - }, {\"key\": \"package_name\", \"value\": \"libssh2\"}, {\"key\": \"CVSS2_VECTOR\"\ - , \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ - : \"5.8\"}]}, {\"name\": \"CVE-2016-9318\", \"description\": \"libxml2 2.9.4 and - earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer - a flag directly indicating that the current document may be read but other files - may not be opened, which makes it easier for remote attackers to conduct XML External - Entity (XXE) attacks via a crafted document.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-9318\"\ - , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.9.4+dfsg1-7+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"libxml2\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-16932\", \"description\"\ - : \"parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter - entities.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16932\"\ - , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.9.4+dfsg1-7+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"libxml2\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2020-36309\", \"description\"\ - : \"ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows - unsafe characters in an argument when using the API to mutate a URI, or a request - or response header.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-36309\"\ - , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"}, {\"key\"\ - : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"5\"}]}, {\"name\": \"CVE-2020-14155\", \"description\": \"libpcre - in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-14155\", \"severity\"\ - : \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2:8.39-12\"\ - }, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"CVSS2_VECTOR\"\ - , \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ - : \"5\"}]}, {\"name\": \"CVE-2019-3843\", \"description\": \"It was discovered that - a systemd service that uses DynamicUser property can create a SUID/SGID binary that - would be allowed to run as the transient service UID/GID even after the service - is terminated. A local attacker may use this flaw to access resources that will - be owned by a potentially different service in the future, when the UID/GID will - be recycled.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-3843\"\ - , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\ - : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"4.6\"}]}, {\"name\": \"CVE-2019-3844\", \"description\": \"It was - discovered that a systemd service that uses DynamicUser property can get new privileges - through the execution of SUID binaries, which would allow to create binaries owned - by the service transient group with the setgid bit set. A local attacker may use - this flaw to access resources that will be owned by a potentially different service - in the future, when the GID will be recycled.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-3844\"\ - , \"severity\": \"MEDIUM\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\ - : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"4.6\"}]}, {\"name\": \"CVE-2016-2781\", \"description\": \"chroot - in GNU coreutils, when used with --userspec, allows local users to escape to the - parent session via a crafted TIOCSTI ioctl call, which pushes characters to the - terminal's input buffer.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-2781\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"8.30-3\"}, {\"key\": \"package_name\", \"value\": \"coreutils\"}, {\"key\": - \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-22898\", \"description\": \"curl - 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command - line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content - pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV - variables, libcurl could be made to pass on uninitialized data from a stack based - buffer to the server, resulting in potentially revealing sensitive internal information - to the server using a clear-text network protocol.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22898\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"}, {\"key\"\ - : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:H/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"2.6\"}]}, {\"name\": \"CVE-2019-15847\", \"description\": \"The POWER9 - backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple - calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy - of the random number generator. This occurred because a volatile operation was not - specified. For example, within a single execution of a program, the output of every - __builtin_darn() call may be the same.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-15847\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"8.3.0-6\"}, {\"key\": \"package_name\", \"value\": \"gcc-8\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"5\"}]}, {\"name\": \"CVE-2020-1752\", \"description\": \"A use-after-free - vulnerability introduced in glibc upstream version 2.14 was found in the way the - tilde expansion was carried out. Directory paths containing an initial tilde followed - by a valid username were affected by this issue. A local attacker could exploit - this flaw by creating a specially crafted path that, when processed by the glob - function, would potentially lead to arbitrary code execution. This was fixed in - version 2.32.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-1752\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"3.7\"}]}, {\"name\": \"CVE-2020-6096\", \"description\": \"An exploitable - signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU - glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) - with a negative value for the 'num' parameter results in a signed comparison vulnerability. - If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could - lead to undefined behavior such as writing to out-of-bounds memory and potentially - remote code execution. Furthermore, this memcpy() implementation allows for program - execution to continue in scenarios where a segmentation fault or crash should have - occurred. The dangers occur in that subsequent execution and iterations of this - code will be executed with this corrupted data.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-6096\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-10029\", \"description\": \"The GNU - C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during - range reduction if an input to an 80-bit long double function contains a non-canonical - bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. - This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-10029\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2020-27618\", \"description\": \"The iconv - function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing - invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 - encodings, fails to advance the input state, which could lead to an infinite loop - in applications, resulting in a denial of service, a different vulnerability from - CVE-2016-10228.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-27618\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2016-10228\", \"description\": \"The iconv - program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked - with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with - the -c option, enters an infinite loop when processing invalid multi-byte input - sequences, leading to a denial of service.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-10228\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2019-19126\", \"description\": \"On the - x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the - LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security - transition, allowing local attackers to restrict the possible mapping addresses - for loaded libraries and thus bypass ASLR for a setuid program.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-19126\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-27645\", \"description\": \"The nameserver - caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, - when processing a request for netgroup lookup, may crash due to a double-free, potentially - resulting in degraded service or Denial of Service on the local system. This is - related to netgroupcache.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-27645\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"1.9\"}]}, {\"name\": \"CVE-2019-14855\", \"description\": \"A flaw - was found in the way certificate signatures could be forged using collisions found - in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate - signatures. This issue affects GnuPG versions before 2.2.18.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-14855\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.2.12-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"gnupg2\"}, {\"\ - key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"\ - CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-13627\", \"description\"\ - : \"It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic + mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.", + "uri": "https://security-tracker.debian.org/tracker/CVE-2019-13115", "severity": + "MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"}, {"key": + "package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2016-9318", "description": + "libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, + does not offer a flag directly indicating that the current document may be read + but other files may not be opened, which makes it easier for remote attackers to + conduct XML External Entity (XXE) attacks via a crafted document.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9318", + "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"}, + {"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, + {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2017-16932", "description": + "parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter + entities.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16932", + "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"}, + {"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-36309", "description": + "ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe + characters in an argument when using the API to mutate a URI, or a request or response + header.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-36309", "severity": + "MEDIUM", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"}, + {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, + {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-14155", "description": + "libpcre in PCRE before 8.44 allows an integer overflow via a large number after + a (?C substring.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-14155", + "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2:8.39-12"}, + {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-3843", "description": + "It was discovered that a systemd service that uses DynamicUser property can create + a SUID/SGID binary that would be allowed to run as the transient service UID/GID + even after the service is terminated. A local attacker may use this flaw to access + resources that will be owned by a potentially different service in the future, when + the UID/GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3843", + "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"}, + {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2019-3844", "description": + "It was discovered that a systemd service that uses DynamicUser property can get + new privileges through the execution of SUID binaries, which would allow to create + binaries owned by the service transient group with the setgid bit set. A local attacker + may use this flaw to access resources that will be owned by a potentially different + service in the future, when the GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3844", + "severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"}, + {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2016-2781", "description": + "chroot in GNU coreutils, when used with --userspec, allows local users to escape + to the parent session via a crafted TIOCSTI ioctl call, which pushes characters + to the terminal''s input buffer.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-2781", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "8.30-3"}, + {"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR", "value": + "AV:L/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": + "CVE-2021-22898", "description": "curl 7.7 through 7.76.1 suffers from an information + disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in + libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw + in the option parser for sending NEW_ENV variables, libcurl could be made to pass + on uninitialized data from a stack based buffer to the server, resulting in potentially + revealing sensitive internal information to the server using a clear-text network + protocol.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22898", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"}, + {"key": "package_name", "value": "curl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:N/A:N"}, + {"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name": "CVE-2019-15847", "description": + "The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize + multiple calls of the __builtin_darn intrinsic into a single call, thus reducing + the entropy of the random number generator. This occurred because a volatile operation + was not specified. For example, within a single execution of a program, the output + of every __builtin_darn() call may be the same.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-15847", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "8.3.0-6"}, + {"key": "package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, + {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-1752", "description": + "A use-after-free vulnerability introduced in glibc upstream version 2.14 was found + in the way the tilde expansion was carried out. Directory paths containing an initial + tilde followed by a valid username were affected by this issue. A local attacker + could exploit this flaw by creating a specially crafted path that, when processed + by the glob function, would potentially lead to arbitrary code execution. This was + fixed in version 2.32.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1752", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, + {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:H/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "3.7"}]}, {"name": "CVE-2020-6096", "description": + "An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation + of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU + glibc implementation) with a negative value for the ''num'' parameter results in + a signed comparison vulnerability. If an attacker underflows the ''num'' parameter + to memcpy(), this vulnerability could lead to undefined behavior such as writing + to out-of-bounds memory and potentially remote code execution. Furthermore, this + memcpy() implementation allows for program execution to continue in scenarios where + a segmentation fault or crash should have occurred. The dangers occur in that subsequent + execution and iterations of this code will be executed with this corrupted data.", + "uri": "https://security-tracker.debian.org/tracker/CVE-2020-6096", "severity": + "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name", + "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-10029", "description": + "The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer + during range reduction if an input to an 80-bit long double function contains a + non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to + sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.", + "uri": "https://security-tracker.debian.org/tracker/CVE-2020-10029", "severity": + "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name", + "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2020-27618", "description": + "The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, + when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, + IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead + to an infinite loop in applications, resulting in a denial of service, a different + vulnerability from CVE-2016-10228.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-27618", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, + {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2016-10228", "description": + "The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when + invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) + along with the -c option, enters an infinite loop when processing invalid multi-byte + input sequences, leading to a denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-10228", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, + {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-19126", "description": + "On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to + ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution + after a security transition, allowing local attackers to restrict the possible mapping + addresses for loaded libraries and thus bypass ASLR for a setuid program.", "uri": + "https://security-tracker.debian.org/tracker/CVE-2019-19126", "severity": "LOW", + "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name", + "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:N/A:N"}, + {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-27645", "description": + "The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) + 2.29 through 2.33, when processing a request for netgroup lookup, may crash due + to a double-free, potentially resulting in degraded service or Denial of Service + on the local system. This is related to netgroupcache.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-27645", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, + {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2019-14855", "description": + "A flaw was found in the way certificate signatures could be forged using collisions + found in the SHA-1 algorithm. An attacker could use this weakness to create forged + certificate signatures. This issue affects GnuPG versions before 2.2.18.", "uri": + "https://security-tracker.debian.org/tracker/CVE-2019-14855", "severity": "LOW", + "attributes": [{"key": "package_version", "value": "2.2.12-1+deb10u1"}, {"key": + "package_name", "value": "gnupg2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, + {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13627", "description": + "It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions - fixed: 1.8.5-2 and 1.6.3-2+deb8u7.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-13627\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"1.8.4-5+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"}, - {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:P/I:P/A:N\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"2.6\"}]}, {\"name\": \"CVE-2018-14553\", \"description\"\ - : \"gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference - allowing attackers to crash an application via a specific function call sequence. - Only affects PHP when linked with an external libgd (not bundled).\", \"uri\": \"\ - https://security-tracker.debian.org/tracker/CVE-2018-14553\", \"severity\": \"LOW\"\ - , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"}, {\"\ - key\": \"package_name\", \"value\": \"libgd2\"}, {\"key\": \"CVSS2_VECTOR\", \"\ - value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\": - \"5\"}]}, {\"name\": \"CVE-2021-36086\", \"description\": \"The CIL compiler in - SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set - and cil_reset_classperms_list).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36086\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36085\", \"description\": \"The CIL - compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called - from __verify_map_perm_classperms and hashtab_map).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36085\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36087\", \"description\": \"The CIL - compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called - indirectly from cil_check_neverallow). This occurs because there is sometimes a - lack of checks for invalid statements in an optional block.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36087\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2021-36084\", \"description\": \"The CIL - compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called - from __cil_verify_classpermission and __cil_pre_verify_helper).\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36084\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.8-1\"}, {\"key\": \"package_name\", \"value\": \"libsepol\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2019-17498\", \"description\": \"In libssh2 - v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer - overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) - offset for a subsequent memory read. A crafted SSH server may be able to disclose - sensitive information or cause a denial of service condition on the client system - when a user connects to the server.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-17498\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"1.8.0-2.1\"}, {\"key\": \"package_name\", \"value\": \"libssh2\"}, {\"key\" - : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"5.8\"}]}, {\"name\": \"CVE-2019-17543\", \"description\": \"LZ4 before - 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), + fixed: 1.8.5-2 and 1.6.3-2+deb8u7.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-13627", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"}, + {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value": + "AV:L/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name": + "CVE-2018-14553", "description": "gdImageClone in gd.c in libgd 2.1.0-rc2 through + 2.2.5 has a NULL pointer dereference allowing attackers to crash an application + via a specific function call sequence. Only affects PHP when linked with an external + libgd (not bundled).", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14553", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"}, + {"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-36086", "description": + "The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission + (called from cil_reset_classperms_set and cil_reset_classperms_list).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36086", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"}, + {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36085", "description": + "The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms + (called from __verify_map_perm_classperms and hashtab_map).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36085", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"}, + {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36087", "description": + "The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any + (called indirectly from cil_check_neverallow). This occurs because there is sometimes + a lack of checks for invalid statements in an optional block.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36087", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"}, + {"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36084", "description": + "The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms + (called from __cil_verify_classpermission and __cil_pre_verify_helper).", "uri": + "https://security-tracker.debian.org/tracker/CVE-2021-36084", "severity": "LOW", + "attributes": [{"key": "package_version", "value": "2.8-1"}, {"key": "package_name", + "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2019-17498", "description": + "In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c + has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary + (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be + able to disclose sensitive information or cause a denial of service condition on + the client system when a user connects to the server.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17498", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"}, + {"key": "package_name", "value": "libssh2"}, {"key" : "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-17543", "description": + "LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue - can also lead to data corruption.) NOTE: the vendor states \\\"only a few specific - / uncommon usages of the API are at risk.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-17543\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"1.8.3-1+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"lz4\"}, {\"key\"\ - : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2013-0337\", \"description\": \"The default - configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions - for the (1) access.log and (2) error.log files, which allows local users to obtain - sensitive information by reading the files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-0337\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"}, {\"key\"\ - : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-7169\", \"description\": \"An issue - was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an - unprivileged user to be placed in a user namespace where setgroups(2) is permitted. - This allows an attacker to remove themselves from a supplementary group, which may - allow access to certain filesystem paths if the administrator has used \\\"group - blacklisting\\\" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively - reverts a security feature in the kernel (in particular, the /proc/self/setgroups - knob) to prevent this sort of privilege escalation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-7169\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\": - \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"5\"}]}, {\"name\": \"CVE-2021-37600\", \"description\": \"An integer - overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if - an attacker were able to use system resources in a way that leads to a large number - in the /proc/sysvipc/sem file.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-37600\"\ - , \"severity\": \"LOW\", \"attributes\": [{\"key\": \"package_version\", \"value\"\ - : \"2.33.1-0.1\"}, {\"key\": \"package_name\", \"value\": \"util-linux\"}, {\"key\"\ - : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"7.5\"}]}, {\"name\": \"CVE-2011-3374\", \"description\": \"It was - found that apt-key in apt, all versions, do not correctly validate gpg keys with - the master keyring, leading to a potential man-in-the-middle attack.\", \"uri\" - : \"https://security-tracker.debian.org/tracker/CVE-2011-3374\", \"severity\": \"\ - INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.8.2.3\"\ - }, {\"key\": \"package_name\", \"value\": \"apt\"}, {\"key\": \"CVSS2_VECTOR\", - \"value\": \"AV:N/AC:M/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ - : \"4.3\"}]}, {\"name\": \"CVE-2019-18276\", \"description\": \"An issue was discovered - in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if - Bash is run with its effective UID not equal to its real UID, it will drop privileges - by setting its effective UID to its real UID. However, it does so incorrectly. On - Linux and other systems that support \\\"saved UID\\\" functionality, the saved - UID is not dropped. An attacker with command execution in the shell can use \\\"\ - enable -f\\\" for runtime loading of a new builtin, which can be a shared object - that calls setuid() and therefore regains privileges. However, binaries running - with an effective UID of 0 are unaffected.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-18276\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"5.0-4\"}, {\"key\": \"package_name\", \"value\": \"bash\"}, {\"key\"\ - : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"7.2\"}]}, {\"name\": \"CVE-2017-18018\", \"description\": \"In GNU - Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement - of a plain file with a symlink during use of the POSIX \\\"-R -L\\\" options, which - allows local users to modify the ownership of arbitrary files by leveraging a race - condition.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-18018\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"8.30-3\"}, {\"key\": \"package_name\", \"value\": \"coreutils\"}, - {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:P/A:N\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"1.9\"}]}, {\"name\": \"CVE-2021-22923\", \"description\"\ - : \"When curl is instructed to get content using the metalink feature, and a user - name and password are used to download the metalink XML file, those same credentials - are then subsequently passed on to each of the servers from which curl will download - or try to download the contents from. Often contrary to the user's expectations - and intentions and without telling the user it happened.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22923\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"\ - }]}, {\"name\": \"CVE-2021-22922\", \"description\": \"When curl is instructed to - download content using the metalink feature, thecontents is verified against a hash - provided in the metalink XML file.The metalink XML file points out to the client - how to get the same contentfrom a set of different URLs, potentially hosted by different - servers and theclient can then download the file from one or several of them. In - a serial orparallel manner.If one of the servers hosting the contents has been breached - and the contentsof the specific file on that server is replaced with a modified - payload, curlshould detect this when the hash of the file mismatches after a completeddownload. - It should remove the contents and instead try getting the contentsfrom another URL. - This is not done, and instead such a hash mismatch is onlymentioned in text and - the potentially malicious content is kept in the file ondisk.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22922\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\"\ - }]}, {\"name\": \"CVE-2013-0340\", \"description\": \"expat 2.1.0 and earlier does - not properly handle entities expansion unless an application developer uses the - XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial - of service (resource consumption), send HTTP requests to intranet servers, or read - arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue.\ - \ NOTE: it could be argued that because expat already provides the ability to disable - external entity expansion, the responsibility for resolving this issue lies with - application developers; according to this argument, this entry should be REJECTed, - and each affected application would need its own CVE.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-0340\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2.2.6-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"expat\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-1010023\", \"description\"\ - : \"** DISPUTED ** GNU Libc current is affected by: Re-mapping current loaded library + can also lead to data corruption.) NOTE: the vendor states \"only a few specific + / uncommon usages of the API are at risk.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17543", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.3-1+deb10u1"}, + {"key": "package_name", "value": "lz4"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2013-0337", "description": + "The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable + permissions for the (1) access.log and (2) error.log files, which allows local users + to obtain sensitive information by reading the files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0337", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"}, + {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-7169", "description": + "An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and + allows an unprivileged user to be placed in a user namespace where setgroups(2) + is permitted. This allows an attacker to remove themselves from a supplementary + group, which may allow access to certain filesystem paths if the administrator has + used \"group blacklisting\" (e.g., chmod g-rwx) to restrict access to paths. This + flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups + knob) to prevent this sort of privilege escalation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-7169", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "1:4.5-1.1"}, + {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, + {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-37600", "description": + "An integer overflow in util-linux through 2.37.1 can potentially cause a buffer + overflow if an attacker were able to use system resources in a way that leads to + a large number in the /proc/sysvipc/sem file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-37600", + "severity": "LOW", "attributes": [{"key": "package_version", "value": "2.33.1-0.1"}, + {"key": "package_name", "value": "util-linux"}, {"key": "CVSS2_VECTOR", "value": + "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": + "CVE-2011-3374", "description": "It was found that apt-key in apt, all versions, + do not correctly validate gpg keys with the master keyring, leading to a potential + man-in-the-middle attack.", "uri" : "https://security-tracker.debian.org/tracker/CVE-2011-3374", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1.8.2.3"}, {"key": "package_name", "value": "apt"}, {"key": "CVSS2_VECTOR", "value": + "AV:N/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": + "CVE-2019-18276", "description": "An issue was discovered in disable_priv_mode in + shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective + UID not equal to its real UID, it will drop privileges by setting its effective + UID to its real UID. However, it does so incorrectly. On Linux and other systems + that support \"saved UID\" functionality, the saved UID is not dropped. An attacker + with command execution in the shell can use \"enable -f\" for runtime loading of + a new builtin, which can be a shared object that calls setuid() and therefore regains + privileges. However, binaries running with an effective UID of 0 are unaffected.", + "uri": "https://security-tracker.debian.org/tracker/CVE-2019-18276", "severity": + "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "5.0-4"}, {"key": + "package_name", "value": "bash"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:C/I:C/A:C"}, + {"key": "CVSS2_SCORE", "value": "7.2"}]}, {"name": "CVE-2017-18018", "description": + "In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent + replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options, + which allows local users to modify the ownership of arbitrary files by leveraging + a race condition.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-18018", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "8.30-3"}, {"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR", + "value": "AV:L/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "1.9"}]}, + {"name": "CVE-2021-22923", "description": "When curl is instructed to get content + using the metalink feature, and a user name and password are used to download the + metalink XML file, those same credentials are then subsequently passed on to each + of the servers from which curl will download or try to download the contents from. + Often contrary to the user''s expectations and intentions and without telling the + user it happened.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22923", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-22922", + "description": "When curl is instructed to download content using the metalink feature, + thecontents is verified against a hash provided in the metalink XML file.The metalink + XML file points out to the client how to get the same contentfrom a set of different + URLs, potentially hosted by different servers and theclient can then download the + file from one or several of them. In a serial orparallel manner.If one of the servers + hosting the contents has been breached and the contentsof the specific file on that + server is replaced with a modified payload, curlshould detect this when the hash + of the file mismatches after a completeddownload. It should remove the contents + and instead try getting the contentsfrom another URL. This is not done, and instead + such a hash mismatch is onlymentioned in text and the potentially malicious content + is kept in the file ondisk.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22922", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2013-0340", + "description": "expat 2.1.0 and earlier does not properly handle entities expansion + unless an application developer uses the XML_SetEntityDeclHandler function, which + allows remote attackers to cause a denial of service (resource consumption), send + HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, + aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat + already provides the ability to disable external entity expansion, the responsibility + for resolving this issue lies with application developers; according to this argument, + this entry should be REJECTed, and each affected application would need its own + CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0340", "severity": + "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.2.6-2+deb10u1"}, + {"key": "package_name", "value": "expat"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-1010023", "description": + "** DISPUTED ** GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim - and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \\\ - \"this is being treated as a non-security bug and no real threat.\\\"\", \"uri\"\ - : \"https://security-tracker.debian.org/tracker/CVE-2019-1010023\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ - , \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ - : \"6.8\"}]}, {\"name\": \"CVE-2010-4051\", \"description\": \"The regcomp implementation - in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, - allows context-dependent attackers to cause a denial of service (application crash) - via a regular expression containing adjacent bounded repetitions that bypass the - intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence - in the proftpd.gnu.c exploit for ProFTPD, related to a \\\"RE_DUP_MAX overflow.\\\ - \"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4051\", \"\ - severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"\ - value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\"\ - : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"5\"}]}, {\"name\": \"CVE-2019-1010022\", \"description\": \"** DISPUTED - ** GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may - bypass stack guard protection. The component is: nptl. The attack vector is: Exploit - stack buffer overflow vulnerability and use this bypass vulnerability to bypass - stack guard. NOTE: Upstream comments indicate \\\"this is being treated as a non-security - bug and no real threat.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-1010022\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\ - key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\": \"\ - CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2010-4052\", \"description\"\ - : \"Stack consumption vulnerability in the regcomp implementation in the GNU C Library + and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this + is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010023", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": + "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": + "CVE-2010-4051", "description": "The regcomp implementation in the GNU C Library + (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent + attackers to cause a denial of service (application crash) via a regular expression + containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, + as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit + for ProFTPD, related to a \"RE_DUP_MAX overflow.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4051", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": + "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": + "CVE-2019-1010022", "description": "** DISPUTED ** GNU Libc current is affected + by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. + The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability + and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments + indicate \"this is being treated as a non-security bug and no real threat.\"", "uri": + "https://security-tracker.debian.org/tracker/CVE-2019-1010022", "severity": "INFORMATIONAL", + "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name", + "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2010-4052", "description": + "Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} - sequence in the proftpd.gnu.c exploit for ProFTPD.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4052\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\ - key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\ - CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-1010024\", \"description\"\ - : \"** DISPUTED ** GNU Libc current is affected by: Mitigation bypass. The impact - is: Attacker may bypass ASLR using cache of thread stack and heap. The component - is: glibc. NOTE: Upstream comments indicate \\\"this is being treated as a non-security - bug and no real threat.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-1010024\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\ - key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"\ - CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2010-4756\", \"description\"\ - : \"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote - authenticated users to cause a denial of service (CPU and memory consumption) via - crafted glob expressions that do not match any pathnames, as demonstrated by glob - expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-4756\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ - , \"value\": \"AV:N/AC:L/Au:S/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ - : \"4\"}]}, {\"name\": \"CVE-2019-1010025\", \"description\": \"** DISPUTED ** GNU - Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess - the heap addresses of pthread_created thread. The component is: glibc. NOTE: the - vendor's position is \\\"ASLR bypass itself is not a vulnerability.\\\"\", \"uri\"\ - : \"https://security-tracker.debian.org/tracker/CVE-2019-1010025\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"key\": \"CVSS2_VECTOR\"\ - , \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ - : \"5\"}]}, {\"name\": \"CVE-2018-20796\", \"description\": \"In the GNU C Library - (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c - has Uncontrolled Recursion, as demonstrated by '(\\\\227|)(\\\\\\\\1\\\\\\\\1|t1|\\\ - \\\\\\\\\\2537)+' in grep.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-20796\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\ - key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\ - CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2019-9192\", \"description\"\ - : \"** DISPUTED ** In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 - in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\\\\\\ - 1\\\\\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software - maintainer disputes that this is a vulnerability because the behavior occurs only - with a crafted pattern.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9192\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2.28-10\"}, {\"key\": \"package_name\", \"value\": \"glibc\"}, {\"\ - key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"\ - CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2011-3389\", \"description\"\ - : \"The SSL protocol, as used in certain configurations in Microsoft Windows and - Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, - encrypts data by using CBC mode with chained initialization vectors, which allows - man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary - attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses - (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight - WebClient API, aka a \\\"BEAST\\\" attack.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2011-3389\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"3.6.7-4+deb10u7\"}, {\"key\": \"package_name\", \"value\": \"gnutls28\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:N/A:N\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2021-30535\", \"description\"\ - : \"Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker - to potentially exploit heap corruption via a crafted HTML page.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-30535\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"63.1-6+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"icu\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2017-9937\", \"description\"\ - : \"In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted - TIFF document can lead to an abort resulting in a remote denial of service attack.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-9937\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"2.1-3.1\"}, {\"key\": \"package_name\", \"value\": \"jbigkit\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-5709\", \"description\": \"An issue - was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \\\ - \"dbentry->n_key_data\\\" in kadmin/dbutil/dump.c that can store 16-bit data but - unknowingly the developer has assigned a \\\"u4\\\" variable to it, which is for - 32-bit data. An attacker can use this vulnerability to affect other artifacts of - the database as we know that a Kerberos database dump file contains trusted data.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-5709\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"}, {\"key\" - : \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"5\"}]}, {\"name\": \"CVE-2021-36222\", \"description\": \"ec_verify - in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka - krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a - NULL pointer dereference and daemon crash. This occurs because a return value is - not properly managed in a certain situation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-36222\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2004-0971\", \"description\"\ - : \"The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux - 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite - files via a symlink attack on temporary files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2004-0971\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"1.17-3+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"krb5\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2018-6829\", \"description\"\ - : \"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, + sequence in the proftpd.gnu.c exploit for ProFTPD.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4052", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": + "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": + "CVE-2019-1010024", "description": "** DISPUTED ** GNU Libc current is affected + by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread + stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this + is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010024", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": + "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": + "CVE-2010-4756", "description": "The glob implementation in the GNU C Library (aka + glibc or libc6) allows remote authenticated users to cause a denial of service (CPU + and memory consumption) via crafted glob expressions that do not match any pathnames, + as demonstrated by glob expressions in STAT commands to an FTP daemon, a different + vulnerability than CVE-2010-2632.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4756", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": + "AV:N/AC:L/Au:S/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4"}]}, {"name": + "CVE-2019-1010025", "description": "** DISPUTED ** GNU Libc current is affected + by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created + thread. The component is: glibc. NOTE: the vendor''s position is \"ASLR bypass itself + is not a vulnerability.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010025", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": + "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": + "CVE-2018-20796", "description": "In the GNU C Library (aka glibc or libc6) through + 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, + as demonstrated by ''(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+'' in grep.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-20796", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": + "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": + "CVE-2019-9192", "description": "** DISPUTED ** In the GNU C Library (aka glibc + or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled + Recursion, as demonstrated by ''(|)(\\\\1\\\\1)*'' in grep, a different issue than + CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability + because the behavior occurs only with a crafted pattern.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9192", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": + "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": + "CVE-2011-3389", "description": "The SSL protocol, as used in certain configurations + in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, + Opera, and other products, encrypts data by using CBC mode with chained initialization + vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers + via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction + with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection + API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3389", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "3.6.7-4+deb10u7"}, {"key": "package_name", "value": "gnutls28"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, + {"name": "CVE-2021-30535", "description": "Double free in ICU in Google Chrome prior + to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption + via a crafted HTML page.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-30535", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "63.1-6+deb10u1"}, {"key": "package_name", "value": "icu"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, + {"name": "CVE-2017-9937", "description": "In LibTIFF 4.0.8, there is a memory malloc + failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in + a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-9937", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.1-3.1"}, {"key": "package_name", "value": "jbigkit"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, + {"name": "CVE-2018-5709", "description": "An issue was discovered in MIT Kerberos + 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c + that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable + to it, which is for 32-bit data. An attacker can use this vulnerability to affect + other artifacts of the database as we know that a Kerberos database dump file contains + trusted data.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-5709", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key" : "CVSS2_VECTOR", + "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, + {"name": "CVE-2021-36222", "description": "ec_verify in kdc/kdc_preauth_ec.c in + the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and + 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference + and daemon crash. This occurs because a return value is not properly managed in + a certain situation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36222", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, + {"name": "CVE-2004-0971", "description": "The krb5-send-pr script in the kerberos5 + (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating + systems, allows local users to overwrite files via a symlink attack on temporary + files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2004-0971", "severity": + "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.17-3+deb10u1"}, + {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:P/A:N"}, + {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2018-6829", "description": + "cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not - hold for Libgcrypt's ElGamal implementation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-6829\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"1.8.4-5+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libgcrypt20\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2018-11813\", \"description\"\ - : \"libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-11813\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2020-17541\", \"description\"\ - : \"Libjpeg-turbo all version have a stack-based buffer overflow in the \\\"transform\\\ - \" component. A remote attacker can send a malformed jpeg file to the service and - cause arbitrary code execution or denial of service of the target service.\", \"\ - uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-17541\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2017-15232\", \"description\"\ - : \"libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c - via a crafted JPEG file.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-15232\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"1:1.5.2-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libjpeg-turbo\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-14048\", \"description\"\ - : \"An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data - in png.c, related to the recommended error handling for png_read_image.\", \"uri\"\ - : \"https://security-tracker.debian.org/tracker/CVE-2018-14048\", \"severity\": - \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"\ - 1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2019-6129\", \"description\": \"** DISPUTED - ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated - by pngcp. NOTE: a third party has stated \\\"I don't think it is libpng's job to - free this buffer.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-6129\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2018-14550\", \"description\"\ - : \"An issue has been found in third-party PNM decoding associated with libpng 1.6.35. - It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-14550\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"1.6.36-6\"}, {\"key\": \"package_name\", \"value\": \"libpng1.6\"}, {\"key\": - \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-9893\", \"description\": \"libseccomp - before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using - the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing - seccomp filters and potential privilege escalations.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9893\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2.3.3-4\"}, {\"key\": \"package_name\", \"value\": \"libseccomp\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2018-1000654\", \"description\"\ - : \"GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains - a DoS, specifically CPU usage will reach 100% when running asn1Paser against the - POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program - will be killed. This attack appears to be exploitable via parsing a crafted file.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-1000654\", \"\ - severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"\ - value\": \"4.13-3\"}, {\"key\": \"package_name\", \"value\": \"libtasn1-6\"}, {\"\ - key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:C\"}, {\"key\": \"\ - CVSS2_SCORE\", \"value\": \"7.1\"}]}, {\"name\": \"CVE-2016-9085\", \"description\"\ - : \"Multiple integer overflows in libwebp allows attackers to have unspecified impact - via unknown vectors.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2016-9085\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"0.6.1-2+deb10u1\"}, {\"key\": \"package_name\", \"value\": \"libwebp\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2015-9019\", \"description\"\ - : \"In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized - with a random seed during startup, which could cause usage of this function to produce - predictable outputs.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2015-9019\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"1.1.32-2.2~deb10u1\"}, {\"key\": \"package_name\", \"value\": \"\ - libxslt\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:N/A:N\"\ - }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2009-4487\" - , \"description\": \"nginx 0.7.64 writes data to a log file without sanitizing non-printable - characters, which might allow remote attackers to modify a window's title, or possibly - execute arbitrary commands or overwrite files, via an HTTP request containing an - escape sequence for a terminal emulator.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2009-4487\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"1.21.1-1~buster\"}, {\"key\": \"package_name\", \"value\": \"nginx\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-15719\", \"description\"\ - : \"libldap in certain third-party OpenLDAP packages has a certificate-validation - flaw when the third-party package is asserting RFC6125 support. It considers CN - even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, - openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-15719\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\": - \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:H/Au:N/C:P/I:P/A:N\"\ - }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4\"}]}, {\"name\": \"CVE-2015-3276\" - , \"description\": \"The nss_parse_ciphers function in libraries/libldap/tls_m.c - in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, - which might cause a weaker than intended cipher to be used and allow remote attackers - to have unspecified impact via unknown vectors.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2015-3276\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\": - \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"\ - }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2017-14159\"\ - , \"description\": \"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after - dropping privileges to a non-root account, which might allow local users to kill - arbitrary processes by leveraging access to this non-root account for PID file modification - before a root script executes a \\\"kill `cat /pathname`\\\" command, as demonstrated - by openldap-initscript.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-14159\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\": - \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:N/A:P\"\ - }, {\"key\": \"CVSS2_SCORE\", \"value\": \"1.9\"}]}, {\"name\": \"CVE-2017-17740\"\ - , \"description\": \"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, - when both the nops module and the memberof overlay are enabled, attempts to free - a buffer that was allocated on the stack, which allows remote attackers to cause - a denial of service (slapd crash) via a member MODDN operation.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-17740\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2.4.47+dfsg-3+deb10u6\"}, {\"key\": \"package_name\", \"value\": - \"openldap\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"\ - }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2010-0928\" - , \"description\": \"OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx - Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain - signature calculations, and does not verify the signature before providing it to - a caller, which makes it easier for physically proximate attackers to determine - the private key via a modified supply voltage for the microprocessor, related to - a \\\"fault-based attack.\\\"\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2010-0928\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"1.1.1d-0+deb10u6\"}, {\"key\": \"package_name\", \"value\": \"openssl\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:C/I:N/A:N\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"4\"}]}, {\"name\": \"CVE-2007-6755\", \"description\"\ - : \"The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic - Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a - possible relationship to certain \\\"skeleton key\\\" values, which might allow - context-dependent attackers to defeat cryptographic protection mechanisms by leveraging - knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future - research may provide additional details about point Q and associated attacks, and - could potentially lead to a RECAST or REJECT of this CVE.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2007-6755\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"1.1.1d-0+deb10u6\"}, {\"key\": \"package_name\", \"value\": \"openssl\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:N\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"5.8\"}]}, {\"name\": \"CVE-2017-7246\", \"description\"\ - : \"Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c + hold for Libgcrypt''s ElGamal implementation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-6829", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1.8.4-5+deb10u1"}, {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, + {"name": "CVE-2018-11813", "description": "libjpeg 9c has a large loop because read_pixel + in rdtarga.c mishandles EOF.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-11813", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key": + "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": + "5"}]}, {"name": "CVE-2020-17541", "description": "Libjpeg-turbo all version have + a stack-based buffer overflow in the \"transform\" component. A remote attacker + can send a malformed jpeg file to the service and cause arbitrary code execution + or denial of service of the target service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-17541", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key": + "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": + "6.8"}]}, {"name": "CVE-2017-15232", "description": "libjpeg-turbo 1.5.2 has a NULL + Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.", "uri": + "https://security-tracker.debian.org/tracker/CVE-2017-15232", "severity": "INFORMATIONAL", + "attributes": [{"key": "package_version", "value": "1:1.5.2-2+deb10u1"}, {"key": + "package_name", "value": "libjpeg-turbo"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2018-14048", "description": + "An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data + in png.c, related to the recommended error handling for png_read_image.", "uri": + "https://security-tracker.debian.org/tracker/CVE-2018-14048", "severity": "INFORMATIONAL", + "attributes": [{"key": "package_version", "value": "1.6.36-6"}, {"key": "package_name", + "value": "libpng1.6"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-6129", "description": + "** DISPUTED ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, + as demonstrated by pngcp. NOTE: a third party has stated \"I don''t think it is + libpng''s job to free this buffer.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-6129", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, + {"name": "CVE-2018-14550", "description": "An issue has been found in third-party + PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow + in the function get_token in pnm2png.c in pnm2png.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14550", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, + {"name": "CVE-2019-9893", "description": "libseccomp before 2.4.0 did not correctly + generate 64-bit syscall argument comparisons using the arithmetic operators (LT, + GT, LE, GE), which might able to lead to bypassing seccomp filters and potential + privilege escalations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9893", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.3.3-4"}, {"key": "package_name", "value": "libseccomp"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]}, + {"name": "CVE-2018-1000654", "description": "GNU Libtasn1-4.13 libtasn1-4.13 version + libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% + when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), + after a long time, the program will be killed. This attack appears to be exploitable + via parsing a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-1000654", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "4.13-3"}, {"key": "package_name", "value": "libtasn1-6"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.1"}]}, + {"name": "CVE-2016-9085", "description": "Multiple integer overflows in libwebp + allows attackers to have unspecified impact via unknown vectors.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9085", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "0.6.1-2+deb10u1"}, {"key": "package_name", "value": "libwebp"}, {"key": "CVSS2_VECTOR", + "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, + {"name": "CVE-2015-9019", "description": "In libxslt 1.1.29 and earlier, the EXSLT + math.random function was not initialized with a random seed during startup, which + could cause usage of this function to produce predictable outputs.", "uri": "https://security-tracker.debian.org/tracker/CVE-2015-9019", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1.1.32-2.2~deb10u1"}, {"key": "package_name", "value": "libxslt"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, + {"name": "CVE-2009-4487" , "description": "nginx 0.7.64 writes data to a log file + without sanitizing non-printable characters, which might allow remote attackers + to modify a window''s title, or possibly execute arbitrary commands or overwrite + files, via an HTTP request containing an escape sequence for a terminal emulator.", + "uri": "https://security-tracker.debian.org/tracker/CVE-2009-4487", "severity": + "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"}, + {"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-15719", "description": + "libldap in certain third-party OpenLDAP packages has a certificate-validation flaw + when the third-party package is asserting RFC6125 support. It considers CN even + when there is a non-matching subjectAltName (SAN). This is fixed in, for example, + openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-15719", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key": + "CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": + "4"}]}, {"name": "CVE-2015-3276" , "description": "The nss_parse_ciphers function + in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword + mode cipher strings, which might cause a weaker than intended cipher to be used + and allow remote attackers to have unspecified impact via unknown vectors.", "uri": + "https://security-tracker.debian.org/tracker/CVE-2015-3276", "severity": "INFORMATIONAL", + "attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"}, {"key": + "package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, + {"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2017-14159", "description": + "slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges + to a non-root account, which might allow local users to kill arbitrary processes + by leveraging access to this non-root account for PID file modification before a + root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.", + "uri": "https://security-tracker.debian.org/tracker/CVE-2017-14159", "severity": + "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"}, + {"key": "package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2017-17740", "description": + "contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops + module and the memberof overlay are enabled, attempts to free a buffer that was + allocated on the stack, which allows remote attackers to cause a denial of service + (slapd crash) via a member MODDN operation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17740", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key": + "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": + "5"}]}, {"name": "CVE-2010-0928" , "description": "OpenSSL 0.9.8i on the Gaisler + Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation + (FWE) algorithm for certain signature calculations, and does not verify the signature + before providing it to a caller, which makes it easier for physically proximate + attackers to determine the private key via a modified supply voltage for the microprocessor, + related to a \"fault-based attack.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-0928", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1.1.1d-0+deb10u6"}, {"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR", + "value": "AV:L/AC:H/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4"}]}, + {"name": "CVE-2007-6755", "description": "The NIST SP 800-90A default statement + of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm + contains point Q constants with a possible relationship to certain \"skeleton key\" + values, which might allow context-dependent attackers to defeat cryptographic protection + mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary + CVE for Dual_EC_DRBG; future research may provide additional details about point + Q and associated attacks, and could potentially lead to a RECAST or REJECT of this + CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-6755", "severity": + "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.1.1d-0+deb10u6"}, + {"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:N"}, + {"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2017-7246", "description": + "Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE - of size 268) or possibly have unspecified other impact via a crafted file.\", \"\ - uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-7246\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"6.8\"}]}, {\"name\": \"CVE-2019-20838\", \"description\": \"libpcre - in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, - and \\\\X or \\\\R has more than one fixed quantifier, a related issue to CVE-2019-20454.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-20838\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-7245\", \"description\": \"Stack-based - buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 - in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size - 4) or possibly have unspecified other impact via a crafted file.\", \"uri\": \"\ - https://security-tracker.debian.org/tracker/CVE-2017-7245\", \"severity\": \"INFORMATIONAL\"\ - , \"attributes\": [{\"key\": \"package_version\", \"value\": \"2:8.39-12\"}, {\"\ - key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"CVSS2_VECTOR\", \"value\"\ - : \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\": \"CVSS2_SCORE\", \"value\": \"6.8\"\ - }]}, {\"name\": \"CVE-2017-16231\", \"description\": \"** DISPUTED ** In PCRE 8.41, - after compiling, a pcretest load test PoC produces a crash overflow in the function - match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute - the relevance of this report, noting that there are options that can be used to - limit the amount of stack that is used.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16231\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, - {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"2.1\"}]}, {\"name\": \"CVE-2017-11164\", \"description\"\ - : \"In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows - stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-11164\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"2:8.39-12\"}, {\"key\": \"package_name\", \"value\": \"pcre3\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:C\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"7.8\"}]}, {\"name\": \"CVE-2011-4116\", \"description\": \"_is_safe - in the File::Temp module for Perl does not properly handle symlinks.\", \"uri\" - : \"https://security-tracker.debian.org/tracker/CVE-2011-4116\", \"severity\": \"\ - INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"5.28.1-6+deb10u1\"\ - }, {\"key\": \"package_name\", \"value\": \"perl\"}, {\"key\": \"CVSS2_VECTOR\" - , \"value\": \"AV:N/AC:L/Au:N/C:N/I:P/A:N\"}, {\"key\": \"CVSS2_SCORE\", \"value\"\ - : \"5\"}]}, {\"name\": \"CVE-2019-19882\", \"description\": \"shadow 4.8, in certain - circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local - users to obtain root access because setuid programs are misconfigured. Specifically, - this affects shadow 4.8 when compiled using --with-libpam but without explicitly - passing --disable-account-tools-setuid, and without a PAM configuration suitable - for use with setuid account management tools. This combination leads to account - management tools (groupadd, groupdel, groupmod, useradd, userdel, usermod) that - can easily be used by unprivileged local users to escalate privileges to root in - multiple ways. This issue became much more relevant in approximately December 2019 - when an unrelated bug was fixed (i.e., the chmod calls to suidusbins were fixed - in the upstream Makefile which is now included in the release version 4.8).\", \"\ - uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-19882\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"6.9\"}]}, {\"name\": \"CVE-2007-5686\", \"description\": \"initscripts - in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows - local users to obtain sensitive information regarding authentication attempts. \ - \ NOTE: because sshd detects the insecure permissions and does not log certain events, - this also prevents sshd from logging failed authentication attempts by remote attackers.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2007-5686\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:C/I:N/A:N\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"4.9\"}]}, {\"name\": \"CVE-2013-4235\", \"description\": \"shadow: - TOCTOU (time-of-check time-of-use) race condition when copying and removing directory - trees\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-4235\" - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"1:4.5-1.1\"}, {\"key\": \"package_name\", \"value\": \"shadow\"}, - {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:N/I:P/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"3.3\"}]}, {\"name\": \"CVE-2020-13529\", \"description\"\ - : \"An exploitable denial-of-service vulnerability exists in Systemd 245. A specially - crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be - vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW - and DCHP ACK packets to reconfigure the server.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-13529\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:A/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"2.9\"}]}, {\"name\": \"CVE-2013-4392\", \"description\"\ - : \"systemd, when updating file permissions, allows local users to change the permissions + of size 268) or possibly have unspecified other impact via a crafted file.", "uri": + "https://security-tracker.debian.org/tracker/CVE-2017-7246", "severity": "INFORMATIONAL", + "attributes": [{"key": "package_version", "value": "2:8.39-12"}, {"key": "package_name", + "value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-20838", "description": + "libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is + disabled, and \\X or \\R has more than one fixed quantifier, a related issue to + CVE-2019-20454.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20838", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, + {"name": "CVE-2017-7245", "description": "Stack-based buffer overflow in the pcre32_copy_substring + function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause + a denial of service (WRITE of size 4) or possibly have unspecified other impact + via a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-7245", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, + {"name": "CVE-2017-16231", "description": "** DISPUTED ** In PCRE 8.41, after compiling, + a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c + because of a self-recursive call. NOTE: third parties dispute the relevance of this + report, noting that there are options that can be used to limit the amount of stack + that is used.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16231", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", + "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, + {"name": "CVE-2017-11164", "description": "In PCRE 8.41, the OP_KETRMAX feature + in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) + when processing a crafted regular expression.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-11164", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:L/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.8"}]}, + {"name": "CVE-2011-4116", "description": "_is_safe in the File::Temp module for + Perl does not properly handle symlinks.", "uri" : "https://security-tracker.debian.org/tracker/CVE-2011-4116", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "5.28.1-6+deb10u1"}, {"key": "package_name", "value": "perl"}, {"key": "CVSS2_VECTOR" + , "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, + {"name": "CVE-2019-19882", "description": "shadow 4.8, in certain circumstances + affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain + root access because setuid programs are misconfigured. Specifically, this affects + shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid, + and without a PAM configuration suitable for use with setuid account management + tools. This combination leads to account management tools (groupadd, groupdel, groupmod, + useradd, userdel, usermod) that can easily be used by unprivileged local users to + escalate privileges to root in multiple ways. This issue became much more relevant + in approximately December 2019 when an unrelated bug was fixed (i.e., the chmod + calls to suidusbins were fixed in the upstream Makefile which is now included in + the release version 4.8).", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-19882", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", + "value": "AV:L/AC:M/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.9"}]}, + {"name": "CVE-2007-5686", "description": "initscripts in rPath Linux 1 sets insecure + permissions for the /var/log/btmp file, which allows local users to obtain sensitive + information regarding authentication attempts. NOTE: because sshd detects the insecure + permissions and does not log certain events, this also prevents sshd from logging + failed authentication attempts by remote attackers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-5686", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", + "value": "AV:L/AC:L/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.9"}]}, + {"name": "CVE-2013-4235", "description": "shadow: TOCTOU (time-of-check time-of-use) + race condition when copying and removing directory trees", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4235" + , "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", + "value": "AV:L/AC:M/Au:N/C:N/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "3.3"}]}, + {"name": "CVE-2020-13529", "description": "An exploitable denial-of-service vulnerability + exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server + running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker + can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.", + "uri": "https://security-tracker.debian.org/tracker/CVE-2020-13529", "severity": + "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"}, + {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:A/AC:M/Au:N/C:N/I:N/A:P"}, + {"key": "CVSS2_SCORE", "value": "2.9"}]}, {"name": "CVE-2013-4392", "description": + "systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified - files.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2013-4392\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:M/Au:N/C:P/I:P/A:N\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"3.3\"}]}, {\"name\": \"CVE-2020-13776\", \"description\"\ - : \"systemd through v245 mishandles numerical usernames such as ones composed of - decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges - when privileges of the 0x0 user account were intended. NOTE: this issue exists because - of an incomplete fix for CVE-2017-1000082.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-13776\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"\ - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:H/Au:N/C:C/I:C/A:C\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"6.2\"}]}, {\"name\": \"CVE-2019-20386\", \"description\"\ - : \"An issue was discovered in button_open in login/logind-button.c in systemd before - 243. When executing the udevadm trigger command, a memory leak may occur.\", \"\ - uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-20386\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"241-7~deb10u8\"}, {\"key\": \"package_name\", \"value\": \"systemd\"}, {\"key\"\ - : \"CVSS2_VECTOR\", \"value\": \"AV:L/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"2.1\"}]}, {\"name\": \"CVE-2019-9923\", \"description\": \"pax_decode_header - in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain - archives that have malformed extended headers.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2019-9923\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"}, - {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2005-2541\", \"description\"\ - : \"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid - files, which may allow local users or remote attackers to gain privileges.\", \"\ - uri\": \"https://security-tracker.debian.org/tracker/CVE-2005-2541\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:C/I:C/A:C\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"10\"}]}, {\"name\": \"CVE-2021-20193\", \"description\": \"A flaw - was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker - who can submit a crafted input file to tar to cause uncontrolled consumption of - memory. The highest threat from this vulnerability is to system availability.\" - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-20193\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"1.30+dfsg-6\"}, {\"key\": \"package_name\", \"value\": \"tar\"}, {\"key\": \"\ - CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\": \"CVSS2_SCORE\"\ - , \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-17973\", \"description\": \"** DISPUTED - ** In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function - in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this - issue.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-17973\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\ - : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"\ - }, {\"key\": \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-35521\"\ - , \"description\": \"A flaw was found in libtiff. Due to a memory allocation failure - in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of - service.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-35521\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\ - : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"\ - }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2014-8130\"\ - , \"description\": \"The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does - not reject a zero size, which allows remote attackers to cause a denial of service - (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled - by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2014-8130\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\" - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-5563\", \"description\"\ - : \"LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c - resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.\" - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-5563\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\" - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:P/I:P/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"6.8\"}]}, {\"name\": \"CVE-2020-35522\", \"description\"\ - : \"In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF - document can lead to an abort, resulting in a remote denial of service attack.\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2020-35522\", \"severity\"\ - : \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\", \"value\": - \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\": \"tiff\" - }, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"}, {\"key\"\ - : \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2017-9117\", \"description\"\ - : \"In LibTIFF 4.0.7, the program processes BMP images without verifying that biWidth - and biHeight in the bitmap-information header match the actual input, leading to - a heap-based buffer over-read in bmp2tiff.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-9117\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\ - : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:P/I:P/A:P\"\ - }, {\"key\": \"CVSS2_SCORE\", \"value\": \"7.5\"}]}, {\"name\": \"CVE-2017-16232\"\ - , \"description\": \"** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, - which allow attackers to cause a denial of service (memory consumption), as demonstrated - by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce - the issue.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2017-16232\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\ - : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:L/Au:N/C:N/I:N/A:P\"\ - }, {\"key\": \"CVSS2_SCORE\", \"value\": \"5\"}]}, {\"name\": \"CVE-2018-10126\"\ - , \"description\": \"LibTIFF 4.0.9 has a NULL pointer dereference in the jpeg_fdct_16x16 - function in jfdctint.c.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2018-10126\"\ - , \"severity\": \"INFORMATIONAL\", \"attributes\": [{\"key\": \"package_version\"\ - , \"value\": \"4.1.0+git191117-2~deb10u2\"}, {\"key\": \"package_name\", \"value\"\ - : \"tiff\"}, {\"key\": \"CVSS2_VECTOR\", \"value\": \"AV:N/AC:M/Au:N/C:N/I:N/A:P\"\ - }, {\"key\": \"CVSS2_SCORE\", \"value\": \"4.3\"}]}, {\"name\": \"CVE-2021-22924\"\ - , \"description\": \"libcurl keeps previously used connections in a connection pool - for subsequenttransfers to reuse, if one of them matches the setup.Due to errors - in the logic, the config matching function did not take 'issuercert' into account - and it compared the involved paths *case insensitively*,which could lead to libcurl - reusing wrong connections.File paths are, or can be, case sensitive on many systems - but not all, and caneven vary depending on used file systems.The comparison also - didn't include the 'issuer cert' which a transfer can setto qualify how to verify - the server certificate.\", \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-22924\"\ - , \"severity\": \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"\ - value\": \"7.64.0-4+deb10u2\"}, {\"key\": \"package_name\", \"value\": \"curl\" - }]}, {\"name\": \"CVE-2021-38115\", \"description\": \"read_header_tga in gd_tga.c - in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to - cause a denial of service (out-of-bounds read) via a crafted TGA file.\", \"uri\"\ - : \"https://security-tracker.debian.org/tracker/CVE-2021-38115\", \"severity\": - \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"2.2.5-5.2\"\ - }, {\"key\": \"package_name\", \"value\": \"libgd2\"}]}, {\"name\": \"CVE-2021-3618\"\ - , \"uri\": \"https://security-tracker.debian.org/tracker/CVE-2021-3618\", \"severity\"\ - : \"UNDEFINED\", \"attributes\": [{\"key\": \"package_version\", \"value\": \"1.21.1-1~buster\"\ - }, {\"key\": \"package_name\", \"value\": \"nginx\"}]}], \"findingSeverityCounts\"\ - : {\"HIGH\": 2, \"MEDIUM\": 14, \"INFORMATIONAL\": 63, \"LOW\": 22, \"UNDEFINED\"\ - : 3}}}, \"requestID\": \"23c19e2d-c48b-4265-b4eb-853e7b325780\", \"eventID\": \"\ - 6c94a9b2-36dc-43f8-a6dd-4ec839ded8af\", \"readOnly\": true, \"eventType\": \"AwsApiCall\"\ - , \"managementEvent\": true, \"recipientAccountId\": \"111111111111\", \"eventCategory\"\ - : \"Management\"}" + files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4392", "severity": + "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"}, + {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:N"}, + {"key": "CVSS2_SCORE", "value": "3.3"}]}, {"name": "CVE-2020-13776", "description": + "systemd through v245 mishandles numerical usernames such as ones composed of decimal + digits or 0x followed by hex digits, as demonstrated by use of root privileges when + privileges of the 0x0 user account were intended. NOTE: this issue exists because + of an incomplete fix for CVE-2017-1000082.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-13776", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", + "value": "AV:L/AC:H/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.2"}]}, + {"name": "CVE-2019-20386", "description": "An issue was discovered in button_open + in login/logind-button.c in systemd before 243. When executing the udevadm trigger + command, a memory leak may occur.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20386", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", + "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, + {"name": "CVE-2019-9923", "description": "pax_decode_header in sparse.c in GNU Tar + before 1.32 had a NULL pointer dereference when parsing certain archives that have + malformed extended headers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9923", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, + {"name": "CVE-2005-2541", "description": "Tar 1.15.1 does not properly warn the + user when extracting setuid or setgid files, which may allow local users or remote + attackers to gain privileges.", "uri": "https://security-tracker.debian.org/tracker/CVE-2005-2541", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:L/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "10"}]}, + {"name": "CVE-2021-20193", "description": "A flaw was found in the src/list.c of + tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input + file to tar to cause uncontrolled consumption of memory. The highest threat from + this vulnerability is to system availability." , "uri": "https://security-tracker.debian.org/tracker/CVE-2021-20193", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR", + "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, + {"name": "CVE-2017-17973", "description": "** DISPUTED ** In LibTIFF 4.0.8, there + is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: + there is a third-party report of inability to reproduce this issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17973", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key": + "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": + "6.8"}]}, {"name": "CVE-2020-35521", "description": "A flaw was found in libtiff. + Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to + an abort, resulting in denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35521", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key": + "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": + "4.3"}]}, {"name": "CVE-2014-8130", "description": "The _TIFFmalloc function in + tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers + to cause a denial of service (divide-by-zero error and application crash) via a + crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, + as demonstrated by tiffdither.", "uri": "https://security-tracker.debian.org/tracker/CVE-2014-8130", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key": + "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": + "4.3"}]}, {"name": "CVE-2017-5563", "description": "LibTIFF version 4.0.7 is vulnerable + to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution + via a crafted bmp image to tools/bmp2tiff." , "uri": "https://security-tracker.debian.org/tracker/CVE-2017-5563", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key": + "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": + "6.8"}]}, {"name": "CVE-2020-35522", "description": "In LibTIFF, there is a memory + malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, + resulting in a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35522", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key": + "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": + "4.3"}]}, {"name": "CVE-2017-9117", "description": "In LibTIFF 4.0.7, the program + processes BMP images without verifying that biWidth and biHeight in the bitmap-information + header match the actual input, leading to a heap-based buffer over-read in bmp2tiff.", + "uri": "https://security-tracker.debian.org/tracker/CVE-2017-9117", "severity": + "INFORMATIONAL", "attributes": [{"key": "package_version", "value": "4.1.0+git191117-2~deb10u2"}, + {"key": "package_name", "value": "tiff"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, + {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2017-16232", "description": + "** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow + attackers to cause a denial of service (memory consumption), as demonstrated by + tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce + the issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16232", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key": + "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": + "5"}]}, {"name": "CVE-2018-10126", "description": "LibTIFF 4.0.9 has a NULL pointer + dereference in the jpeg_fdct_16x16 function in jfdctint.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-10126", + "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value": + "4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key": + "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": + "4.3"}]}, {"name": "CVE-2021-22924", "description": "libcurl keeps previously used + connections in a connection pool for subsequenttransfers to reuse, if one of them + matches the setup.Due to errors in the logic, the config matching function did not + take ''issuercert'' into account and it compared the involved paths *case insensitively*,which + could lead to libcurl reusing wrong connections.File paths are, or can be, case + sensitive on many systems but not all, and caneven vary depending on used file systems.The + comparison also didn''t include the ''issuer cert'' which a transfer can setto qualify + how to verify the server certificate.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22924", + "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"}, + {"key": "package_name", "value": "curl" }]}, {"name": "CVE-2021-38115", "description": + "read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 + allows remote attackers to cause a denial of service (out-of-bounds read) via a + crafted TGA file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-38115", + "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"}, + {"key": "package_name", "value": "libgd2"}]}, {"name": "CVE-2021-3618", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3618", + "severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"}, + {"key": "package_name", "value": "nginx"}]}], "findingSeverityCounts": {"HIGH": + 2, "MEDIUM": 14, "INFORMATIONAL": 63, "LOW": 22, "UNDEFINED": 3}}}, "requestID": + "23c19e2d-c48b-4265-b4eb-853e7b325780", "eventID": "6c94a9b2-36dc-43f8-a6dd-4ec839ded8af", + "readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": + "111111111111", "eventCategory": "Management"}' diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml index 56fa1914b9..0a63249da0 100644 --- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml @@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk description: Logs an event when a request is made to get the account password policy in AWS CloudTrail. mitre_components: - - User Account Authentication - - User Account Metadata +- User Account Authentication +- User Account Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: GetAccountPasswordPolicy supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - desc - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- desc +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDASBMSCQHHTH5NDF4GD", "arn": "arn:aws:iam::111111111111:user/strt_fonder", "accountId": "111111111111", "accessKeyId": "AKIASBMSCQHH5A5NJDM5", "userName": "strt_fonder"}, diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml index d303eb012c..2e9608547a 100644 --- a/data_sources/aws_cloudtrail_getobject.yml +++ b/data_sources/aws_cloudtrail_getobject.yml @@ -6,100 +6,100 @@ author: Patrick Bareiss, Splunk description: Logs an event when a request is made to access an object stored in an AWS S3 bucket. mitre_components: - - Cloud Storage Access - - Cloud Storage Metadata - - Cloud Storage Enumeration +- Cloud Storage Access +- Cloud Storage Metadata +- Cloud Storage Enumeration source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: GetObject supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - additionalEventData.AuthenticationMethod - - additionalEventData.CipherSuite - - additionalEventData.SignatureVersion - - additionalEventData.bytesTransferredIn - - additionalEventData.bytesTransferredOut - - additionalEventData.x-amz-id-2 - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.Host - - requestParameters.bucketName - - requestParameters.key - - requestParameters.x-amz-request-payer - - resources{}.ARN - - resources{}.accountId - - resources{}.type - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- additionalEventData.AuthenticationMethod +- additionalEventData.CipherSuite +- additionalEventData.SignatureVersion +- additionalEventData.bytesTransferredIn +- additionalEventData.bytesTransferredOut +- additionalEventData.x-amz-id-2 +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.Host +- requestParameters.bucketName +- requestParameters.key +- requestParameters.x-amz-request-payer +- resources{}.ARN +- resources{}.accountId +- resources{}.type +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/console", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": "console"}, "eventTime": diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml index 6644109837..ca47e32ca9 100644 --- a/data_sources/aws_cloudtrail_getpassworddata.yml +++ b/data_sources/aws_cloudtrail_getpassworddata.yml @@ -6,101 +6,101 @@ author: Patrick Bareiss, Splunk description: Logs an event when a request is made to retrieve the administrator password of an EC2 instance. mitre_components: - - Instance Metadata - - User Account Authentication +- Instance Metadata +- User Account Authentication source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: GetPasswordData supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - errorMessage - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - reason - - recipientAccountId - - region - - requestID - - requestParameters.instanceId - - responseElements - - result - - result_id - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- errorMessage +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- reason +- recipientAccountId +- region +- requestID +- requestParameters.instanceId +- responseElements +- result +- result_id +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLP5AASA6I5:aws-go-sdk-1660169051746043000", "arn": "arn:aws:sts::111111111111:assumed-role/sample-role-used-by-stratus-for-ec2-password-data/aws-go-sdk-1660169051746043000", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLLY5RQXEF", "sessionContext": diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml index 2278f224a5..d0fbf8d5a8 100644 --- a/data_sources/aws_cloudtrail_jobcreated.yml +++ b/data_sources/aws_cloudtrail_jobcreated.yml @@ -5,77 +5,77 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a new job is created in AWS CloudTrail. mitre_components: - - Scheduled Job Creation - - Cloud Service Metadata +- Scheduled Job Creation +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: JobCreated supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - desc - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestParameters - - responseElements - - serviceEventDetails.jobArn - - serviceEventDetails.jobEventId - - serviceEventDetails.jobId - - serviceEventDetails.status - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - userAgent - - userIdentity.accountId - - userIdentity.invokedBy - - user_agent - - user_group_id - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- desc +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestParameters +- responseElements +- serviceEventDetails.jobArn +- serviceEventDetails.jobEventId +- serviceEventDetails.jobId +- serviceEventDetails.status +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- userAgent +- userIdentity.accountId +- userIdentity.invokedBy +- user_agent +- user_group_id +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"accountId": "111111111111", "invokedBy": "s3.amazonaws.com"}, "eventTime": "2023-04-24T23:51:17Z", "eventSource": "s3.amazonaws.com", "eventName": "JobCreated", "awsRegion": "us-west-2", "sourceIPAddress": diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml index 99cb79f0b2..156008b8c1 100644 --- a/data_sources/aws_cloudtrail_modifydbinstance.yml +++ b/data_sources/aws_cloudtrail_modifydbinstance.yml @@ -6,150 +6,150 @@ author: Patrick Bareiss, Splunk description: Logs an event when a modification is made to an AWS database instance, such as parameters or configurations. mitre_components: - - Instance Modification - - Cloud Service Modification - - Instance Metadata +- Instance Modification +- Cloud Service Modification +- Instance Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: ModifyDBInstance supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.allowMajorVersionUpgrade - - requestParameters.applyImmediately - - requestParameters.dBInstanceIdentifier - - requestParameters.deletionProtection - - requestParameters.masterUserPassword - - responseElements.allocatedStorage - - responseElements.autoMinorVersionUpgrade - - responseElements.availabilityZone - - responseElements.backupRetentionPeriod - - responseElements.backupTarget - - responseElements.cACertificateIdentifier - - responseElements.copyTagsToSnapshot - - responseElements.customerOwnedIpEnabled - - responseElements.dBInstanceArn - - responseElements.dBInstanceClass - - responseElements.dBInstanceIdentifier - - responseElements.dBInstanceStatus - - responseElements.dBParameterGroups{}.dBParameterGroupName - - responseElements.dBParameterGroups{}.parameterApplyStatus - - responseElements.dBSubnetGroup.dBSubnetGroupDescription - - responseElements.dBSubnetGroup.dBSubnetGroupName - - responseElements.dBSubnetGroup.subnetGroupStatus - - responseElements.dBSubnetGroup.subnets{}.subnetAvailabilityZone.name - - responseElements.dBSubnetGroup.subnets{}.subnetIdentifier - - responseElements.dBSubnetGroup.subnets{}.subnetStatus - - responseElements.dBSubnetGroup.vpcId - - responseElements.dbInstancePort - - responseElements.dbiResourceId - - responseElements.deletionProtection - - responseElements.endpoint.address - - responseElements.endpoint.hostedZoneId - - responseElements.endpoint.port - - responseElements.engine - - responseElements.engineVersion - - responseElements.enhancedMonitoringResourceArn - - responseElements.httpEndpointEnabled - - responseElements.iAMDatabaseAuthenticationEnabled - - responseElements.instanceCreateTime - - responseElements.kmsKeyId - - responseElements.latestRestorableTime - - responseElements.licenseModel - - responseElements.masterUsername - - responseElements.monitoringInterval - - responseElements.monitoringRoleArn - - responseElements.multiAZ - - responseElements.networkType - - responseElements.optionGroupMemberships{}.optionGroupName - - responseElements.optionGroupMemberships{}.status - - responseElements.pendingModifiedValues.masterUserPassword - - responseElements.performanceInsightsEnabled - - responseElements.performanceInsightsKMSKeyId - - responseElements.performanceInsightsRetentionPeriod - - responseElements.preferredBackupWindow - - responseElements.preferredMaintenanceWindow - - responseElements.publiclyAccessible - - responseElements.storageEncrypted - - responseElements.storageThroughput - - responseElements.storageType - - responseElements.vpcSecurityGroups{}.status - - responseElements.vpcSecurityGroups{}.vpcSecurityGroupId - - sessionCredentialFromConsole - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.allowMajorVersionUpgrade +- requestParameters.applyImmediately +- requestParameters.dBInstanceIdentifier +- requestParameters.deletionProtection +- requestParameters.masterUserPassword +- responseElements.allocatedStorage +- responseElements.autoMinorVersionUpgrade +- responseElements.availabilityZone +- responseElements.backupRetentionPeriod +- responseElements.backupTarget +- responseElements.cACertificateIdentifier +- responseElements.copyTagsToSnapshot +- responseElements.customerOwnedIpEnabled +- responseElements.dBInstanceArn +- responseElements.dBInstanceClass +- responseElements.dBInstanceIdentifier +- responseElements.dBInstanceStatus +- responseElements.dBParameterGroups{}.dBParameterGroupName +- responseElements.dBParameterGroups{}.parameterApplyStatus +- responseElements.dBSubnetGroup.dBSubnetGroupDescription +- responseElements.dBSubnetGroup.dBSubnetGroupName +- responseElements.dBSubnetGroup.subnetGroupStatus +- responseElements.dBSubnetGroup.subnets{}.subnetAvailabilityZone.name +- responseElements.dBSubnetGroup.subnets{}.subnetIdentifier +- responseElements.dBSubnetGroup.subnets{}.subnetStatus +- responseElements.dBSubnetGroup.vpcId +- responseElements.dbInstancePort +- responseElements.dbiResourceId +- responseElements.deletionProtection +- responseElements.endpoint.address +- responseElements.endpoint.hostedZoneId +- responseElements.endpoint.port +- responseElements.engine +- responseElements.engineVersion +- responseElements.enhancedMonitoringResourceArn +- responseElements.httpEndpointEnabled +- responseElements.iAMDatabaseAuthenticationEnabled +- responseElements.instanceCreateTime +- responseElements.kmsKeyId +- responseElements.latestRestorableTime +- responseElements.licenseModel +- responseElements.masterUsername +- responseElements.monitoringInterval +- responseElements.monitoringRoleArn +- responseElements.multiAZ +- responseElements.networkType +- responseElements.optionGroupMemberships{}.optionGroupName +- responseElements.optionGroupMemberships{}.status +- responseElements.pendingModifiedValues.masterUserPassword +- responseElements.performanceInsightsEnabled +- responseElements.performanceInsightsKMSKeyId +- responseElements.performanceInsightsRetentionPeriod +- responseElements.preferredBackupWindow +- responseElements.preferredMaintenanceWindow +- responseElements.publiclyAccessible +- responseElements.storageEncrypted +- responseElements.storageThroughput +- responseElements.storageType +- responseElements.vpcSecurityGroups{}.status +- responseElements.vpcSecurityGroups{}.vpcSecurityGroupId +- sessionCredentialFromConsole +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WP4HD6:gowthamarajr@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/gowthamarajr@splunk.com", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAKJDBQGB", "sessionContext": diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml index 67fd0edb8a..ab8bb25d87 100644 --- a/data_sources/aws_cloudtrail_modifyimageattribute.yml +++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml @@ -6,95 +6,95 @@ author: Patrick Bareiss, Splunk description: Logs an event when the attributes of an Amazon Machine Image (AMI) are modified. mitre_components: - - Image Modification - - Image Metadata +- Image Modification +- Image Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: ModifyImageAttribute supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.attributeType - - requestParameters.imageId - - requestParameters.launchPermission.add.items{}.userId - - responseElements._return - - responseElements.requestId - - sessionCredentialFromConsole - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.attributeType +- requestParameters.imageId +- requestParameters.launchPermission.add.items{}.userId +- responseElements._return +- responseElements.requestId +- sessionCredentialFromConsole +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WP4HD6:bonobo@bo.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bonobo@bo.com", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLBHIEEEPN", "sessionContext": diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml index d44c5fa436..0dec70fdf0 100644 --- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml @@ -6,90 +6,90 @@ author: Patrick Bareiss, Splunk description: Logs an event when modifications are made to the attributes of a snapshot in AWS CloudTrail. mitre_components: - - Snapshot Modification +- Snapshot Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: ModifySnapshotAttribute supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.attributeType - - requestParameters.createVolumePermission.add.items{}.userId - - requestParameters.snapshotId - - responseElements._return - - responseElements.requestId - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.attributeType +- requestParameters.createVolumePermission.add.items{}.userId +- requestParameters.snapshotId +- responseElements._return +- responseElements.requestId +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml index 715cb571cb..c531275617 100644 --- a/data_sources/aws_cloudtrail_putbucketacl.yml +++ b/data_sources/aws_cloudtrail_putbucketacl.yml @@ -6,104 +6,104 @@ author: Patrick Bareiss, Splunk description: Logs an event when an ACL is set or modified for an S3 bucket in AWS CloudTrail. mitre_components: - - Cloud Storage Modification - - Cloud Storage Metadata +- Cloud Storage Modification +- Cloud Storage Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: PutBucketAcl supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - additionalEventData.AuthenticationMethod - - additionalEventData.CipherSuite - - additionalEventData.SignatureVersion - - additionalEventData.bytesTransferredIn - - additionalEventData.bytesTransferredOut - - additionalEventData.x-amz-id-2 - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object - - object_category - - object_id - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.Host - - requestParameters.accessControlList.x-amz-grant-write-acp - - requestParameters.acl - - requestParameters.bucketName - - resources{}.ARN - - resources{}.accountId - - resources{}.type - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - src_user - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- additionalEventData.AuthenticationMethod +- additionalEventData.CipherSuite +- additionalEventData.SignatureVersion +- additionalEventData.bytesTransferredIn +- additionalEventData.bytesTransferredOut +- additionalEventData.x-amz-id-2 +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object +- object_category +- object_id +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.Host +- requestParameters.accessControlList.x-amz-grant-write-acp +- requestParameters.acl +- requestParameters.bucketName +- resources{}.ARN +- resources{}.accountId +- resources{}.type +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- src_user +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"}, diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml index e5108f5812..aa74257621 100644 --- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml +++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml @@ -6,105 +6,105 @@ author: Patrick Bareiss, Splunk description: Logs an event when a lifecycle configuration is added to an S3 bucket in AWS CloudTrail. mitre_components: - - Cloud Storage Modification - - Cloud Storage Metadata +- Cloud Storage Modification +- Cloud Storage Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: PutBucketLifecycle supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - additionalEventData.AuthenticationMethod - - additionalEventData.CipherSuite - - additionalEventData.SignatureVersion - - additionalEventData.bytesTransferredIn - - additionalEventData.bytesTransferredOut - - additionalEventData.x-amz-id-2 - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object - - object_category - - object_id - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.Host - - requestParameters.LifecycleConfiguration.Rule.Expiration.Days - - requestParameters.LifecycleConfiguration.Rule.Filter.Prefix - - requestParameters.LifecycleConfiguration.Rule.ID - - requestParameters.LifecycleConfiguration.Rule.Status - - requestParameters.LifecycleConfiguration.xmlns - - requestParameters.bucketName - - requestParameters.lifecycle - - resources{}.ARN - - resources{}.accountId - - resources{}.type - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- additionalEventData.AuthenticationMethod +- additionalEventData.CipherSuite +- additionalEventData.SignatureVersion +- additionalEventData.bytesTransferredIn +- additionalEventData.bytesTransferredOut +- additionalEventData.x-amz-id-2 +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object +- object_category +- object_id +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.Host +- requestParameters.LifecycleConfiguration.Rule.Expiration.Days +- requestParameters.LifecycleConfiguration.Rule.Filter.Prefix +- requestParameters.LifecycleConfiguration.Rule.ID +- requestParameters.LifecycleConfiguration.Rule.Status +- requestParameters.LifecycleConfiguration.xmlns +- requestParameters.bucketName +- requestParameters.lifecycle +- resources{}.ARN +- resources{}.accountId +- resources{}.type +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml index 779545c3e7..0da2860b07 100644 --- a/data_sources/aws_cloudtrail_putbucketreplication.yml +++ b/data_sources/aws_cloudtrail_putbucketreplication.yml @@ -6,117 +6,117 @@ author: Patrick Bareiss, Splunk description: Logs an event when replication configurations are added or modified for an S3 bucket. mitre_components: - - Cloud Storage Modification +- Cloud Storage Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: PutBucketReplication supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - additionalEventData.AuthenticationMethod - - additionalEventData.CipherSuite - - additionalEventData.SignatureVersion - - additionalEventData.bytesTransferredIn - - additionalEventData.bytesTransferredOut - - additionalEventData.x-amz-id-2 - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object - - object_category - - object_id - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.Host - - requestParameters.ReplicationConfiguration.Role - - requestParameters.ReplicationConfiguration.Rule.DeleteMarkerReplication.Status - - requestParameters.ReplicationConfiguration.Rule.Destination.Bucket - - requestParameters.ReplicationConfiguration.Rule.Filter - - requestParameters.ReplicationConfiguration.Rule.ID - - requestParameters.ReplicationConfiguration.Rule.Priority - - requestParameters.ReplicationConfiguration.Rule.Status - - requestParameters.ReplicationConfiguration.xmlns - - requestParameters.bucketName - - requestParameters.replication - - resources{}.ARN - - resources{}.accountId - - resources{}.type - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region - - vpcEndpointId +- _time +- additionalEventData.AuthenticationMethod +- additionalEventData.CipherSuite +- additionalEventData.SignatureVersion +- additionalEventData.bytesTransferredIn +- additionalEventData.bytesTransferredOut +- additionalEventData.x-amz-id-2 +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object +- object_category +- object_id +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.Host +- requestParameters.ReplicationConfiguration.Role +- requestParameters.ReplicationConfiguration.Rule.DeleteMarkerReplication.Status +- requestParameters.ReplicationConfiguration.Rule.Destination.Bucket +- requestParameters.ReplicationConfiguration.Rule.Filter +- requestParameters.ReplicationConfiguration.Rule.ID +- requestParameters.ReplicationConfiguration.Rule.Priority +- requestParameters.ReplicationConfiguration.Rule.Status +- requestParameters.ReplicationConfiguration.xmlns +- requestParameters.bucketName +- requestParameters.replication +- resources{}.ARN +- resources{}.accountId +- resources{}.type +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region +- vpcEndpointId example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WP4H11:bpatel@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bpatel@splunk.com", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLJOVYQHW2", "sessionContext": diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml index 1d727cc4d1..a0b031cda4 100644 --- a/data_sources/aws_cloudtrail_putbucketversioning.yml +++ b/data_sources/aws_cloudtrail_putbucketversioning.yml @@ -6,108 +6,108 @@ author: Patrick Bareiss, Splunk description: Logs an event when the bucket versioning state is modified in an AWS S3 bucket. mitre_components: - - Cloud Storage Modification +- Cloud Storage Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: PutBucketVersioning supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - additionalEventData.AuthenticationMethod - - additionalEventData.CipherSuite - - additionalEventData.SignatureVersion - - additionalEventData.bytesTransferredIn - - additionalEventData.bytesTransferredOut - - additionalEventData.x-amz-id-2 - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object - - object_category - - object_id - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.Host - - requestParameters.VersioningConfiguration.Status - - requestParameters.VersioningConfiguration.xmlns - - requestParameters.bucketName - - requestParameters.versioning - - resources{}.ARN - - resources{}.accountId - - resources{}.type - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region - - vpcEndpointId +- _time +- additionalEventData.AuthenticationMethod +- additionalEventData.CipherSuite +- additionalEventData.SignatureVersion +- additionalEventData.bytesTransferredIn +- additionalEventData.bytesTransferredOut +- additionalEventData.x-amz-id-2 +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object +- object_category +- object_id +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.Host +- requestParameters.VersioningConfiguration.Status +- requestParameters.VersioningConfiguration.xmlns +- requestParameters.bucketName +- requestParameters.versioning +- resources{}.ARN +- resources{}.accountId +- resources{}.type +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region +- vpcEndpointId example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLDF6WP4HD6:daftpunk@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/daftpunk@splunk.com", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAQ5VXXXX", "sessionContext": diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml index 713ed667e1..f5ba052aa0 100644 --- a/data_sources/aws_cloudtrail_putimage.yml +++ b/data_sources/aws_cloudtrail_putimage.yml @@ -6,98 +6,98 @@ author: Patrick Bareiss, Splunk description: Logs an event when a container image is uploaded to a repository in AWS CloudTrail. mitre_components: - - Image Creation - - Image Metadata +- Image Creation +- Image Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: PutImage supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.imageManifest - - requestParameters.imageManifestMediaType - - requestParameters.imageTag - - requestParameters.registryId - - requestParameters.repositoryName - - resources{}.ARN - - resources{}.accountId - - responseElements.image.imageId.imageDigest - - responseElements.image.imageId.imageTag - - responseElements.image.imageManifest - - responseElements.image.imageManifestMediaType - - responseElements.image.registryId - - responseElements.image.repositoryName - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.invokedBy - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.imageManifest +- requestParameters.imageManifestMediaType +- requestParameters.imageTag +- requestParameters.registryId +- requestParameters.repositoryName +- resources{}.ARN +- resources{}.accountId +- responseElements.image.imageId.imageDigest +- responseElements.image.imageId.imageTag +- responseElements.image.imageManifest +- responseElements.image.imageManifestMediaType +- responseElements.image.registryId +- responseElements.image.repositoryName +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.invokedBy +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AAAAAAAAAAAAAAAAAAAAA", "arn": "arn:aws:iam::111111111111:user/test", "accountId": "111111111111", "accessKeyId": "AAAAAAAAAAAAAAAAAAAAA", "userName": "test", "sessionContext": diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml index d291365312..597af6e6cb 100644 --- a/data_sources/aws_cloudtrail_putkeypolicy.yml +++ b/data_sources/aws_cloudtrail_putkeypolicy.yml @@ -9,94 +9,94 @@ source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.bypassPolicyLockoutSafetyCheck - - requestParameters.keyId - - requestParameters.policy - - requestParameters.policyName - - resources{}.ARN - - resources{}.accountId - - resources{}.type - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.bypassPolicyLockoutSafetyCheck +- requestParameters.keyId +- requestParameters.policy +- requestParameters.policyName +- resources{}.ARN +- resources{}.accountId +- resources{}.type +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region mitre_components: - - Cloud Service Modification +- Cloud Service Modification example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext": diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml index 4e7c3f9359..fb1752d56b 100644 --- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml @@ -5,106 +5,106 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail. mitre_components: - - Firewall Rule Modification - - Cloud Service Modification +- Firewall Rule Modification +- Cloud Service Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: ReplaceNetworkAclEntry supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - direction - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - protocol - - protocol_code - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.aclProtocol - - requestParameters.cidrBlock - - requestParameters.egress - - requestParameters.networkAclId - - requestParameters.ruleAction - - requestParameters.ruleNumber - - responseElements._return - - responseElements.requestId - - rule_action - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - src_ip_range - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- direction +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- protocol +- protocol_code +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.aclProtocol +- requestParameters.cidrBlock +- requestParameters.egress +- requestParameters.networkAclId +- requestParameters.ruleAction +- requestParameters.ruleNumber +- responseElements._return +- responseElements.requestId +- rule_action +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- src_ip_range +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext": diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml index d5c2a78694..b8e4d54281 100644 --- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml +++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml @@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk description: Logs an event when the default version of a resource policy in AWS is set or changed. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: SetDefaultPolicyVersion supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.policyArn - - requestParameters.versionId - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.policyArn +- requestParameters.versionId +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLESDK2NOSX", "arn": "arn:aws:iam::111111111111:user/AtomicRedTeam", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKMZDMPVA", "userName": diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml index 934920e8fb..00d6b018a9 100644 --- a/data_sources/aws_cloudtrail_stoplogging.yml +++ b/data_sources/aws_cloudtrail_stoplogging.yml @@ -6,86 +6,86 @@ author: Patrick Bareiss, Splunk description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated or stopped. mitre_components: - - Cloud Service Disable +- Cloud Service Disable source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: StopLogging supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.name - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.name +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml index 6fd33c83e7..9c9fee7893 100644 --- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml @@ -5,98 +5,98 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an AWS account's password policy is updated. mitre_components: - - User Account Modification - - Cloud Service Modification +- User Account Modification +- Cloud Service Modification source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: UpdateAccountPasswordPolicy supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.allowUsersToChangePassword - - requestParameters.hardExpiry - - requestParameters.minimumPasswordLength - - requestParameters.requireLowercaseCharacters - - requestParameters.requireNumbers - - requestParameters.requireSymbols - - requestParameters.requireUppercaseCharacters - - responseElements - - sessionCredentialFromConsole - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.allowUsersToChangePassword +- requestParameters.hardExpiry +- requestParameters.minimumPasswordLength +- requestParameters.requireLowercaseCharacters +- requestParameters.requireNumbers +- requestParameters.requireSymbols +- requestParameters.requireUppercaseCharacters +- responseElements +- sessionCredentialFromConsole +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId": "111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111", "accessKeyId": "ASIASBMSCQHHZZ4THONS", "sessionContext": {"sessionIssuer": {}, "webIdFederationData": diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml index 911021b6d6..ee8d48a0d4 100644 --- a/data_sources/aws_cloudtrail_updateloginprofile.yml +++ b/data_sources/aws_cloudtrail_updateloginprofile.yml @@ -5,90 +5,90 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an IAM user's login profile is updated. mitre_components: - - User Account Modification - - User Account Authentication +- User Account Modification +- User Account Authentication source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: UpdateLoginProfile supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.userName - - responseElements - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.userName +- responseElements +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml index 3c7f55c5ea..55fb18209d 100644 --- a/data_sources/aws_cloudtrail_updatesamlprovider.yml +++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml @@ -5,207 +5,188 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a SAML provider is updated in AWS. mitre_components: - - Cloud Service Modification - - User Account Modification - - Cloud Service Metadata +- Cloud Service Modification +- User Account Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: UpdateSAMLProvider supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - action - - app - - awsRegion - - aws_account_id - - change_type - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - eventtype - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.sAMLMetadataDocument - - requestParameters.sAMLProviderArn - - responseElements.sAMLProviderArn - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.sessionContext.attributes.creationDate - - userIdentity.sessionContext.attributes.mfaAuthenticated - - userIdentity.sessionContext.sessionIssuer.accountId - - userIdentity.sessionContext.sessionIssuer.arn - - userIdentity.sessionContext.sessionIssuer.principalId - - userIdentity.sessionContext.sessionIssuer.type - - userIdentity.sessionContext.sessionIssuer.userName - - userIdentity.type - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region -example_log: "{\"eventVersion\": \"1.08\", \"userIdentity\": {\"type\": \"AssumedRole\"\ - , \"principalId\": \"AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com\", \"\ - arn\": \"arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com\"\ - , \"accountId\": \"111111111111\", \"accessKeyId\": \"ASIAYTOGP2RLMZGPIW6C\", \"\ - sessionContext\": {\"sessionIssuer\": {\"type\": \"Role\", \"principalId\": \"AROAYTOGP2RLKFUVAQAIJ\"\ - , \"arn\": \"arn:aws:iam::111111111111:role/rodonmicrotestrole\", \"accountId\" - : \"111111111111\", \"userName\": \"rodonmicrotestrole\"}, \"webIdFederationData\"\ - : {}, \"attributes\": {\"mfaAuthenticated\": \"false\", \"creationDate\": \"2021-01-20T03:10:32Z\"\ - }}}, \"eventTime\": \"2021-01-20T03:12:39Z\", \"eventSource\": \"iam.amazonaws.com\"\ - , \"eventName\": \"UpdateSAMLProvider\", \"awsRegion\": \"us-east-1\", \"sourceIPAddress\"\ - : \"66.176.252.11\", \"userAgent\": \"aws-internal/3 aws-sdk-java/1.11.930 Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 - OpenJDK_64-Bit_Server_VM/25.275-b01 java/1.8.0_275 vendor/Oracle_Corporation\", - \"requestParameters\": {\"sAMLMetadataDocument\": \"ncp+pf0e75KdoRTy1PQeu74OKXjcVNM+bnT7Ns6cwQI=J9PRCq201gGMzMtt4Ye+gsM7xOgrNvDg/usqIMvsyUy2r/MeTBz5FKCK+Okjwm49vyTWUoUioYGiwm/TD2Knv59g1zy+/OjZcmBJgDrCmksFJdkwG/fDlOZQNGuj2qh1CEKL5n6Ipy2z1dQ9XUmhhndtXNnjdZ0fJ9QWufWoxveSCLHcU7eUB9obwq96pbAp+6as0XreMNC/xPv5gDdHfKaIppsXtEwcZY7m1c25jDWqPUTQrtbVC0uryffg1Yu0JLTr646GMTzxulBSpQGRfNf5UT0bUiLtKngi++UHrngKdv3ovWwpVmY82JhG7rMDhkuWZu3LdEFvY3svNxGtsQ==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNNameThe +- _time +- action +- app +- awsRegion +- aws_account_id +- change_type +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- eventtype +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.sAMLMetadataDocument +- requestParameters.sAMLProviderArn +- responseElements.sAMLProviderArn +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.sessionContext.attributes.creationDate +- userIdentity.sessionContext.attributes.mfaAuthenticated +- userIdentity.sessionContext.sessionIssuer.accountId +- userIdentity.sessionContext.sessionIssuer.arn +- userIdentity.sessionContext.sessionIssuer.principalId +- userIdentity.sessionContext.sessionIssuer.type +- userIdentity.sessionContext.sessionIssuer.userName +- userIdentity.type +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region +example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": + "AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com", + "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLMZGPIW6C", "sessionContext": + {"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLKFUVAQAIJ", "arn": + "arn:aws:iam::111111111111:role/rodonmicrotestrole", "accountId" : "111111111111", + "userName": "rodonmicrotestrole"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated": + "false", "creationDate": "2021-01-20T03:10:32Z"}}}, "eventTime": "2021-01-20T03:12:39Z", + "eventSource": "iam.amazonaws.com", "eventName": "UpdateSAMLProvider", "awsRegion": + "us-east-1", "sourceIPAddress": "66.176.252.11", "userAgent": "aws-internal/3 aws-sdk-java/1.11.930 + Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.275-b01 + java/1.8.0_275 vendor/Oracle_Corporation", "requestParameters": {"sAMLMetadataDocument": + "ncp+pf0e75KdoRTy1PQeu74OKXjcVNM+bnT7Ns6cwQI=J9PRCq201gGMzMtt4Ye+gsM7xOgrNvDg/usqIMvsyUy2r/MeTBz5FKCK+Okjwm49vyTWUoUioYGiwm/TD2Knv59g1zy+/OjZcmBJgDrCmksFJdkwG/fDlOZQNGuj2qh1CEKL5n6Ipy2z1dQ9XUmhhndtXNnjdZ0fJ9QWufWoxveSCLHcU7eUB9obwq96pbAp+6as0XreMNC/xPv5gDdHfKaIppsXtEwcZY7m1c25jDWqPUTQrtbVC0uryffg1Yu0JLTr646GMTzxulBSpQGRfNf5UT0bUiLtKngi++UHrngKdv3ovWwpVmY82JhG7rMDhkuWZu3LdEFvY3svNxGtsQ==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNNameThe mutable display name of the user.SubjectAn + Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">SubjectAn immutable, globally unique, non-reusable identifier of the user that is unique to the application for which a token is issued.Given + Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">Given NameFirst name of the user.SurnameLast - name of the user.Display + Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">SurnameLast + name of the user.Display NameDisplay name of the user.Nick + Uri=\"http://schemas.microsoft.com/identity/claims/nickname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">Nick NameNick name of the user.Authentication + Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant\" + xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">Authentication InstantThe time (UTC) when the user is authenticated to Windows Azure Active Directory.Authentication + Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod\" + xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">Authentication MethodThe method that Windows Azure Active Directory uses to authenticate users.ObjectIdentifierPrimary + Uri=\"http://schemas.microsoft.com/identity/claims/objectidentifier\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">ObjectIdentifierPrimary identifier for the user in the directory. Immutable, globally unique, non-reusable.TenantIdIdentifier - for the user's tenant.IdentityProviderIdentity - provider for the user.EmailEmail - address of the user.GroupsGroups - of the user.External + Uri=\"http://schemas.microsoft.com/identity/claims/tenantid\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">TenantIdIdentifier + for the user''s tenant.IdentityProviderIdentity + provider for the user.EmailEmail + address of the user.GroupsGroups + of the user.External Access TokenAccess token issued by external - identity provider.External + identity provider.External Access Token ExpirationUTC expiration time of access token issued by external identity provider.External + Uri=\"http://schemas.microsoft.com/identity/claims/openid2_id\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">External OpenID 2.0 IdentifierOpenID 2.0 identifier issued by external identity provider.GroupsOverageClaimIssued - when number of user's group claims exceeds return limit.Role + Uri=\"http://schemas.microsoft.com/claims/groups.link\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\">GroupsOverageClaimIssued + when number of user''s group claims exceeds return limit.Role ClaimRoles that the user or Service Principal - is attached toRoleTemplate + is attached toRoleTemplate Id ClaimRole template id of the Built-in Directory Roles that the user is a member ofhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNhttps://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN\", \"sAMLProviderArn\": \"arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft\"\ - }, \"responseElements\": {\"sAMLProviderArn\": \"arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft\"\ - }, \"requestID\": \"83d621ad-5b33-4ff0-acf4-0043cb432844\", \"eventID\": \"51b6d859-0cc4-4591-ba76-3494f3f43832\"\ - , \"readOnly\": false, \"eventType\": \"AwsApiCall\", \"managementEvent\": true, - \"eventCategory\": \"Management\", \"recipientAccountId\": \"111111111111\"}" + xmlns:wsa=\"http://www.w3.org/2005/08/addressing\">https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KNhttps://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedhttps://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfedMIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN", "sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}, + "responseElements": {"sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}, + "requestID": "83d621ad-5b33-4ff0-acf4-0043cb432844", "eventID": "51b6d859-0cc4-4591-ba76-3494f3f43832", + "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": + "Management", "recipientAccountId": "111111111111"}' diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml index 6020310ebe..33813ccfec 100644 --- a/data_sources/aws_cloudtrail_updatetrail.yml +++ b/data_sources/aws_cloudtrail_updatetrail.yml @@ -6,95 +6,95 @@ author: Patrick Bareiss, Splunk description: Logs an event when an AWS CloudTrail trail is updated, typically involving changes to settings or configuration. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata +- Cloud Service Modification +- Cloud Service Metadata source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName separator_value: UpdateTrail supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - app - - awsRegion - - aws_account_id - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - errorCode - - eventCategory - - eventID - - eventName - - eventSource - - eventTime - - eventType - - eventVersion - - host - - index - - linecount - - managementEvent - - msg - - object_category - - product - - punct - - readOnly - - recipientAccountId - - region - - requestID - - requestParameters.includeGlobalServiceEvents - - requestParameters.isMultiRegionTrail - - requestParameters.name - - responseElements.includeGlobalServiceEvents - - responseElements.isMultiRegionTrail - - responseElements.isOrganizationTrail - - responseElements.logFileValidationEnabled - - responseElements.name - - responseElements.s3BucketName - - responseElements.trailARN - - signature - - source - - sourceIPAddress - - sourcetype - - splunk_server - - src - - src_ip - - start_time - - timeendpos - - timestartpos - - tlsDetails.cipherSuite - - tlsDetails.clientProvidedHostHeader - - tlsDetails.tlsVersion - - user - - userAgent - - userIdentity.accessKeyId - - userIdentity.accountId - - userIdentity.arn - - userIdentity.principalId - - userIdentity.type - - userIdentity.userName - - userName - - user_access_key - - user_agent - - user_arn - - user_group_id - - user_id - - user_name - - user_type - - vendor - - vendor_account - - vendor_product - - vendor_region +- _time +- app +- awsRegion +- aws_account_id +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- errorCode +- eventCategory +- eventID +- eventName +- eventSource +- eventTime +- eventType +- eventVersion +- host +- index +- linecount +- managementEvent +- msg +- object_category +- product +- punct +- readOnly +- recipientAccountId +- region +- requestID +- requestParameters.includeGlobalServiceEvents +- requestParameters.isMultiRegionTrail +- requestParameters.name +- responseElements.includeGlobalServiceEvents +- responseElements.isMultiRegionTrail +- responseElements.isOrganizationTrail +- responseElements.logFileValidationEnabled +- responseElements.name +- responseElements.s3BucketName +- responseElements.trailARN +- signature +- source +- sourceIPAddress +- sourcetype +- splunk_server +- src +- src_ip +- start_time +- timeendpos +- timestartpos +- tlsDetails.cipherSuite +- tlsDetails.clientProvidedHostHeader +- tlsDetails.tlsVersion +- user +- userAgent +- userIdentity.accessKeyId +- userIdentity.accountId +- userIdentity.arn +- userIdentity.principalId +- userIdentity.type +- userIdentity.userName +- userName +- user_access_key +- user_agent +- user_arn +- user_group_id +- user_id +- user_name +- user_type +- vendor +- vendor_account +- vendor_product +- vendor_region example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName": diff --git a/data_sources/aws_cloudwatchlogs_vpcflow.yml b/data_sources/aws_cloudwatchlogs_vpcflow.yml index 6cd8b1cec1..535431134a 100644 --- a/data_sources/aws_cloudwatchlogs_vpcflow.yml +++ b/data_sources/aws_cloudwatchlogs_vpcflow.yml @@ -7,67 +7,67 @@ description: Logs an event when network traffic flow information such as source destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in AWS. mitre_components: - - Network Traffic Flow - - Network Connection Creation +- Network Traffic Flow +- Network Connection Creation source: aws_cloudwatchlogs_vpcflow sourcetype: aws:cloudwatchlogs:vpcflow supported_TA: - - name: Splunk Add-on for AWS - version: 7.9.0 - url: https://splunkbase.splunk.com/app/1876 +- name: Splunk Add-on for AWS + version: 7.9.0 + url: https://splunkbase.splunk.com/app/1876 fields: - - _raw - - _time - - account_id - - action - - app - - aws_account_id - - bytes - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_ip - - dest_port - - duration - - dvc - - end_time - - eventtype - - host - - index - - interface_id - - linecount - - log_status - - packets - - protocol - - protocol_code - - protocol_full_name - - protocol_version - - punct - - region - - source - - sourcetype - - splunk_server - - splunk_server_group - - src - - src_ip - - src_port - - start_time - - tag - - tag::action - - tag::eventtype - - timeendpos - - timestartpos - - transport - - user_id - - vendor_account - - vendor_product - - version - - vpcflow_action +- _raw +- _time +- account_id +- action +- app +- aws_account_id +- bytes +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_ip +- dest_port +- duration +- dvc +- end_time +- eventtype +- host +- index +- interface_id +- linecount +- log_status +- packets +- protocol +- protocol_code +- protocol_full_name +- protocol_version +- punct +- region +- source +- sourcetype +- splunk_server +- splunk_server_group +- src +- src_ip +- src_port +- start_time +- tag +- tag::action +- tag::eventtype +- timeendpos +- timestartpos +- transport +- user_id +- vendor_account +- vendor_product +- version +- vpcflow_action example_log: 2 123397614277 eni-0b0f9f261f45e6489 10.0.1.30 10.0.1.1 47254 22 17 2 98 1697608042 1697608070 ACCEPT OK diff --git a/data_sources/aws_security_hub.yml b/data_sources/aws_security_hub.yml index 0173357cdf..c5ff1ade29 100644 --- a/data_sources/aws_security_hub.yml +++ b/data_sources/aws_security_hub.yml @@ -6,120 +6,120 @@ author: Patrick Bareiss, Splunk description: Logs an event when AWS Security Hub identifies potential security risks or deviations from configured best practices across AWS accounts. mitre_components: - - Cloud Service Metadata - - Cloud Service Enumeration - - Cloud Service Modification - - Cloud Service Disable +- Cloud Service Metadata +- Cloud Service Enumeration +- Cloud Service Modification +- Cloud Service Disable source: aws_securityhub_finding sourcetype: aws:securityhub:finding supported_TA: - - name: Splunk Add-on for AWS - url: https://splunkbase.splunk.com/app/1876 - version: 7.9.0 +- name: Splunk Add-on for AWS + url: https://splunkbase.splunk.com/app/1876 + version: 7.9.0 fields: - - _time - - AwsAccountId - - CreatedAt - - Description - - FirstObservedAt - - GeneratorId - - Id - - LastObservedAt - - ProductArn - - ProductFields.aws/guardduty/service/action/actionType - - ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket - - ProductFields.aws/guardduty/service/action/awsApiCallAction/api - - ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType - - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName - - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName - - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat - - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon - - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4 - - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn - - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg - - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp - - ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org - - ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName - - ProductFields.aws/guardduty/service/additionalInfo/sample - - ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_ - - ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_ - - ProductFields.aws/guardduty/service/archived - - ProductFields.aws/guardduty/service/count - - ProductFields.aws/guardduty/service/detectorId - - ProductFields.aws/guardduty/service/eventFirstSeen - - ProductFields.aws/guardduty/service/eventLastSeen - - ProductFields.aws/guardduty/service/resourceRole - - ProductFields.aws/guardduty/service/serviceName - - ProductFields.aws/securityhub/CompanyName - - ProductFields.aws/securityhub/FindingId - - ProductFields.aws/securityhub/ProductName - - RecordState - - Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn - - Resources{}.Details.AwsEc2Instance.ImageId - - Resources{}.Details.AwsEc2Instance.IpV4Addresses{} - - Resources{}.Details.AwsEc2Instance.LaunchedAt - - Resources{}.Details.AwsEc2Instance.SubnetId - - Resources{}.Details.AwsEc2Instance.Type - - Resources{}.Details.AwsEc2Instance.VpcId - - Resources{}.Details.AwsIamAccessKey.PrincipalId - - Resources{}.Details.AwsIamAccessKey.PrincipalName - - Resources{}.Details.AwsIamAccessKey.PrincipalType - - Resources{}.Details.AwsS3Bucket.CreatedAt - - Resources{}.Details.AwsS3Bucket.OwnerId - - Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID - - Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm - - Resources{}.Id - - Resources{}.Partition - - Resources{}.Region - - Resources{}.Tags.GeneratedFindingInstaceTag1 - - Resources{}.Tags.GeneratedFindingInstaceTag2 - - Resources{}.Tags.GeneratedFindingInstaceTag3 - - Resources{}.Tags.GeneratedFindingInstaceTag4 - - Resources{}.Tags.GeneratedFindingInstaceTag5 - - Resources{}.Tags.GeneratedFindingInstaceTag6 - - Resources{}.Tags.GeneratedFindingInstaceTag7 - - Resources{}.Tags.GeneratedFindingInstaceTag8 - - Resources{}.Tags.GeneratedFindingInstaceTag9 - - Resources{}.Tags.foo - - Resources{}.Type - - SchemaVersion - - Severity.Label - - Severity.Normalized - - Severity.Product - - SourceUrl - - Title - - Types{} - - UpdatedAt - - Workflow.Status - - WorkflowState - - accesskey_extract - - app - - body - - description - - dest - - dest_type - - eventtype - - host - - id - - index - - instance_extract - - linecount - - punct - - s3bucket_extract - - severity - - severity_id - - signature - - signature_id - - source - - sourcetype - - splunk_server - - subject - - tag - - tag::eventtype - - timestamp - - type - - vendor_account - - vendor_region +- _time +- AwsAccountId +- CreatedAt +- Description +- FirstObservedAt +- GeneratorId +- Id +- LastObservedAt +- ProductArn +- ProductFields.aws/guardduty/service/action/actionType +- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket +- ProductFields.aws/guardduty/service/action/awsApiCallAction/api +- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType +- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName +- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName +- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat +- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon +- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4 +- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn +- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg +- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp +- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org +- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName +- ProductFields.aws/guardduty/service/additionalInfo/sample +- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_ +- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_ +- ProductFields.aws/guardduty/service/archived +- ProductFields.aws/guardduty/service/count +- ProductFields.aws/guardduty/service/detectorId +- ProductFields.aws/guardduty/service/eventFirstSeen +- ProductFields.aws/guardduty/service/eventLastSeen +- ProductFields.aws/guardduty/service/resourceRole +- ProductFields.aws/guardduty/service/serviceName +- ProductFields.aws/securityhub/CompanyName +- ProductFields.aws/securityhub/FindingId +- ProductFields.aws/securityhub/ProductName +- RecordState +- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn +- Resources{}.Details.AwsEc2Instance.ImageId +- Resources{}.Details.AwsEc2Instance.IpV4Addresses{} +- Resources{}.Details.AwsEc2Instance.LaunchedAt +- Resources{}.Details.AwsEc2Instance.SubnetId +- Resources{}.Details.AwsEc2Instance.Type +- Resources{}.Details.AwsEc2Instance.VpcId +- Resources{}.Details.AwsIamAccessKey.PrincipalId +- Resources{}.Details.AwsIamAccessKey.PrincipalName +- Resources{}.Details.AwsIamAccessKey.PrincipalType +- Resources{}.Details.AwsS3Bucket.CreatedAt +- Resources{}.Details.AwsS3Bucket.OwnerId +- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID +- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm +- Resources{}.Id +- Resources{}.Partition +- Resources{}.Region +- Resources{}.Tags.GeneratedFindingInstaceTag1 +- Resources{}.Tags.GeneratedFindingInstaceTag2 +- Resources{}.Tags.GeneratedFindingInstaceTag3 +- Resources{}.Tags.GeneratedFindingInstaceTag4 +- Resources{}.Tags.GeneratedFindingInstaceTag5 +- Resources{}.Tags.GeneratedFindingInstaceTag6 +- Resources{}.Tags.GeneratedFindingInstaceTag7 +- Resources{}.Tags.GeneratedFindingInstaceTag8 +- Resources{}.Tags.GeneratedFindingInstaceTag9 +- Resources{}.Tags.foo +- Resources{}.Type +- SchemaVersion +- Severity.Label +- Severity.Normalized +- Severity.Product +- SourceUrl +- Title +- Types{} +- UpdatedAt +- Workflow.Status +- WorkflowState +- accesskey_extract +- app +- body +- description +- dest +- dest_type +- eventtype +- host +- id +- index +- instance_extract +- linecount +- punct +- s3bucket_extract +- severity +- severity_id +- signature +- signature_id +- source +- sourcetype +- splunk_server +- subject +- tag +- tag::eventtype +- timestamp +- type +- vendor_account +- vendor_region example_log: '{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software and Configuration Checks/Exfiltration:S3.ObjectRead.Unusual"],"SourceUrl":"https://us-east-1.console.aws.amazon.com/guardduty/home?region=us-east-1#/findings?macros=current&fId=6aba6b696aea10606e8b336f68d98819","Description":"Principal GeneratedFindingUserName read objects from S3 bucket GeneratedFindingS3Bucket in diff --git a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml index b0f85d0cb5..034f25fb98 100644 --- a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml +++ b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml @@ -7,93 +7,93 @@ description: Logs the addition of an application role assignment to a service pr in Azure Active Directory, including details about the role, service principal, and the user or process performing the action. mitre_components: - - User Account Modification - - Group Modification - - Cloud Service Modification - - Cloud Service Metadata +- User Account Modification +- Group Modification +- Cloud Service Modification +- Cloud Service Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Add app role assignment to service principal supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - additional_details - - additional_details_name - - additional_details_value - - category - - command - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_type - - durationMs - - dvc - - eventtype - - host - - id - - identity - - index - - linecount - - object_attrs - - object_id - - operationName - - operationVersion - - path_from_resourceId - - properties.activityDateTime - - properties.activityDisplayName - - properties.additionalDetails{}.key - - properties.additionalDetails{}.value - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.app.appId - - properties.initiatedBy.app.displayName - - properties.initiatedBy.app.servicePrincipalId - - properties.initiatedBy.app.servicePrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.targetResources{}.type - - properties.userAgent - - punct - - resourceId - - result - - resultSignature - - result_id - - signature - - source - - sourcetype - - splunk_server - - src_user_type - - status - - tag - - tag::eventtype - - tenantId - - time - - timeendpos - - timestartpos - - user_agent - - user_type - - vendor_account - - vendor_product +- _time +- Level +- additional_details +- additional_details_name +- additional_details_value +- category +- command +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_type +- durationMs +- dvc +- eventtype +- host +- id +- identity +- index +- linecount +- object_attrs +- object_id +- operationName +- operationVersion +- path_from_resourceId +- properties.activityDateTime +- properties.activityDisplayName +- properties.additionalDetails{}.key +- properties.additionalDetails{}.value +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.app.appId +- properties.initiatedBy.app.displayName +- properties.initiatedBy.app.servicePrincipalId +- properties.initiatedBy.app.servicePrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.targetResources{}.type +- properties.userAgent +- punct +- resourceId +- result +- resultSignature +- result_id +- signature +- source +- sourcetype +- splunk_server +- src_user_type +- status +- tag +- tag::eventtype +- tenantId +- time +- timeendpos +- timestartpos +- user_agent +- user_type +- vendor_account +- vendor_product example_log: '{"time": "2024-02-08T21:49:53.7643129Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam", "operationName": "Add app role assignment to service principal", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml index 8a977d8625..579bd563b7 100644 --- a/data_sources/azure_active_directory_add_member_to_role.yml +++ b/data_sources/azure_active_directory_add_member_to_role.yml @@ -7,69 +7,69 @@ description: Logs the addition of a member to a directory role in Azure Active D including details about the role, the member added, and the user or process performing the action. mitre_components: - - Group Modification - - Group Metadata - - User Account Metadata - - Cloud Service Modification +- Group Modification +- Group Metadata +- User Account Metadata +- Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Add member to role supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.targetResources{}.type - - properties.targetResources{}.userPrincipalName - - properties.userAgent - - punct - - resourceId - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.targetResources{}.type +- properties.targetResources{}.userPrincipalName +- properties.userAgent +- punct +- resourceId +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-04-28T16:39:51.9312625Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Add member to role", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs": diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml index 70948b2b1f..fb97560390 100644 --- a/data_sources/azure_active_directory_add_owner_to_application.yml +++ b/data_sources/azure_active_directory_add_owner_to_application.yml @@ -7,74 +7,74 @@ description: Logs the addition of an owner to an application in Azure Active Dir including details about the application, the owner added, and the user or process performing the action. mitre_components: - - User Account Modification - - Group Modification - - Cloud Service Modification - - Cloud Service Metadata +- User Account Modification +- Group Modification +- Cloud Service Modification +- Cloud Service Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Add owner to application supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - eventtype - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.additionalDetails{}.key - - properties.additionalDetails{}.value - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.targetResources{}.type - - properties.targetResources{}.userPrincipalName - - properties.userAgent - - punct - - resourceId - - resultSignature - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- eventtype +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.additionalDetails{}.key +- properties.additionalDetails{}.value +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.targetResources{}.type +- properties.targetResources{}.userPrincipalName +- properties.userAgent +- punct +- resourceId +- resultSignature +- source +- sourcetype +- splunk_server +- tag +- tag::eventtype +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-06-20T15:54:13.2420879Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Add owner to application", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml index 46f3c3d7d9..c3d937cb44 100644 --- a/data_sources/azure_active_directory_add_service_principal.yml +++ b/data_sources/azure_active_directory_add_service_principal.yml @@ -7,69 +7,69 @@ description: Logs the creation of a new service principal in Azure Active Direct including details about the service principal, associated application, and the user or process performing the action. mitre_components: - - Cloud Service Creation - - Cloud Service Metadata - - User Account Metadata - - Active Directory Object Creation +- Cloud Service Creation +- Cloud Service Metadata +- User Account Metadata +- Active Directory Object Creation source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Add service principal supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.additionalDetails{}.key - - properties.additionalDetails{}.value - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.targetResources{}.type - - properties.userAgent - - punct - - resourceId - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.additionalDetails{}.key +- properties.additionalDetails{}.value +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.targetResources{}.type +- properties.userAgent +- punct +- resourceId +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2024-02-07T22:31:14.4970418Z", "resourceId": "/tenants/a417c578-c7ee-480d-a225-d48057e74df5/providers/Microsoft.aadiam", "operationName": "Add service principal", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "a417c578-c7ee-480d-a225-d48057e74df5", "resultSignature": diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml index 444d3e1a6f..01badc54df 100644 --- a/data_sources/azure_active_directory_add_unverified_domain.yml +++ b/data_sources/azure_active_directory_add_unverified_domain.yml @@ -6,69 +6,69 @@ author: Patrick Bareiss, Splunk description: Logs the addition of an unverified domain to Azure Active Directory, including details about the domain name and the user or process performing the action. mitre_components: - - Domain Registration - - Cloud Service Modification - - Cloud Service Metadata - - Configuration Modification +- Domain Registration +- Cloud Service Modification +- Cloud Service Metadata +- Configuration Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Add unverified domain supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.additionalDetails{}.key - - properties.additionalDetails{}.value - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.userAgent - - punct - - resourceId - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.additionalDetails{}.key +- properties.additionalDetails{}.value +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.userAgent +- punct +- resourceId +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-07-26T13:45:54.1582053Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Add unverified domain", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml index 4222ab6a7c..4bc104a119 100644 --- a/data_sources/azure_active_directory_consent_to_application.yml +++ b/data_sources/azure_active_directory_consent_to_application.yml @@ -7,74 +7,74 @@ description: Logs user or admin consent to an application's permissions in Azure Directory, including details about the application, granted permissions, and the consenting user or process. mitre_components: - - User Account Modification - - Cloud Service Modification - - Cloud Service Metadata - - Configuration Modification +- User Account Modification +- Cloud Service Modification +- Cloud Service Metadata +- Configuration Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Consent to application supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - eventtype - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.additionalDetails{}.key - - properties.additionalDetails{}.value - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.targetResources{}.type - - properties.userAgent - - punct - - resourceId - - resultDescription - - resultSignature - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- eventtype +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.additionalDetails{}.key +- properties.additionalDetails{}.value +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.targetResources{}.type +- properties.userAgent +- punct +- resourceId +- resultDescription +- resultSignature +- source +- sourcetype +- splunk_server +- tag +- tag::eventtype +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-10-27T16:14:14.9747033Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam", "operationName": "Consent to application", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature": diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml index 6c329d8872..72d6e69e4c 100644 --- a/data_sources/azure_active_directory_disable_strong_authentication.yml +++ b/data_sources/azure_active_directory_disable_strong_authentication.yml @@ -6,67 +6,67 @@ author: Patrick Bareiss, Splunk description: Logs an event when strong authentication methods are disabled in Azure Active Directory. mitre_components: - - User Account Authentication - - User Account Modification - - Cloud Service Modification +- User Account Authentication +- User Account Modification +- Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Disable Strong Authentication supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.targetResources{}.type - - properties.targetResources{}.userPrincipalName - - properties.userAgent - - punct - - resourceId - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.targetResources{}.type +- properties.targetResources{}.userPrincipalName +- properties.userAgent +- punct +- resourceId +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-07-11T00:01:35.0251899Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Disable Strong Authentication", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml index 2e3380277d..5d5105fbcb 100644 --- a/data_sources/azure_active_directory_enable_account.yml +++ b/data_sources/azure_active_directory_enable_account.yml @@ -5,68 +5,68 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Active Directory account is enabled. mitre_components: - - User Account Modification - - User Account Authentication - - User Account Metadata +- User Account Modification +- User Account Authentication +- User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Enable account supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.targetResources{}.type - - properties.targetResources{}.userPrincipalName - - properties.userAgent - - punct - - resourceId - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.targetResources{}.type +- properties.targetResources{}.userPrincipalName +- properties.userAgent +- punct +- resourceId +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-07-24T14:28:15.2223487Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Enable account", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs": diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml index 08726897f3..a7f115be50 100644 --- a/data_sources/azure_active_directory_invite_external_user.yml +++ b/data_sources/azure_active_directory_invite_external_user.yml @@ -6,67 +6,67 @@ author: Patrick Bareiss, Splunk description: Logs an event when an external user is invited to join an Azure Active Directory tenant. mitre_components: - - Active Directory Object Creation - - User Account Creation - - User Account Authentication +- Active Directory Object Creation +- User Account Creation +- User Account Authentication source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Invite external user supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.additionalDetails{}.key - - properties.additionalDetails{}.value - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.type - - properties.targetResources{}.userPrincipalName - - properties.userAgent - - punct - - resourceId - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.additionalDetails{}.key +- properties.additionalDetails{}.value +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.type +- properties.targetResources{}.userPrincipalName +- properties.userAgent +- punct +- resourceId +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-07-13T00:29:59.5100003Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Invite external user", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml index 54208cb250..9e2eacf0f5 100644 --- a/data_sources/azure_active_directory_reset_password_(by_admin).yml +++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml @@ -6,68 +6,68 @@ author: Patrick Bareiss, Splunk description: Logs an event when an admin resets a user's password in Azure Active Directory. mitre_components: - - User Account Authentication - - User Account Modification - - Active Directory Object Modification +- User Account Authentication +- User Account Modification +- Active Directory Object Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Reset password (by admin) supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.additionalDetails{}.key - - properties.additionalDetails{}.value - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.type - - properties.targetResources{}.userPrincipalName - - properties.userAgent - - punct - - resourceId - - resultDescription - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.additionalDetails{}.key +- properties.additionalDetails{}.value +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.type +- properties.targetResources{}.userPrincipalName +- properties.userAgent +- punct +- resourceId +- resultDescription +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-07-24T14:28:55.0648789Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Reset password (by admin)", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml index c29183d14e..939da08d9f 100644 --- a/data_sources/azure_active_directory_set_domain_authentication.yml +++ b/data_sources/azure_active_directory_set_domain_authentication.yml @@ -6,68 +6,68 @@ author: Patrick Bareiss, Splunk description: Logs an event when the authentication method for a domain in Azure Active Directory is set or modified. mitre_components: - - Active Directory Object Modification - - User Account Authentication - - Cloud Service Modification +- Active Directory Object Modification +- User Account Authentication +- Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Set domain authentication supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.additionalDetails{}.key - - properties.additionalDetails{}.value - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.userAgent - - punct - - resourceId - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.additionalDetails{}.key +- properties.additionalDetails{}.value +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.userAgent +- punct +- resourceId +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-07-26T13:44:59.0372448Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Set domain authentication", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml index d5ed7fa94d..4b8e5c152f 100644 --- a/data_sources/azure_active_directory_sign_in_activity.yml +++ b/data_sources/azure_active_directory_sign_in_activity.yml @@ -6,118 +6,118 @@ author: Patrick Bareiss, Splunk description: Logs an event when a user attempts to sign into Azure Active Directory, capturing authentication details and outcomes. mitre_components: - - User Account Authentication - - Logon Session Creation - - User Account Metadata +- User Account Authentication +- Logon Session Creation +- User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Sign-in activity supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - identity - - index - - linecount - - location - - operationName - - operationVersion - - properties.alternateSignInName - - properties.appDisplayName - - properties.appId - - properties.appServicePrincipalId - - properties.authenticationDetails{}.RequestSequence - - properties.authenticationDetails{}.StatusSequence - - properties.authenticationDetails{}.authenticationMethod - - properties.authenticationDetails{}.authenticationMethodDetail - - properties.authenticationDetails{}.authenticationStepDateTime - - properties.authenticationDetails{}.authenticationStepRequirement - - properties.authenticationDetails{}.authenticationStepResultDetail - - properties.authenticationDetails{}.succeeded - - properties.authenticationProcessingDetails{}.key - - properties.authenticationProcessingDetails{}.value - - properties.authenticationProtocol - - properties.authenticationRequirement - - properties.authenticationRequirementPolicies{}.detail - - properties.authenticationRequirementPolicies{}.requirementProvider - - properties.autonomousSystemNumber - - properties.clientAppUsed - - properties.clientCredentialType - - properties.conditionalAccessStatus - - properties.correlationId - - properties.createdDateTime - - properties.crossTenantAccessType - - properties.deviceDetail.deviceId - - properties.deviceDetail.operatingSystem - - properties.flaggedForReview - - properties.homeTenantId - - properties.id - - properties.incomingTokenType - - properties.ipAddress - - properties.isInteractive - - properties.isTenantRestricted - - properties.location.city - - properties.location.countryOrRegion - - properties.location.geoCoordinates.latitude - - properties.location.geoCoordinates.longitude - - properties.location.state - - properties.originalRequestId - - properties.originalTransferMethod - - properties.processingTimeInMilliseconds - - properties.resourceDisplayName - - properties.resourceId - - properties.resourceServicePrincipalId - - properties.resourceTenantId - - properties.riskDetail - - properties.riskLevelAggregated - - properties.riskLevelDuringSignIn - - properties.riskState - - properties.rngcStatus - - properties.servicePrincipalId - - properties.signInIdentifier - - properties.signInTokenProtectionStatus - - properties.ssoExtensionVersion - - properties.status.additionalDetails - - properties.status.errorCode - - properties.status.failureReason - - properties.tenantId - - properties.tokenIssuerName - - properties.tokenIssuerType - - properties.uniqueTokenIdentifier - - properties.userAgent - - properties.userDisplayName - - properties.userId - - properties.userPrincipalName - - properties.userType - - punct - - resourceId - - resultDescription - - resultSignature - - resultType - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- identity +- index +- linecount +- location +- operationName +- operationVersion +- properties.alternateSignInName +- properties.appDisplayName +- properties.appId +- properties.appServicePrincipalId +- properties.authenticationDetails{}.RequestSequence +- properties.authenticationDetails{}.StatusSequence +- properties.authenticationDetails{}.authenticationMethod +- properties.authenticationDetails{}.authenticationMethodDetail +- properties.authenticationDetails{}.authenticationStepDateTime +- properties.authenticationDetails{}.authenticationStepRequirement +- properties.authenticationDetails{}.authenticationStepResultDetail +- properties.authenticationDetails{}.succeeded +- properties.authenticationProcessingDetails{}.key +- properties.authenticationProcessingDetails{}.value +- properties.authenticationProtocol +- properties.authenticationRequirement +- properties.authenticationRequirementPolicies{}.detail +- properties.authenticationRequirementPolicies{}.requirementProvider +- properties.autonomousSystemNumber +- properties.clientAppUsed +- properties.clientCredentialType +- properties.conditionalAccessStatus +- properties.correlationId +- properties.createdDateTime +- properties.crossTenantAccessType +- properties.deviceDetail.deviceId +- properties.deviceDetail.operatingSystem +- properties.flaggedForReview +- properties.homeTenantId +- properties.id +- properties.incomingTokenType +- properties.ipAddress +- properties.isInteractive +- properties.isTenantRestricted +- properties.location.city +- properties.location.countryOrRegion +- properties.location.geoCoordinates.latitude +- properties.location.geoCoordinates.longitude +- properties.location.state +- properties.originalRequestId +- properties.originalTransferMethod +- properties.processingTimeInMilliseconds +- properties.resourceDisplayName +- properties.resourceId +- properties.resourceServicePrincipalId +- properties.resourceTenantId +- properties.riskDetail +- properties.riskLevelAggregated +- properties.riskLevelDuringSignIn +- properties.riskState +- properties.rngcStatus +- properties.servicePrincipalId +- properties.signInIdentifier +- properties.signInTokenProtectionStatus +- properties.ssoExtensionVersion +- properties.status.additionalDetails +- properties.status.errorCode +- properties.status.failureReason +- properties.tenantId +- properties.tokenIssuerName +- properties.tokenIssuerType +- properties.uniqueTokenIdentifier +- properties.userAgent +- properties.userDisplayName +- properties.userId +- properties.userPrincipalName +- properties.userType +- punct +- resourceId +- resultDescription +- resultSignature +- resultType +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-10-24T20:13:31.4449614Z", "resourceId": "/tenants/887c9144-28b8-431b-885b-764fdeefcf62/providers/Microsoft.aadiam", "operationName": "Sign-in activity", "operationVersion": "1.0", "category": "SignInLogs", "tenantId": "887c9144-28b8-431b-885b-764fdeefcf62", "resultType": "50076", "resultSignature": diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml index fe57e659f8..e82edafcca 100644 --- a/data_sources/azure_active_directory_update_application.yml +++ b/data_sources/azure_active_directory_update_application.yml @@ -6,68 +6,68 @@ author: Patrick Bareiss, Splunk description: Logs an event when an application in Azure Active Directory is updated, such as changes to its settings or permissions. mitre_components: - - Service Modification - - User Account Modification - - Cloud Service Modification +- Service Modification +- User Account Modification +- Cloud Service Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Update application supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.additionalDetails{}.key - - properties.additionalDetails{}.value - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.targetResources{}.type - - properties.userAgent - - punct - - resourceId - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.additionalDetails{}.key +- properties.additionalDetails{}.value +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.targetResources{}.type +- properties.userAgent +- punct +- resourceId +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2024-01-29T21:31:03.0102031Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam", "operationName": "Update application", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature": "None", "durationMs": diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml index 34e141f92e..54dd3ca2a9 100644 --- a/data_sources/azure_active_directory_update_authorization_policy.yml +++ b/data_sources/azure_active_directory_update_authorization_policy.yml @@ -6,69 +6,69 @@ author: Patrick Bareiss, Splunk description: Logs an event when an authorization policy is updated in Azure Active Directory. mitre_components: - - User Account Modification - - Group Modification - - Active Directory Object Modification +- User Account Modification +- Group Modification +- Active Directory Object Modification source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Update authorization policy supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.additionalDetails{}.key - - properties.additionalDetails{}.value - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.targetResources{}.type - - properties.userAgent - - punct - - resourceId - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.additionalDetails{}.key +- properties.additionalDetails{}.value +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.targetResources{}.type +- properties.userAgent +- punct +- resourceId +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-10-26T19:22:20.2814027Z", "resourceId": "/tenants/5f210575-a69b-41a7-b623-3f6d79ccd432/providers/Microsoft.aadiam", "operationName": "Update authorization policy", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "5f210575-a69b-41a7-b623-3f6d79ccd432", "resultSignature": diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml index 3bc111e209..26951a9695 100644 --- a/data_sources/azure_active_directory_update_user.yml +++ b/data_sources/azure_active_directory_update_user.yml @@ -5,69 +5,69 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a user account is updated in Azure Active Directory. mitre_components: - - User Account Modification - - User Account Metadata +- User Account Modification +- User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: Update user supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.additionalDetails{}.key - - properties.additionalDetails{}.value - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.modifiedProperties{}.displayName - - properties.targetResources{}.modifiedProperties{}.newValue - - properties.targetResources{}.modifiedProperties{}.oldValue - - properties.targetResources{}.type - - properties.targetResources{}.userPrincipalName - - properties.userAgent - - punct - - resourceId - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.additionalDetails{}.key +- properties.additionalDetails{}.value +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.modifiedProperties{}.displayName +- properties.targetResources{}.modifiedProperties{}.newValue +- properties.targetResources{}.modifiedProperties{}.oldValue +- properties.targetResources{}.type +- properties.targetResources{}.userPrincipalName +- properties.userAgent +- punct +- resourceId +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-07-24T14:28:15.2233481Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", "operationName": "Update user", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs": diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml index db1c5af928..3a2ba69d86 100644 --- a/data_sources/azure_active_directory_user_registered_security_info.yml +++ b/data_sources/azure_active_directory_user_registered_security_info.yml @@ -6,65 +6,65 @@ author: Patrick Bareiss, Splunk description: Logs an event when a user registers or updates their security information in Azure Active Directory. mitre_components: - - User Account Modification - - User Account Metadata +- User Account Modification +- User Account Metadata source: Azure AD sourcetype: azure:monitor:aad separator: operationName separator_value: User registered security info supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - Level - - callerIpAddress - - category - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - durationMs - - host - - index - - linecount - - operationName - - operationVersion - - properties.activityDateTime - - properties.activityDisplayName - - properties.category - - properties.correlationId - - properties.id - - properties.initiatedBy.user.displayName - - properties.initiatedBy.user.id - - properties.initiatedBy.user.ipAddress - - properties.initiatedBy.user.userPrincipalName - - properties.loggedByService - - properties.operationType - - properties.result - - properties.resultReason - - properties.targetResources{}.displayName - - properties.targetResources{}.id - - properties.targetResources{}.type - - properties.targetResources{}.userPrincipalName - - properties.userAgent - - punct - - resourceId - - resultDescription - - resultSignature - - source - - sourcetype - - splunk_server - - tenantId - - time - - timeendpos - - timestartpos +- _time +- Level +- callerIpAddress +- category +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- durationMs +- host +- index +- linecount +- operationName +- operationVersion +- properties.activityDateTime +- properties.activityDisplayName +- properties.category +- properties.correlationId +- properties.id +- properties.initiatedBy.user.displayName +- properties.initiatedBy.user.id +- properties.initiatedBy.user.ipAddress +- properties.initiatedBy.user.userPrincipalName +- properties.loggedByService +- properties.operationType +- properties.result +- properties.resultReason +- properties.targetResources{}.displayName +- properties.targetResources{}.id +- properties.targetResources{}.type +- properties.targetResources{}.userPrincipalName +- properties.userAgent +- punct +- resourceId +- resultDescription +- resultSignature +- source +- sourcetype +- splunk_server +- tenantId +- time +- timeendpos +- timestartpos example_log: '{"time": "2023-01-30T21:11:30.8690619Z", "resourceId": "/tenants/91da745f-8abb-4a7d-ba94-5667c6f9e01a/providers/Microsoft.aadiam", "operationName": "User registered security info", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "91da745f-8abb-4a7d-ba94-5667c6f9e01a", "resultSignature": diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml index d16b39fe67..65f6f7e767 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml @@ -5,106 +5,106 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Automation account is created or updated. mitre_components: - - Cloud Service Creation - - Cloud Service Modification - - Cloud Service Metadata +- Cloud Service Creation +- Cloud Service Modification +- Cloud Service Metadata source: mscs:azure:audit sourcetype: mscs:azure:audit separator: operationName.localizedValue separator_value: Create or Update an Azure Automation account supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - authorization.action - - authorization.scope - - caller - - channels - - claims.aio - - claims.altsecid - - claims.appid - - claims.appidacr - - claims.aud - - claims.exp - - claims.groups - - claims.http://schemas.microsoft.com/claims/authnclassreference - - claims.http://schemas.microsoft.com/claims/authnmethodsreferences - - claims.http://schemas.microsoft.com/identity/claims/identityprovider - - claims.http://schemas.microsoft.com/identity/claims/objectidentifier - - claims.http://schemas.microsoft.com/identity/claims/scope - - claims.http://schemas.microsoft.com/identity/claims/tenantid - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname - - claims.iat - - claims.ipaddr - - claims.iss - - claims.name - - claims.nbf - - claims.puid - - claims.rh - - claims.uti - - claims.ver - - claims.wids - - claims.xms_tcdt - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - eventDataId - - eventName.localizedValue - - eventName.value - - eventSource.localizedValue - - eventSource.value - - eventTimestamp - - host - - id - - index - - level - - linecount - - object - - object_id - - object_path - - operationId - - operationName.localizedValue - - operationName.value - - product - - properties.entity - - properties.eventCategory - - properties.hierarchy - - properties.message - - punct - - resourceGroupName - - resourceProviderName.localizedValue - - resourceProviderName.value - - resourceUri - - source - - sourcetype - - splunk_server - - status - - status.localizedValue - - status.value - - subStatus.value - - submissionTimestamp - - subscriptionId - - timeendpos - - timestartpos - - user - - user_name - - vendor - - vendor_product - - vendor_res_code +- _time +- authorization.action +- authorization.scope +- caller +- channels +- claims.aio +- claims.altsecid +- claims.appid +- claims.appidacr +- claims.aud +- claims.exp +- claims.groups +- claims.http://schemas.microsoft.com/claims/authnclassreference +- claims.http://schemas.microsoft.com/claims/authnmethodsreferences +- claims.http://schemas.microsoft.com/identity/claims/identityprovider +- claims.http://schemas.microsoft.com/identity/claims/objectidentifier +- claims.http://schemas.microsoft.com/identity/claims/scope +- claims.http://schemas.microsoft.com/identity/claims/tenantid +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname +- claims.iat +- claims.ipaddr +- claims.iss +- claims.name +- claims.nbf +- claims.puid +- claims.rh +- claims.uti +- claims.ver +- claims.wids +- claims.xms_tcdt +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- eventDataId +- eventName.localizedValue +- eventName.value +- eventSource.localizedValue +- eventSource.value +- eventTimestamp +- host +- id +- index +- level +- linecount +- object +- object_id +- object_path +- operationId +- operationName.localizedValue +- operationName.value +- product +- properties.entity +- properties.eventCategory +- properties.hierarchy +- properties.message +- punct +- resourceGroupName +- resourceProviderName.localizedValue +- resourceProviderName.value +- resourceUri +- source +- sourcetype +- splunk_server +- status +- status.localizedValue +- status.value +- subStatus.value +- submissionTimestamp +- subscriptionId +- timeendpos +- timestartpos +- user +- user_name +- vendor +- vendor_product +- vendor_res_code example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/write", "scope": "/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount"}, "caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/", diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml index 8522e7ab79..f9de2d68b5 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml @@ -6,105 +6,105 @@ author: Patrick Bareiss, Splunk description: Logs an event when a new Azure Automation Runbook is created or an existing one is updated. mitre_components: - - Scheduled Job Modification - - Scheduled Job Creation +- Scheduled Job Modification +- Scheduled Job Creation source: mscs:azure:audit sourcetype: mscs:azure:audit separator: operationName.localizedValue separator_value: Create or Update an Azure Automation Runbook supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - authorization.action - - authorization.scope - - caller - - channels - - claims.aio - - claims.altsecid - - claims.appid - - claims.appidacr - - claims.aud - - claims.exp - - claims.groups - - claims.http://schemas.microsoft.com/claims/authnclassreference - - claims.http://schemas.microsoft.com/claims/authnmethodsreferences - - claims.http://schemas.microsoft.com/identity/claims/identityprovider - - claims.http://schemas.microsoft.com/identity/claims/objectidentifier - - claims.http://schemas.microsoft.com/identity/claims/scope - - claims.http://schemas.microsoft.com/identity/claims/tenantid - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname - - claims.iat - - claims.ipaddr - - claims.iss - - claims.name - - claims.nbf - - claims.puid - - claims.rh - - claims.uti - - claims.ver - - claims.wids - - claims.xms_tcdt - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - eventDataId - - eventName.localizedValue - - eventName.value - - eventSource.localizedValue - - eventSource.value - - eventTimestamp - - host - - id - - index - - level - - linecount - - object - - object_id - - object_path - - operationId - - operationName.localizedValue - - operationName.value - - product - - properties.entity - - properties.eventCategory - - properties.hierarchy - - properties.message - - punct - - resourceGroupName - - resourceProviderName.localizedValue - - resourceProviderName.value - - resourceUri - - source - - sourcetype - - splunk_server - - status - - status.localizedValue - - status.value - - subStatus.value - - submissionTimestamp - - subscriptionId - - timeendpos - - timestartpos - - user - - user_name - - vendor - - vendor_product - - vendor_res_code +- _time +- authorization.action +- authorization.scope +- caller +- channels +- claims.aio +- claims.altsecid +- claims.appid +- claims.appidacr +- claims.aud +- claims.exp +- claims.groups +- claims.http://schemas.microsoft.com/claims/authnclassreference +- claims.http://schemas.microsoft.com/claims/authnmethodsreferences +- claims.http://schemas.microsoft.com/identity/claims/identityprovider +- claims.http://schemas.microsoft.com/identity/claims/objectidentifier +- claims.http://schemas.microsoft.com/identity/claims/scope +- claims.http://schemas.microsoft.com/identity/claims/tenantid +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname +- claims.iat +- claims.ipaddr +- claims.iss +- claims.name +- claims.nbf +- claims.puid +- claims.rh +- claims.uti +- claims.ver +- claims.wids +- claims.xms_tcdt +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- eventDataId +- eventName.localizedValue +- eventName.value +- eventSource.localizedValue +- eventSource.value +- eventTimestamp +- host +- id +- index +- level +- linecount +- object +- object_id +- object_path +- operationId +- operationName.localizedValue +- operationName.value +- product +- properties.entity +- properties.eventCategory +- properties.hierarchy +- properties.message +- punct +- resourceGroupName +- resourceProviderName.localizedValue +- resourceProviderName.value +- resourceUri +- source +- sourcetype +- splunk_server +- status +- status.localizedValue +- status.value +- subStatus.value +- submissionTimestamp +- subscriptionId +- timeendpos +- timestartpos +- user +- user_name +- vendor +- vendor_product +- vendor_res_code example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/runbooks/write", "scope": "/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourceGroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook"}, "caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/", diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml index eb21ed90a8..6668b0a88d 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml @@ -5,115 +5,115 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a webhook is created or updated in Azure Automation. mitre_components: - - Scheduled Job Modification - - Cloud Service Modification - - Scheduled Job Metadata +- Scheduled Job Modification +- Cloud Service Modification +- Scheduled Job Metadata source: mscs:azure:audit sourcetype: mscs:azure:audit separator: operationName.localizedValue separator_value: Create or Update an Azure Automation webhook supported_TA: - - name: Splunk Add-on for Microsoft Cloud Services - url: https://splunkbase.splunk.com/app/3110 - version: 5.4.1 +- name: Splunk Add-on for Microsoft Cloud Services + url: https://splunkbase.splunk.com/app/3110 + version: 5.4.1 fields: - - _time - - authorization.action - - authorization.scope - - caller - - channels - - claims.aio - - claims.altsecid - - claims.appid - - claims.appidacr - - claims.aud - - claims.exp - - claims.groups - - claims.http://schemas.microsoft.com/claims/authnclassreference - - claims.http://schemas.microsoft.com/claims/authnmethodsreferences - - claims.http://schemas.microsoft.com/identity/claims/identityprovider - - claims.http://schemas.microsoft.com/identity/claims/objectidentifier - - claims.http://schemas.microsoft.com/identity/claims/scope - - claims.http://schemas.microsoft.com/identity/claims/tenantid - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier - - claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname - - claims.iat - - claims.ipaddr - - claims.iss - - claims.name - - claims.nbf - - claims.puid - - claims.rh - - claims.uti - - claims.ver - - claims.wids - - claims.xms_tcdt - - correlationId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - eventDataId - - eventName.localizedValue - - eventName.value - - eventSource.localizedValue - - eventSource.value - - eventTimestamp - - host - - httpRequest.clientIpAddress - - httpRequest.clientRequestId - - httpRequest.method - - id - - index - - level - - linecount - - object - - object_id - - object_path - - operationId - - operationName.localizedValue - - operationName.value - - product - - properties.entity - - properties.eventCategory - - properties.hierarchy - - properties.message - - properties.serviceRequestId - - properties.statusCode - - punct - - resourceGroupName - - resourceProviderName.localizedValue - - resourceProviderName.value - - resourceUri - - result - - result_id - - source - - sourcetype - - splunk_server - - src - - status - - status.localizedValue - - status.value - - subStatus.localizedValue - - subStatus.value - - submissionTimestamp - - subscriptionId - - timeendpos - - timestartpos - - user - - user_name - - vendor - - vendor_product - - vendor_res_code +- _time +- authorization.action +- authorization.scope +- caller +- channels +- claims.aio +- claims.altsecid +- claims.appid +- claims.appidacr +- claims.aud +- claims.exp +- claims.groups +- claims.http://schemas.microsoft.com/claims/authnclassreference +- claims.http://schemas.microsoft.com/claims/authnmethodsreferences +- claims.http://schemas.microsoft.com/identity/claims/identityprovider +- claims.http://schemas.microsoft.com/identity/claims/objectidentifier +- claims.http://schemas.microsoft.com/identity/claims/scope +- claims.http://schemas.microsoft.com/identity/claims/tenantid +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier +- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname +- claims.iat +- claims.ipaddr +- claims.iss +- claims.name +- claims.nbf +- claims.puid +- claims.rh +- claims.uti +- claims.ver +- claims.wids +- claims.xms_tcdt +- correlationId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- eventDataId +- eventName.localizedValue +- eventName.value +- eventSource.localizedValue +- eventSource.value +- eventTimestamp +- host +- httpRequest.clientIpAddress +- httpRequest.clientRequestId +- httpRequest.method +- id +- index +- level +- linecount +- object +- object_id +- object_path +- operationId +- operationName.localizedValue +- operationName.value +- product +- properties.entity +- properties.eventCategory +- properties.hierarchy +- properties.message +- properties.serviceRequestId +- properties.statusCode +- punct +- resourceGroupName +- resourceProviderName.localizedValue +- resourceProviderName.value +- resourceUri +- result +- result_id +- source +- sourcetype +- splunk_server +- src +- status +- status.localizedValue +- status.value +- subStatus.localizedValue +- subStatus.value +- submissionTimestamp +- subscriptionId +- timeendpos +- timestartpos +- user +- user_name +- vendor +- vendor_product +- vendor_res_code example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/webhooks/write", "scope": "/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook"}, "caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/", diff --git a/data_sources/bro_conn.yml b/data_sources/bro_conn.yml index 992da75275..1d8e4110c3 100644 --- a/data_sources/bro_conn.yml +++ b/data_sources/bro_conn.yml @@ -6,11 +6,10 @@ author: Jacob Delgado, SnapAttack description: Logs network connection metadata captured by Zeek (formerly Bro), including details such as source and destination IPs, ports, connection state, and protocol. mitre_components: - - Network Connection Creation - - Network Traffic Flow - - Response Metadata - - Application Log Content +- Network Connection Creation +- Network Traffic Flow +- Response Metadata +- Application Log Content source: bro:conn:json sourcetype: bro:conn:json supported_TA: [] - diff --git a/data_sources/bro_dns.yml b/data_sources/bro_dns.yml index 7d878c681b..b4deae7a6c 100644 --- a/data_sources/bro_dns.yml +++ b/data_sources/bro_dns.yml @@ -6,11 +6,11 @@ author: Jacob Delgado, SnapAttack description: Logs DNS queries and responses captured by Zeek (formerly Bro), including details such as queried domains, resolved IPs, query types, and response codes. mitre_components: - - Active DNS - - Passive DNS - - Network Traffic Content - - Network Traffic Flow - - Response Metadata +- Active DNS +- Passive DNS +- Network Traffic Content +- Network Traffic Flow +- Response Metadata source: bro:dns:json sourcetype: bro:dns:json supported_TA: [] diff --git a/data_sources/bro_files.yml b/data_sources/bro_files.yml index 4cb84af9fa..20121d2067 100644 --- a/data_sources/bro_files.yml +++ b/data_sources/bro_files.yml @@ -7,11 +7,11 @@ description: Logs metadata about files transferred over the network captured by (formerly Bro), including details such as file names, hashes, MIME types, and transfer protocols. mitre_components: - - File Metadata - - Network Traffic Content - - Network Traffic Flow - - Response Metadata - - Application Log Content +- File Metadata +- Network Traffic Content +- Network Traffic Flow +- Response Metadata +- Application Log Content source: bro:files:json sourcetype: bro:files:json supported_TA: [] diff --git a/data_sources/bro_http.yml b/data_sources/bro_http.yml index 59232b529e..e8e25150dc 100644 --- a/data_sources/bro_http.yml +++ b/data_sources/bro_http.yml @@ -6,11 +6,11 @@ author: Patrick Bareiss, Splunk description: Logs HTTP traffic analyzed by Zeek (formerly Bro), including details such as request methods, URLs, user agents, response codes, and headers. mitre_components: - - Network Traffic Content - - Network Traffic Flow - - Response Content - - Response Metadata - - Application Log Content +- Network Traffic Content +- Network Traffic Flow +- Response Content +- Response Metadata +- Application Log Content source: bro:http:json sourcetype: bro:http:json supported_TA: [] diff --git a/data_sources/bro_loaded_scripts.yml b/data_sources/bro_loaded_scripts.yml index be17c3a7e1..2b9669bac3 100644 --- a/data_sources/bro_loaded_scripts.yml +++ b/data_sources/bro_loaded_scripts.yml @@ -6,10 +6,10 @@ author: Jacob Delgado, SnapAttack description: Logs details about the scripts loaded by Zeek (formerly Bro) during initialization, including script names and paths. mitre_components: - - Application Log Content - - Configuration Modification - - Script Execution - - OS API Execution +- Application Log Content +- Configuration Modification +- Script Execution +- OS API Execution source: bro:loaded_scripts:json sourcetype: bro:loaded_scripts:json supported_TA: [] diff --git a/data_sources/bro_ntp.yml b/data_sources/bro_ntp.yml index b849d5d5db..727dfc5bfa 100644 --- a/data_sources/bro_ntp.yml +++ b/data_sources/bro_ntp.yml @@ -6,10 +6,10 @@ author: Jacob Delgado, SnapAttack description: Logs Network Time Protocol (NTP) activity captured by Zeek (formerly Bro), including details such as NTP requests, responses, and server metadata. mitre_components: - - Network Traffic Flow - - Network Traffic Content - - Response Metadata - - Application Log Content +- Network Traffic Flow +- Network Traffic Content +- Response Metadata +- Application Log Content source: bro:ntp:json sourcetype: bro:ntp:json supported_TA: [] diff --git a/data_sources/bro_ocsp.yml b/data_sources/bro_ocsp.yml index 00e8942e83..316e75d352 100644 --- a/data_sources/bro_ocsp.yml +++ b/data_sources/bro_ocsp.yml @@ -6,11 +6,11 @@ author: Jacob Delgado, SnapAttack description: Logs Online Certificate Status Protocol (OCSP) activity captured by Zeek (formerly Bro), including details such as certificate validation requests and responses. mitre_components: - - Certificate Registration - - Network Traffic Flow - - Network Traffic Content - - Response Metadata - - Application Log Content +- Certificate Registration +- Network Traffic Flow +- Network Traffic Content +- Response Metadata +- Application Log Content source: bro:ocsp:json sourcetype: bro:ocsp:json supported_TA: [] diff --git a/data_sources/bro_ssl.yml b/data_sources/bro_ssl.yml index a2c17d7261..b138786a0f 100644 --- a/data_sources/bro_ssl.yml +++ b/data_sources/bro_ssl.yml @@ -6,11 +6,11 @@ author: Jacob Delgado, SnapAttack description: Logs SSL/TLS handshake and session details captured by Zeek (formerly Bro), including certificates, cipher suites, and session information. mitre_components: - - Certificate Registration - - Network Traffic Flow - - Network Traffic Content - - Response Metadata - - Application Log Content +- Certificate Registration +- Network Traffic Flow +- Network Traffic Content +- Response Metadata +- Application Log Content source: bro:ssl:json sourcetype: bro:ssl:json supported_TA: [] diff --git a/data_sources/bro_weird.yml b/data_sources/bro_weird.yml index 1fc72ac2de..4d46c68d74 100644 --- a/data_sources/bro_weird.yml +++ b/data_sources/bro_weird.yml @@ -6,11 +6,11 @@ author: Jacob Delgado, SnapAttack description: Logs anomalous or unexpected network behaviors identified by Zeek (formerly Bro), including protocol violations and unusual traffic patterns. mitre_components: - - Network Traffic Flow - - Network Traffic Content - - Response Metadata - - Application Log Content - - Host Status +- Network Traffic Flow +- Network Traffic Content +- Response Metadata +- Application Log Content +- Host Status source: bro:weird:json sourcetype: bro:weird:json supported_TA: [] diff --git a/data_sources/bro_x509.yml b/data_sources/bro_x509.yml index 3d9d08adf7..3f23109ebd 100644 --- a/data_sources/bro_x509.yml +++ b/data_sources/bro_x509.yml @@ -6,11 +6,11 @@ author: Jacob Delgado, SnapAttack description: Logs details about X.509 certificates observed in network traffic captured by Zeek (formerly Bro), including certificate fields, validity periods, and issuers. mitre_components: - - Certificate Registration - - Network Traffic Content - - Response Metadata - - Application Log Content - - Host Status +- Certificate Registration +- Network Traffic Content +- Response Metadata +- Application Log Content +- Host Status source: bro:x509:json sourcetype: bro:x509:json supported_TA: [] diff --git a/data_sources/circleci.yml b/data_sources/circleci.yml index b07ad95c84..dc231daca7 100644 --- a/data_sources/circleci.yml +++ b/data_sources/circleci.yml @@ -6,70 +6,70 @@ author: Patrick Bareiss, Splunk description: Logs activities related to CI/CD pipelines executed in CircleCI, including job execution, workflow progress, and configuration changes. mitre_components: - - Scheduled Job Execution - - Scheduled Job Metadata - - Application Log Content - - Configuration Modification - - Host Status +- Scheduled Job Execution +- Scheduled Job Metadata +- Application Log Content +- Configuration Modification +- Host Status source: circleci sourcetype: circleci supported_TA: - - name: App for CircleCI - url: https://splunkbase.splunk.com/app/5162 - version: 0.1.1 +- name: App for CircleCI + url: https://splunkbase.splunk.com/app/5162 + version: 0.1.1 fields: - - _time - - author_name - - avatar_url - - branch - - build_num - - build_time_millis - - build_url - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - eventtype - - fail_reason - - host - - index - - job_name - - job_time - - linecount - - owners{} - - project_slug - - punct - - queued_time - - reponame - - source - - sourcetype - - splunk_server - - start_time - - status - - stop_time - - tag - - tag::eventtype - - timedout - - timeendpos - - timestartpos - - username - - vcs.commit_time - - vcs.committer_name - - vcs.revision - - vcs.subject - - vcs.tag - - vcs.type - - vcs.url - - workflows.job_id - - workflows.job_name - - workflows.upstream_job_ids{} - - workflows.workflow_id - - workflows.workflow_name - - workflows.workspace_id +- _time +- author_name +- avatar_url +- branch +- build_num +- build_time_millis +- build_url +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- eventtype +- fail_reason +- host +- index +- job_name +- job_time +- linecount +- owners{} +- project_slug +- punct +- queued_time +- reponame +- source +- sourcetype +- splunk_server +- start_time +- status +- stop_time +- tag +- tag::eventtype +- timedout +- timeendpos +- timestartpos +- username +- vcs.commit_time +- vcs.committer_name +- vcs.revision +- vcs.subject +- vcs.tag +- vcs.type +- vcs.url +- workflows.job_id +- workflows.job_name +- workflows.upstream_job_ids{} +- workflows.workflow_id +- workflows.workflow_name +- workflows.workspace_id example_log: '{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z", "start_time": "2021-09-02T08:10:15.829Z", "queued_time": "2021-09-02T08:10:12.764Z", "job_name": "Unknown", "reponame": "devsecops_poc", "build_num": 94, "build_url": diff --git a/data_sources/crowdstrike_processrollup2.yml b/data_sources/crowdstrike_processrollup2.yml index d160cf8620..a038a6273f 100644 --- a/data_sources/crowdstrike_processrollup2.yml +++ b/data_sources/crowdstrike_processrollup2.yml @@ -7,109 +7,109 @@ description: Logs process-related activities captured by CrowdStrike, including creation, termination, and metadata such as hashes, parent processes, and command-line arguments. mitre_components: - - Process Creation - - Process Termination - - Process Metadata - - Command Execution - - OS API Execution +- Process Creation +- Process Termination +- Process Metadata +- Command Execution +- OS API Execution source: crowdstrike sourcetype: crowdstrike:events:sensor separator: event_simpleName separator_value: ProcessRollup2 supported_TA: - - name: Splunk Add-on for CrowdStrike FDR - url: https://splunkbase.splunk.com/app/5579 - version: 2.0.3 +- name: Splunk Add-on for CrowdStrike FDR + url: https://splunkbase.splunk.com/app/5579 + version: 2.0.3 fields: - - AuthenticationId - - AuthenticationId_meaning - - AuthenticodeHashData - - CommandLine - - ConfigBuild - - ConfigStateHash - - EffectiveTransmissionClass - - Entitlements - - EventOrigin - - ImageFileName - - ImageSubsystem - - ImageSubsystem_meaning - - IntegrityLevel - - IntegrityLevel_meaning - - MD5HashData - - ParentAuthenticationId - - ParentBaseFileName - - ParentProcessId - - ProcessCreateFlags - - ProcessEndTime - - ProcessParameterFlags - - ProcessParameterFlags_meaning - - ProcessStartTime - - ProcessSxsFlags - - ProcessSxsFlags_meaning - - RawProcessId - - SHA1HashData - - SHA256HashData - - SessionId - - SignInfoFlags - - SignInfoFlags_meaning - - SourceProcessId - - SourceThreadId - - Tags - - TargetProcessId - - TokenType - - TokenType_meaning - - UserSid - - WindowFlags - - WindowFlags_meaning - - action - - aid - - aid_city - - aid_computer_name - - aid_continent - - aid_country - - aid_machine_domain - - aid_os_version - - aid_ou - - aid_site_name - - aid_system_product_name - - aip - - cid - - dest - - event_ingest_time - - event_platform - - event_simpleName - - eventtype - - host_res_aid - - id - - os - - parent_process_exec - - parent_process_id - - parent_process_name - - process - - process_exec - - process_hash - - process_id - - process_integrity_level - - process_name - - process_path - - resolve_dest - - resolve_process_integrity_level - - tag - - timestamp - - user - - user_id - - vendor_product +- AuthenticationId +- AuthenticationId_meaning +- AuthenticodeHashData +- CommandLine +- ConfigBuild +- ConfigStateHash +- EffectiveTransmissionClass +- Entitlements +- EventOrigin +- ImageFileName +- ImageSubsystem +- ImageSubsystem_meaning +- IntegrityLevel +- IntegrityLevel_meaning +- MD5HashData +- ParentAuthenticationId +- ParentBaseFileName +- ParentProcessId +- ProcessCreateFlags +- ProcessEndTime +- ProcessParameterFlags +- ProcessParameterFlags_meaning +- ProcessStartTime +- ProcessSxsFlags +- ProcessSxsFlags_meaning +- RawProcessId +- SHA1HashData +- SHA256HashData +- SessionId +- SignInfoFlags +- SignInfoFlags_meaning +- SourceProcessId +- SourceThreadId +- Tags +- TargetProcessId +- TokenType +- TokenType_meaning +- UserSid +- WindowFlags +- WindowFlags_meaning +- action +- aid +- aid_city +- aid_computer_name +- aid_continent +- aid_country +- aid_machine_domain +- aid_os_version +- aid_ou +- aid_site_name +- aid_system_product_name +- aip +- cid +- dest +- event_ingest_time +- event_platform +- event_simpleName +- eventtype +- host_res_aid +- id +- os +- parent_process_exec +- parent_process_id +- parent_process_name +- process +- process_exec +- process_hash +- process_id +- process_integrity_level +- process_name +- process_path +- resolve_dest +- resolve_process_integrity_level +- tag +- timestamp +- user +- user_id +- vendor_product field_mappings: - - data_model: cim - data_set: Endpoint.Processes - mapping: - CommandLine: Processes.process - ImageFileName: Processes.process_path - ParentBaseFileName: Processes.parent_process_name - ParentProcessId: Processes.parent_process_id - RawProcessId: Processes.process_id - SHA256HashData: Processes.process_hash - UserSid: Processes.user +- data_model: cim + data_set: Endpoint.Processes + mapping: + CommandLine: Processes.process + ImageFileName: Processes.process_path + ParentBaseFileName: Processes.parent_process_name + ParentProcessId: Processes.parent_process_id + RawProcessId: Processes.process_id + SHA256HashData: Processes.process_hash + UserSid: Processes.user example_log: '{"LinkName":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\Windows PowerShell.lnk","ProcessCreateFlags":"67634196","IntegrityLevel":"12288","ParentProcessId":"5459598860","SourceProcessId":"5459598860","aip":"3.126.231.40","SHA1HashData":"0000000000000000000000000000000000000000","UserSid":"S-1-5-21-586445407-708991241-1829972403-500","event_platform":"Win","TokenType":"1","ProcessEndTime":"","AuthenticodeHashData":"3b98faafc17b47beb9027c437fceeafdf0624a1c","ParentBaseFileName":"explorer.exe","EventOrigin":"1","ImageSubsystem":"3","id":"e2210781-0e8f-47d2-bf6a-56d2c59f38ee","EffectiveTransmissionClass":"3","SessionId":"2","ShowWindowFlags":"1","Tags":"27, 40, 151, 874, 924, 12094627905582, 12094627906234, 211106232533012, 212205744161605, diff --git a/data_sources/crushftp.yml b/data_sources/crushftp.yml index 67968d73ef..597fda30f8 100644 --- a/data_sources/crushftp.yml +++ b/data_sources/crushftp.yml @@ -6,17 +6,17 @@ author: Patrick Bareiss, Splunk description: Logs activities related to file transfers and user interactions in CrushFTP, including file uploads, downloads, user authentication, and session details. mitre_components: - - File Access - - File Metadata - - User Account Authentication - - Logon Session Metadata - - Network Traffic Content +- File Access +- File Metadata +- User Account Authentication +- Logon Session Metadata +- Network Traffic Content source: crushftp sourcetype: crushftp:sessionlogs supported_TA: [] fields: - - _time - - _raw +- _time +- _raw example_log: 'SESSION|05/14/2024 17:36:21.859|[HTTPS:169_52326_sMa:anonymous:10.0.1.30] READ: *POST /WebInterface/function/?c2f=CmF1&command=zip&path=%3CINCLUDE%3Eusers/MainUsers/groups.XML%3C/INCLUDE%3E&names=/a HTTP/1.1*' diff --git a/data_sources/g_suite_drive.yml b/data_sources/g_suite_drive.yml index 0d56a7944d..dac656446b 100644 --- a/data_sources/g_suite_drive.yml +++ b/data_sources/g_suite_drive.yml @@ -6,49 +6,49 @@ author: Patrick Bareiss, Splunk description: Logs activities related to Google Drive in G Suite, including file creation, modification, sharing, and access details. mitre_components: - - File Access - - File Creation - - File Modification - - Cloud Storage Access - - Cloud Storage Metadata +- File Access +- File Creation +- File Modification +- Cloud Storage Access +- Cloud Storage Metadata source: http:gsuite sourcetype: gsuite:drive:json supported_TA: - - name: Splunk Add-on for Google Workspace - url: https://splunkbase.splunk.com/app/5556 - version: 3.0.2 +- name: Splunk Add-on for Google Workspace + url: https://splunkbase.splunk.com/app/5556 + version: 3.0.2 fields: - - _time - - email - - host - - index - - ip_address - - linecount - - name - - parameters.actor_is_collaborator_account - - parameters.billable - - parameters.doc_id - - parameters.doc_title - - parameters.doc_type - - parameters.is_encrypted - - parameters.new_value{} - - parameters.old_value{} - - parameters.old_visibility - - parameters.originating_app_id - - parameters.owner - - parameters.owner_is_shared_drive - - parameters.owner_is_team_drive - - parameters.primary_event - - parameters.target_user - - parameters.visibility - - parameters.visibility_change - - punct - - source - - sourcetype - - splunk_server - - timestamp - - type - - unique_id +- _time +- email +- host +- index +- ip_address +- linecount +- name +- parameters.actor_is_collaborator_account +- parameters.billable +- parameters.doc_id +- parameters.doc_title +- parameters.doc_type +- parameters.is_encrypted +- parameters.new_value{} +- parameters.old_value{} +- parameters.old_visibility +- parameters.originating_app_id +- parameters.owner +- parameters.owner_is_shared_drive +- parameters.owner_is_team_drive +- parameters.primary_event +- parameters.target_user +- parameters.visibility +- parameters.visibility_change +- punct +- source +- sourcetype +- splunk_server +- timestamp +- type +- unique_id example_log: '{"type": "acl_change", "name": "change_user_access", "parameters": {"primary_event": true, "billable": true, "visibility_change": "none", "target_user": "alberto@internal_test_email.com", "old_value": ["none"], "new_value": ["can_edit"], "old_visibility": "private", "doc_id": diff --git a/data_sources/g_suite_gmail.yml b/data_sources/g_suite_gmail.yml index c89e7087fb..1d698151df 100644 --- a/data_sources/g_suite_gmail.yml +++ b/data_sources/g_suite_gmail.yml @@ -6,87 +6,87 @@ author: Patrick Bareiss, Splunk description: Logs Gmail activities in G Suite, including email sending, receiving, and access details, as well as potential security-related events. mitre_components: - - Application Log Content - - User Account Metadata - - Email Metadata - - Cloud Service Metadata +- Application Log Content +- User Account Metadata +- Email Metadata +- Cloud Service Metadata source: http:gsuite sourcetype: gsuite:gmail:bigquery supported_TA: - - name: Splunk Add-on for Google Workspace - url: https://splunkbase.splunk.com/app/5556 - version: 3.0.2 +- name: Splunk Add-on for Google Workspace + url: https://splunkbase.splunk.com/app/5556 + version: 3.0.2 fields: - - _time - - action_type - - attachment{}.file_extension_type - - attachment{}.malware_family - - attachment{}.sha256 - - connection_info.authenticated_domain{}.name - - connection_info.authenticated_domain{}.type - - connection_info.client_host_zone - - connection_info.client_ip - - connection_info.dkim_pass - - connection_info.dmarc_pass - - connection_info.dmarc_published_domain - - connection_info.ip_geo_city - - connection_info.ip_geo_country - - connection_info.is_internal - - connection_info.is_intra_domain - - connection_info.smtp_in_connect_ip - - connection_info.smtp_out_connect_ip - - connection_info.smtp_out_remote_host - - connection_info.smtp_reply_code - - connection_info.smtp_response_reason - - connection_info.smtp_tls_cipher - - connection_info.smtp_tls_state - - connection_info.smtp_tls_version - - connection_info.smtp_user_agent_ip - - connection_info.spf_pass - - connection_info.tls_required_but_unavailable - - description - - destination{}.address - - destination{}.rcpt_response - - destination{}.selector - - destination{}.service - - destination{}.smime_decryption_success - - destination{}.smime_extraction_success - - destination{}.smime_parsing_success - - destination{}.smime_signature_verification_success - - eventtype - - flattened_destinations - - flattened_triggered_rule_info - - host - - index - - is_policy_check_for_sender - - is_spam - - linecount - - message_set{}.type - - num_message_attachments - - payload_size - - punct - - rfc2822_message_id - - smime_content_type - - smime_encrypt_message - - smime_extraction_success - - smime_packaging_success - - smime_sign_message - - smtp_relay_error - - source - - source.address - - source.from_header_address - - source.from_header_displayname - - source.selector - - source.service - - sourcetype - - spam_info - - splunk_server - - structured_policy_log_info - - subject - - tag - - tag::eventtype - - timestamp - - upload_error_category +- _time +- action_type +- attachment{}.file_extension_type +- attachment{}.malware_family +- attachment{}.sha256 +- connection_info.authenticated_domain{}.name +- connection_info.authenticated_domain{}.type +- connection_info.client_host_zone +- connection_info.client_ip +- connection_info.dkim_pass +- connection_info.dmarc_pass +- connection_info.dmarc_published_domain +- connection_info.ip_geo_city +- connection_info.ip_geo_country +- connection_info.is_internal +- connection_info.is_intra_domain +- connection_info.smtp_in_connect_ip +- connection_info.smtp_out_connect_ip +- connection_info.smtp_out_remote_host +- connection_info.smtp_reply_code +- connection_info.smtp_response_reason +- connection_info.smtp_tls_cipher +- connection_info.smtp_tls_state +- connection_info.smtp_tls_version +- connection_info.smtp_user_agent_ip +- connection_info.spf_pass +- connection_info.tls_required_but_unavailable +- description +- destination{}.address +- destination{}.rcpt_response +- destination{}.selector +- destination{}.service +- destination{}.smime_decryption_success +- destination{}.smime_extraction_success +- destination{}.smime_parsing_success +- destination{}.smime_signature_verification_success +- eventtype +- flattened_destinations +- flattened_triggered_rule_info +- host +- index +- is_policy_check_for_sender +- is_spam +- linecount +- message_set{}.type +- num_message_attachments +- payload_size +- punct +- rfc2822_message_id +- smime_content_type +- smime_encrypt_message +- smime_extraction_success +- smime_packaging_success +- smime_sign_message +- smtp_relay_error +- source +- source.address +- source.from_header_address +- source.from_header_displayname +- source.selector +- source.service +- sourcetype +- spam_info +- splunk_server +- structured_policy_log_info +- subject +- tag +- tag::eventtype +- timestamp +- upload_error_category example_log: '{"action_type": 10, "rfc2822_message_id": "", "subject": "New Order DHL0000001 - Dummy email for Detection Development", "payload_size": 6733, "source": {"address": "john@external_test_email.com", "service": "gmail-for-work", diff --git a/data_sources/github.yml b/data_sources/github.yml index 32ebea53e7..eaeabb40ed 100644 --- a/data_sources/github.yml +++ b/data_sources/github.yml @@ -6,207 +6,207 @@ author: Patrick Bareiss, Splunk description: Logs activities on GitHub repositories, including push events, pull requests, issue creation, and user authentication events. mitre_components: - - User Account Authentication - - Configuration Modification - - Application Log Content - - User Account Metadata - - Scheduled Job Metadata +- User Account Authentication +- Configuration Modification +- Application Log Content +- User Account Metadata +- Scheduled Job Metadata source: github sourcetype: aws:firehose:json supported_TA: - - name: Splunk Add-on for Github - url: https://splunkbase.splunk.com/app/6254 - version: 3.1.0 +- name: Splunk Add-on for Github + url: https://splunkbase.splunk.com/app/6254 + version: 3.1.0 fields: - - _time - - action - - host - - index - - linecount - - meta - - punct - - source - - sourcetype - - splunk_server - - timestamp - - workflow_run.actor.avatar_url - - workflow_run.actor.events_url - - workflow_run.actor.followers_url - - workflow_run.actor.following_url - - workflow_run.actor.gists_url - - workflow_run.actor.gravatar_id - - workflow_run.actor.html_url - - workflow_run.actor.id - - workflow_run.actor.login - - workflow_run.actor.node_id - - workflow_run.actor.organizations_url - - workflow_run.actor.received_events_url - - workflow_run.actor.repos_url - - workflow_run.actor.site_admin - - workflow_run.actor.starred_url - - workflow_run.actor.subscriptions_url - - workflow_run.actor.type - - workflow_run.actor.url - - workflow_run.artifacts_url - - workflow_run.cancel_url - - workflow_run.check_suite_id - - workflow_run.check_suite_node_id - - workflow_run.check_suite_url - - workflow_run.conclusion - - workflow_run.created_at - - workflow_run.event - - workflow_run.head_branch - - workflow_run.head_commit.author.email - - workflow_run.head_commit.author.name - - workflow_run.head_commit.committer.email - - workflow_run.head_commit.committer.name - - workflow_run.head_commit.id - - workflow_run.head_commit.message - - workflow_run.head_commit.timestamp - - workflow_run.head_commit.tree_id - - workflow_run.head_repository.collaborators_url - - workflow_run.head_repository.description - - workflow_run.head_repository.fork - - workflow_run.head_repository.forks_url - - workflow_run.head_repository.full_name - - workflow_run.head_repository.hooks_url - - workflow_run.head_repository.html_url - - workflow_run.head_repository.id - - workflow_run.head_repository.keys_url - - workflow_run.head_repository.name - - workflow_run.head_repository.node_id - - workflow_run.head_repository.owner.avatar_url - - workflow_run.head_repository.owner.events_url - - workflow_run.head_repository.owner.followers_url - - workflow_run.head_repository.owner.following_url - - workflow_run.head_repository.owner.gists_url - - workflow_run.head_repository.owner.gravatar_id - - workflow_run.head_repository.owner.html_url - - workflow_run.head_repository.owner.id - - workflow_run.head_repository.owner.login - - workflow_run.head_repository.owner.node_id - - workflow_run.head_repository.owner.organizations_url - - workflow_run.head_repository.owner.received_events_url - - workflow_run.head_repository.owner.repos_url - - workflow_run.head_repository.owner.site_admin - - workflow_run.head_repository.owner.starred_url - - workflow_run.head_repository.owner.subscriptions_url - - workflow_run.head_repository.owner.type - - workflow_run.head_repository.owner.url - - workflow_run.head_repository.private - - workflow_run.head_repository.teams_url - - workflow_run.head_repository.url - - workflow_run.head_sha - - workflow_run.html_url - - workflow_run.id - - workflow_run.jobs_url - - workflow_run.logs_url - - workflow_run.name - - workflow_run.node_id - - workflow_run.previous_attempt_url - - workflow_run.pull_requests{}.base.ref - - workflow_run.pull_requests{}.base.repo.id - - workflow_run.pull_requests{}.base.repo.name - - workflow_run.pull_requests{}.base.repo.url - - workflow_run.pull_requests{}.base.sha - - workflow_run.pull_requests{}.head.ref - - workflow_run.pull_requests{}.head.repo.id - - workflow_run.pull_requests{}.head.repo.name - - workflow_run.pull_requests{}.head.repo.url - - workflow_run.pull_requests{}.head.sha - - workflow_run.pull_requests{}.id - - workflow_run.pull_requests{}.number - - workflow_run.pull_requests{}.url - - workflow_run.repository.archive_url - - workflow_run.repository.assignees_url - - workflow_run.repository.blobs_url - - workflow_run.repository.branches_url - - workflow_run.repository.collaborators_url - - workflow_run.repository.comments_url - - workflow_run.repository.commits_url - - workflow_run.repository.compare_url - - workflow_run.repository.contents_url - - workflow_run.repository.contributors_url - - workflow_run.repository.deployments_url - - workflow_run.repository.description - - workflow_run.repository.downloads_url - - workflow_run.repository.events_url - - workflow_run.repository.fork - - workflow_run.repository.forks_url - - workflow_run.repository.full_name - - workflow_run.repository.git_commits_url - - workflow_run.repository.git_refs_url - - workflow_run.repository.git_tags_url - - workflow_run.repository.hooks_url - - workflow_run.repository.html_url - - workflow_run.repository.id - - workflow_run.repository.issue_comment_url - - workflow_run.repository.issue_events_url - - workflow_run.repository.issues_url - - workflow_run.repository.keys_url - - workflow_run.repository.labels_url - - workflow_run.repository.languages_url - - workflow_run.repository.merges_url - - workflow_run.repository.milestones_url - - workflow_run.repository.name - - workflow_run.repository.node_id - - workflow_run.repository.notifications_url - - workflow_run.repository.owner.avatar_url - - workflow_run.repository.owner.events_url - - workflow_run.repository.owner.followers_url - - workflow_run.repository.owner.following_url - - workflow_run.repository.owner.gists_url - - workflow_run.repository.owner.gravatar_id - - workflow_run.repository.owner.html_url - - workflow_run.repository.owner.id - - workflow_run.repository.owner.login - - workflow_run.repository.owner.node_id - - workflow_run.repository.owner.organizations_url - - workflow_run.repository.owner.received_events_url - - workflow_run.repository.owner.repos_url - - workflow_run.repository.owner.site_admin - - workflow_run.repository.owner.starred_url - - workflow_run.repository.owner.subscriptions_url - - workflow_run.repository.owner.type - - workflow_run.repository.owner.url - - workflow_run.repository.private - - workflow_run.repository.pulls_url - - workflow_run.repository.releases_url - - workflow_run.repository.stargazers_url - - workflow_run.repository.statuses_url - - workflow_run.repository.subscribers_url - - workflow_run.repository.subscription_url - - workflow_run.repository.tags_url - - workflow_run.repository.teams_url - - workflow_run.repository.trees_url - - workflow_run.repository.url - - workflow_run.rerun_url - - workflow_run.run_attempt - - workflow_run.run_number - - workflow_run.run_started_at - - workflow_run.status - - workflow_run.triggering_actor.avatar_url - - workflow_run.triggering_actor.events_url - - workflow_run.triggering_actor.followers_url - - workflow_run.triggering_actor.following_url - - workflow_run.triggering_actor.gists_url - - workflow_run.triggering_actor.gravatar_id - - workflow_run.triggering_actor.html_url - - workflow_run.triggering_actor.id - - workflow_run.triggering_actor.login - - workflow_run.triggering_actor.node_id - - workflow_run.triggering_actor.organizations_url - - workflow_run.triggering_actor.received_events_url - - workflow_run.triggering_actor.repos_url - - workflow_run.triggering_actor.site_admin - - workflow_run.triggering_actor.starred_url - - workflow_run.triggering_actor.subscriptions_url - - workflow_run.triggering_actor.type - - workflow_run.triggering_actor.url - - workflow_run.updated_at - - workflow_run.url - - workflow_run.workflow_id - - workflow_run.workflow_url +- _time +- action +- host +- index +- linecount +- meta +- punct +- source +- sourcetype +- splunk_server +- timestamp +- workflow_run.actor.avatar_url +- workflow_run.actor.events_url +- workflow_run.actor.followers_url +- workflow_run.actor.following_url +- workflow_run.actor.gists_url +- workflow_run.actor.gravatar_id +- workflow_run.actor.html_url +- workflow_run.actor.id +- workflow_run.actor.login +- workflow_run.actor.node_id +- workflow_run.actor.organizations_url +- workflow_run.actor.received_events_url +- workflow_run.actor.repos_url +- workflow_run.actor.site_admin +- workflow_run.actor.starred_url +- workflow_run.actor.subscriptions_url +- workflow_run.actor.type +- workflow_run.actor.url +- workflow_run.artifacts_url +- workflow_run.cancel_url +- workflow_run.check_suite_id +- workflow_run.check_suite_node_id +- workflow_run.check_suite_url +- workflow_run.conclusion +- workflow_run.created_at +- workflow_run.event +- workflow_run.head_branch +- workflow_run.head_commit.author.email +- workflow_run.head_commit.author.name +- workflow_run.head_commit.committer.email +- workflow_run.head_commit.committer.name +- workflow_run.head_commit.id +- workflow_run.head_commit.message +- workflow_run.head_commit.timestamp +- workflow_run.head_commit.tree_id +- workflow_run.head_repository.collaborators_url +- workflow_run.head_repository.description +- workflow_run.head_repository.fork +- workflow_run.head_repository.forks_url +- workflow_run.head_repository.full_name +- workflow_run.head_repository.hooks_url +- workflow_run.head_repository.html_url +- workflow_run.head_repository.id +- workflow_run.head_repository.keys_url +- workflow_run.head_repository.name +- workflow_run.head_repository.node_id +- workflow_run.head_repository.owner.avatar_url +- workflow_run.head_repository.owner.events_url +- workflow_run.head_repository.owner.followers_url +- workflow_run.head_repository.owner.following_url +- workflow_run.head_repository.owner.gists_url +- workflow_run.head_repository.owner.gravatar_id +- workflow_run.head_repository.owner.html_url +- workflow_run.head_repository.owner.id +- workflow_run.head_repository.owner.login +- workflow_run.head_repository.owner.node_id +- workflow_run.head_repository.owner.organizations_url +- workflow_run.head_repository.owner.received_events_url +- workflow_run.head_repository.owner.repos_url +- workflow_run.head_repository.owner.site_admin +- workflow_run.head_repository.owner.starred_url +- workflow_run.head_repository.owner.subscriptions_url +- workflow_run.head_repository.owner.type +- workflow_run.head_repository.owner.url +- workflow_run.head_repository.private +- workflow_run.head_repository.teams_url +- workflow_run.head_repository.url +- workflow_run.head_sha +- workflow_run.html_url +- workflow_run.id +- workflow_run.jobs_url +- workflow_run.logs_url +- workflow_run.name +- workflow_run.node_id +- workflow_run.previous_attempt_url +- workflow_run.pull_requests{}.base.ref +- workflow_run.pull_requests{}.base.repo.id +- workflow_run.pull_requests{}.base.repo.name +- workflow_run.pull_requests{}.base.repo.url +- workflow_run.pull_requests{}.base.sha +- workflow_run.pull_requests{}.head.ref +- workflow_run.pull_requests{}.head.repo.id +- workflow_run.pull_requests{}.head.repo.name +- workflow_run.pull_requests{}.head.repo.url +- workflow_run.pull_requests{}.head.sha +- workflow_run.pull_requests{}.id +- workflow_run.pull_requests{}.number +- workflow_run.pull_requests{}.url +- workflow_run.repository.archive_url +- workflow_run.repository.assignees_url +- workflow_run.repository.blobs_url +- workflow_run.repository.branches_url +- workflow_run.repository.collaborators_url +- workflow_run.repository.comments_url +- workflow_run.repository.commits_url +- workflow_run.repository.compare_url +- workflow_run.repository.contents_url +- workflow_run.repository.contributors_url +- workflow_run.repository.deployments_url +- workflow_run.repository.description +- workflow_run.repository.downloads_url +- workflow_run.repository.events_url +- workflow_run.repository.fork +- workflow_run.repository.forks_url +- workflow_run.repository.full_name +- workflow_run.repository.git_commits_url +- workflow_run.repository.git_refs_url +- workflow_run.repository.git_tags_url +- workflow_run.repository.hooks_url +- workflow_run.repository.html_url +- workflow_run.repository.id +- workflow_run.repository.issue_comment_url +- workflow_run.repository.issue_events_url +- workflow_run.repository.issues_url +- workflow_run.repository.keys_url +- workflow_run.repository.labels_url +- workflow_run.repository.languages_url +- workflow_run.repository.merges_url +- workflow_run.repository.milestones_url +- workflow_run.repository.name +- workflow_run.repository.node_id +- workflow_run.repository.notifications_url +- workflow_run.repository.owner.avatar_url +- workflow_run.repository.owner.events_url +- workflow_run.repository.owner.followers_url +- workflow_run.repository.owner.following_url +- workflow_run.repository.owner.gists_url +- workflow_run.repository.owner.gravatar_id +- workflow_run.repository.owner.html_url +- workflow_run.repository.owner.id +- workflow_run.repository.owner.login +- workflow_run.repository.owner.node_id +- workflow_run.repository.owner.organizations_url +- workflow_run.repository.owner.received_events_url +- workflow_run.repository.owner.repos_url +- workflow_run.repository.owner.site_admin +- workflow_run.repository.owner.starred_url +- workflow_run.repository.owner.subscriptions_url +- workflow_run.repository.owner.type +- workflow_run.repository.owner.url +- workflow_run.repository.private +- workflow_run.repository.pulls_url +- workflow_run.repository.releases_url +- workflow_run.repository.stargazers_url +- workflow_run.repository.statuses_url +- workflow_run.repository.subscribers_url +- workflow_run.repository.subscription_url +- workflow_run.repository.tags_url +- workflow_run.repository.teams_url +- workflow_run.repository.trees_url +- workflow_run.repository.url +- workflow_run.rerun_url +- workflow_run.run_attempt +- workflow_run.run_number +- workflow_run.run_started_at +- workflow_run.status +- workflow_run.triggering_actor.avatar_url +- workflow_run.triggering_actor.events_url +- workflow_run.triggering_actor.followers_url +- workflow_run.triggering_actor.following_url +- workflow_run.triggering_actor.gists_url +- workflow_run.triggering_actor.gravatar_id +- workflow_run.triggering_actor.html_url +- workflow_run.triggering_actor.id +- workflow_run.triggering_actor.login +- workflow_run.triggering_actor.node_id +- workflow_run.triggering_actor.organizations_url +- workflow_run.triggering_actor.received_events_url +- workflow_run.triggering_actor.repos_url +- workflow_run.triggering_actor.site_admin +- workflow_run.triggering_actor.starred_url +- workflow_run.triggering_actor.subscriptions_url +- workflow_run.triggering_actor.type +- workflow_run.triggering_actor.url +- workflow_run.updated_at +- workflow_run.url +- workflow_run.workflow_id +- workflow_run.workflow_url example_log: '{"action":"requested","workflow_run":{"id":2088708615,"name":"auto-update","node_id":"WFR_kwLOCa00Ec58fyoH","head_branch":"mac_os_detections","head_sha":"4049334910ea3d52a917ca35aed66d11c80ed966","run_number":9504,"event":"push","status":"queued","conclusion":null,"workflow_id":4692335,"check_suite_id":5918781611,"check_suite_node_id":"CS_kwDOCa00Ec8AAAABYMlwqw","url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615","html_url":"https://github.com/splunk/security_content/actions/runs/2088708615","pull_requests":[{"url":"https://api.github.com/repos/splunk/security_content/pulls/2131","id":893091277,"number":2131,"head":{"ref":"mac_os_detections","sha":"4049334910ea3d52a917ca35aed66d11c80ed966","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}},"base":{"ref":"develop","sha":"a7d3d1dc57f9bf36fe22e470bcf518fcc2c89283","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}}}],"created_at":"2022-04-04T08:43:15Z","updated_at":"2022-04-04T08:43:15Z","actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"run_attempt":1,"run_started_at":"2022-04-04T08:43:15Z","triggering_actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"jobs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/jobs","logs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/logs","check_suite_url":"https://api.github.com/repos/splunk/security_content/check-suites/5918781611","artifacts_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/artifacts","cancel_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/cancel","rerun_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/rerun","previous_attempt_url":null,"workflow_url":"https://api.github.com/repos/splunk/security_content/actions/workflows/4692335","head_commit":{"id":"4049334910ea3d52a917ca35aed66d11c80ed966","tree_id":"df4ddc1359be3b19f093b7a27dbf5708187743a0","message":"small change","timestamp":"2022-04-04T08:43:01Z","author":{"name":"jsmith","email":"jsmith@evilcorp.com"},"committer":{"name":"jsmith","email":"jsmith@evilcorp.com"}},"repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/number}","events_url":"https://api.github.com/repos/splunk/security_content/events","assignees_url":"https://api.github.com/repos/splunk/security_content/assignees{/user}","branches_url":"https://api.github.com/repos/splunk/security_content/branches{/branch}","tags_url":"https://api.github.com/repos/splunk/security_content/tags","blobs_url":"https://api.github.com/repos/splunk/security_content/git/blobs{/sha}","git_tags_url":"https://api.github.com/repos/splunk/security_content/git/tags{/sha}","git_refs_url":"https://api.github.com/repos/splunk/security_content/git/refs{/sha}","trees_url":"https://api.github.com/repos/splunk/security_content/git/trees{/sha}","statuses_url":"https://api.github.com/repos/splunk/security_content/statuses/{sha}","languages_url":"https://api.github.com/repos/splunk/security_content/languages","stargazers_url":"https://api.github.com/repos/splunk/security_content/stargazers","contributors_url":"https://api.github.com/repos/splunk/security_content/contributors","subscribers_url":"https://api.github.com/repos/splunk/security_content/subscribers","subscription_url":"https://api.github.com/repos/splunk/security_content/subscription","commits_url":"https://api.github.com/repos/splunk/security_content/commits{/sha}","git_commits_url":"https://api.github.com/repos/splunk/security_content/git/commits{/sha}","comments_url":"https://api.github.com/repos/splunk/security_content/comments{/number}","issue_comment_url":"https://api.github.com/repos/splunk/security_content/issues/comments{/number}","contents_url":"https://api.github.com/repos/splunk/security_content/contents/{+path}","compare_url":"https://api.github.com/repos/splunk/security_content/compare/{base}...{head}","merges_url":"https://api.github.com/repos/splunk/security_content/merges","archive_url":"https://api.github.com/repos/splunk/security_content/{archive_format}{/ref}","downloads_url":"https://api.github.com/repos/splunk/security_content/downloads","issues_url":"https://api.github.com/repos/splunk/security_content/issues{/number}","pulls_url":"https://api.github.com/repos/splunk/security_content/pulls{/number}","milestones_url":"https://api.github.com/repos/splunk/security_content/milestones{/number}","notifications_url":"https://api.github.com/repos/splunk/security_content/notifications{?since,all,participating}","labels_url":"https://api.github.com/repos/splunk/security_content/labels{/name}","releases_url":"https://api.github.com/repos/splunk/security_content/releases{/id}","deployments_url":"https://api.github.com/repos/splunk/security_content/deployments"},"head_repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk diff --git a/data_sources/google_workspace_login_failure.yml b/data_sources/google_workspace_login_failure.yml index f853aa35f3..702959eef7 100644 --- a/data_sources/google_workspace_login_failure.yml +++ b/data_sources/google_workspace_login_failure.yml @@ -6,54 +6,54 @@ author: Patrick Bareiss, Splunk description: Logs failed login attempts to Google Workspace accounts, including details about the user, IP address, and reason for failure. mitre_components: - - User Account Authentication - - Logon Session Metadata - - User Account Metadata - - Application Log Content +- User Account Authentication +- Logon Session Metadata +- User Account Metadata +- Application Log Content source: gws:reports:admin sourcetype: gws:reports:admin separator: event.name separator_value: login_failure supported_TA: - - name: Splunk Add-on for Google Workspace - url: https://splunkbase.splunk.com/app/5556 - version: 3.0.2 +- name: Splunk Add-on for Google Workspace + url: https://splunkbase.splunk.com/app/5556 + version: 3.0.2 fields: - - _time - - actor.email - - actor.profileId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - etag - - event.name - - event.parameters{}.multiValue{} - - event.parameters{}.name - - event.parameters{}.value - - event.type - - eventtype - - host - - id.applicationName - - id.customerId - - id.time - - id.uniqueQualifier - - index - - ipAddress - - kind - - linecount - - punct - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - timeendpos - - timestartpos +- _time +- actor.email +- actor.profileId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- etag +- event.name +- event.parameters{}.multiValue{} +- event.parameters{}.name +- event.parameters{}.value +- event.type +- eventtype +- host +- id.applicationName +- id.customerId +- id.time +- id.uniqueQualifier +- index +- ipAddress +- kind +- linecount +- punct +- source +- sourcetype +- splunk_server +- tag +- tag::eventtype +- timeendpos +- timestartpos example_log: '{"kind": "admin#reports#activity", "id": {"time": "2022-10-12T01:05:35.119Z", "uniqueQualifier": "720229394436", "applicationName": "login", "customerId": "C046r85ir"}, "etag": "\"JCPRxFaiNR1s5TJ6ecIH8OpGdY4efiOYXbIB65itOzY/_lixtTooT11WXorGf6w6ElN0m0g\"", diff --git a/data_sources/google_workspace_login_success.yml b/data_sources/google_workspace_login_success.yml index 4f0d7d8265..3ad47e3299 100644 --- a/data_sources/google_workspace_login_success.yml +++ b/data_sources/google_workspace_login_success.yml @@ -6,52 +6,52 @@ author: Patrick Bareiss, Splunk description: Logs successful login attempts to Google Workspace accounts, including details about the user, IP address, and session metadata. mitre_components: - - User Account Authentication - - Logon Session Creation - - User Account Metadata - - Logon Session Metadata +- User Account Authentication +- Logon Session Creation +- User Account Metadata +- Logon Session Metadata source: gws:reports:admin sourcetype: gws:reports:admin separator: event.name separator_value: login_success supported_TA: - - name: Splunk Add-on for Google Workspace - url: https://splunkbase.splunk.com/app/5556 - version: 3.0.2 +- name: Splunk Add-on for Google Workspace + url: https://splunkbase.splunk.com/app/5556 + version: 3.0.2 fields: - - _time - - actor.email - - actor.profileId - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - etag - - event.name - - event.parameters{}.boolValue - - event.parameters{}.multiValue{} - - event.parameters{}.name - - event.parameters{}.value - - event.type - - host - - id.applicationName - - id.customerId - - id.time - - id.uniqueQualifier - - index - - ipAddress - - kind - - linecount - - punct - - source - - sourcetype - - splunk_server - - timeendpos - - timestartpos +- _time +- actor.email +- actor.profileId +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- etag +- event.name +- event.parameters{}.boolValue +- event.parameters{}.multiValue{} +- event.parameters{}.name +- event.parameters{}.value +- event.type +- host +- id.applicationName +- id.customerId +- id.time +- id.uniqueQualifier +- index +- ipAddress +- kind +- linecount +- punct +- source +- sourcetype +- splunk_server +- timeendpos +- timestartpos example_log: '{"kind": "admin#reports#activity", "id": {"time": "2022-10-13T20:57:35.833Z", "uniqueQualifier": "437744618349", "applicationName": "login", "customerId": "C046r85ir"}, "etag": "\"JCPRxFaiNR1s5TJ6ecIH8OpGdY4efiOYXbIB65itOzY/OgAbD-Tz8hSD1vUJWw7NLiJ5SF4\"", diff --git a/data_sources/ivanti_vtm_audit.yml b/data_sources/ivanti_vtm_audit.yml index 389bf9b8d9..31e1bdc95e 100644 --- a/data_sources/ivanti_vtm_audit.yml +++ b/data_sources/ivanti_vtm_audit.yml @@ -6,22 +6,22 @@ author: Michael Haag, Splunk description: Logs administrative and operational activities in Ivanti Virtual Traffic Manager (VTM), including configuration changes, user actions, and system events. mitre_components: - - Configuration Modification - - Application Log Content - - User Account Metadata - - Host Status - - Service Modification +- Configuration Modification +- Application Log Content +- User Account Metadata +- Host Status +- Service Modification source: ivanti_vtm sourcetype: ivanti_vtm_audit supported_TA: [] fields: - - _time - - IP - - MODUSER - - OPERATION - - MODGROUP - - AUTH - - USER - - GROUP +- _time +- IP +- MODUSER +- OPERATION +- MODGROUP +- AUTH +- USER +- GROUP example_log: '[19/Aug/2024:19:41:22 +0000] USER=!!ABSENT!! GROUP=!!ABSENT!! AUTH=!!ABSENT!! IP=!!ABSENT!! OPERATION=adduser MODUSER=newadmin MODGROUP=admin' diff --git a/data_sources/kubernetes_audit.yml b/data_sources/kubernetes_audit.yml index 89588cee18..7553357ea4 100644 --- a/data_sources/kubernetes_audit.yml +++ b/data_sources/kubernetes_audit.yml @@ -6,62 +6,62 @@ author: Patrick Bareiss, Splunk description: Logs activities within a Kubernetes cluster, including API server requests, resource access, configuration changes, and user authentication events. mitre_components: - - Pod Metadata - - Pod Modification - - Cluster Metadata - - User Account Authentication - - Configuration Modification - - Application Log Content +- Pod Metadata +- Pod Modification +- Cluster Metadata +- User Account Authentication +- Configuration Modification +- Application Log Content source: kubernetes sourcetype: _json supported_TA: [] fields: - - _time - - annotations.authorization.k8s.io/decision - - annotations.authorization.k8s.io/reason - - apiVersion - - auditID - - eventtype - - host - - index - - kind - - level - - linecount - - objectRef.apiGroup - - objectRef.apiVersion - - objectRef.namespace - - objectRef.resource - - punct - - requestReceivedTimestamp - - requestURI - - responseObject.apiVersion - - responseObject.code - - responseObject.details.group - - responseObject.details.kind - - responseObject.kind - - responseObject.message - - responseObject.reason - - responseObject.status - - responseStatus.code - - responseStatus.details.group - - responseStatus.details.kind - - responseStatus.message - - responseStatus.reason - - responseStatus.status - - source - - sourceIPs{} - - sourcetype - - splunk_server - - stage - - stageTimestamp - - tag - - tag::eventtype - - timestamp - - user.groups{} - - user.uid - - user.username - - userAgent - - verb +- _time +- annotations.authorization.k8s.io/decision +- annotations.authorization.k8s.io/reason +- apiVersion +- auditID +- eventtype +- host +- index +- kind +- level +- linecount +- objectRef.apiGroup +- objectRef.apiVersion +- objectRef.namespace +- objectRef.resource +- punct +- requestReceivedTimestamp +- requestURI +- responseObject.apiVersion +- responseObject.code +- responseObject.details.group +- responseObject.details.kind +- responseObject.kind +- responseObject.message +- responseObject.reason +- responseObject.status +- responseStatus.code +- responseStatus.details.group +- responseStatus.details.kind +- responseStatus.message +- responseStatus.reason +- responseStatus.status +- source +- sourceIPs{} +- sourcetype +- splunk_server +- stage +- stageTimestamp +- tag +- tag::eventtype +- timestamp +- user.groups{} +- user.uid +- user.username +- userAgent +- verb example_log: '{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"RequestResponse","auditID":"582c31ab-4906-49bb-9ff9-872f980ccb84","stage":"ResponseComplete","requestURI":"/apis/batch/v1/namespaces/test2/jobs?fieldManager=kubectl-create\u0026fieldValidation=Strict","verb":"create","user":{"username":"k8s-test-user","uid":"aws-iam-authenticator:591511147606:AROAYTOGP2RLFHNBOTP5J","groups":["system:authenticated"]},"sourceIPs":["176.95.188.101"],"userAgent":"kubectl/v1.27.2 (darwin/arm64) kubernetes/7f6f68f","objectRef":{"resource":"jobs","namespace":"test2","apiGroup":"batch","apiVersion":"v1"},"responseStatus":{"metadata":{},"status":"Failure","message":"jobs.batch is forbidden: User \"k8s-test-user\" cannot create resource \"jobs\" in API group diff --git a/data_sources/kubernetes_falco.yml b/data_sources/kubernetes_falco.yml index cff1b27f1c..f5f7cf1762 100644 --- a/data_sources/kubernetes_falco.yml +++ b/data_sources/kubernetes_falco.yml @@ -6,50 +6,50 @@ author: Patrick Bareiss, Splunk description: Logs suspicious or anomalous activities within a Kubernetes environment detected by Falco, including system calls, file access, and network activity. mitre_components: - - File Access - - Network Traffic Content - - Process Creation - - Process Modification - - Application Log Content - - Host Status +- File Access +- Network Traffic Content +- Process Creation +- Process Modification +- Application Log Content +- Host Status source: kubernetes sourcetype: kube:container:falco supported_TA: [] fields: - - _time - - command - - container_id - - container_image - - container_image_tag - - container_name - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - evt_type - - exe_flags - - host - - index - - k8s_ns - - k8s_pod_name - - linecount - - parent - - proc_exepath - - process - - punct - - source - - sourcetype - - splunk_server - - terminal - - timeendpos - - timestartpos - - user - - user_loginuid - - user_uid +- _time +- command +- container_id +- container_image +- container_image_tag +- container_name +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- evt_type +- exe_flags +- host +- index +- k8s_ns +- k8s_pod_name +- linecount +- parent +- proc_exepath +- process +- punct +- source +- sourcetype +- splunk_server +- terminal +- timeendpos +- timestartpos +- user +- user_loginuid +- user_uid example_log: '12:18:18.691725165: Notice A shell was spawned in a container with an attached terminal (evt_type=execve user=root user_uid=0 user_loginuid=-1 process=bash proc_exepath=/usr/lib/splunk-otel-collector/agent-bundle/bin/bash parent=runc command=bash diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml index da361ede71..4fce4de435 100644 --- a/data_sources/linux_auditd_add_user.yml +++ b/data_sources/linux_auditd_add_user.yml @@ -7,38 +7,38 @@ description: Logs activities related to the addition of a new user account on a system, including details about the username, UID, and the process initiating the action. mitre_components: - - User Account Creation - - User Account Metadata - - OS API Execution - - Application Log Content +- User Account Creation +- User Account Metadata +- OS API Execution +- Application Log Content source: /var/log/audit/audit.log sourcetype: linux:audit separator: type separator_value: ADD_USER configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - - name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 +- name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: - - msg - - type - - pid - - uid - - auid - - ses - - subj - - msg - - op - - id - - exe - - hostname - - addr - - terminal - - res - - UID - - AUID - - ID -example_log: "type=ADD_USER msg=audit(1722950859.266:6994): pid=1788 uid=0 auid=1000 - ses=1 subj=unconfined msg='op=adding user id=1002 exe=\"/usr/sbin/useradd\" hostname=ar-linux1 - addr=? terminal=pts/1 res=success'UID=\"root\" AUID=\"ubuntu\" ID=\"unknown(1002)\"" +- msg +- type +- pid +- uid +- auid +- ses +- subj +- msg +- op +- id +- exe +- hostname +- addr +- terminal +- res +- UID +- AUID +- ID +example_log: 'type=ADD_USER msg=audit(1722950859.266:6994): pid=1788 uid=0 auid=1000 + ses=1 subj=unconfined msg=''op=adding user id=1002 exe="/usr/sbin/useradd" hostname=ar-linux1 + addr=? terminal=pts/1 res=success''UID="root" AUID="ubuntu" ID="unknown(1002)"' diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml index 72433806de..c9f6bac6aa 100644 --- a/data_sources/linux_auditd_execve.yml +++ b/data_sources/linux_auditd_execve.yml @@ -6,24 +6,24 @@ author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the executed command, arguments, and the initiating process. mitre_components: - - Command Execution - - Process Creation - - Process Metadata - - OS API Execution - - Application Log Content +- Command Execution +- Process Creation +- Process Metadata +- OS API Execution +- Application Log Content source: /var/log/audit/audit.log sourcetype: linux:audit separator: type separator_value: EXECVE configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - - name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 +- name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: - - msg - - type - - msg - - argc +- msg +- type +- msg +- argc example_log: 'type=EXECVE msg=audit(1723044684.257:15795): argc=3 a0="sudo" a1="LD_PRELOAD=./myfopen.so" a2="./prog"' diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml index d612530b4e..27ecc36cab 100644 --- a/data_sources/linux_auditd_path.yml +++ b/data_sources/linux_auditd_path.yml @@ -6,39 +6,39 @@ author: Teoderick Contreras, Splunk description: Logs file system access events on a Linux system, including details about file paths, permissions, and associated processes. mitre_components: - - File Access - - File Metadata - - Process Metadata - - OS API Execution - - Application Log Content +- File Access +- File Metadata +- Process Metadata +- OS API Execution +- Application Log Content source: /var/log/audit/audit.log sourcetype: linux:audit separator: type separator_value: PATH configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - - name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 +- name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: - - msg - - type - - item - - name - - inode - - dev - - mode - - ouid - - ogid - - rdev - - nametype - - cap_fp - - cap_fi - - cap_fe - - cap_fver - - cap_frootid - - OUID - - OGID +- msg +- type +- item +- name +- inode +- dev +- mode +- ouid +- ogid +- rdev +- nametype +- cap_fp +- cap_fi +- cap_fe +- cap_fver +- cap_frootid +- OUID +- OGID example_log: 'type=PATH msg=audit(1723043687.149:14898): item=1 name="/etc/ssh/ssh_config~" inode=1292 dev=103:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 nametype=DELETE cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 OUID="root" OGID="root"' diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml index fbd067aed5..bd4b0ce319 100644 --- a/data_sources/linux_auditd_proctitle.yml +++ b/data_sources/linux_auditd_proctitle.yml @@ -6,21 +6,21 @@ author: Teoderick Contreras, Splunk description: Logs the full command-line arguments of a process execution on a Linux system, providing visibility into the executed command and its parameters. mitre_components: - - Command Execution - - Process Metadata - - OS API Execution - - Application Log Content +- Command Execution +- Process Metadata +- OS API Execution +- Application Log Content separator: type separator_value: PROCTITLE source: /var/log/audit/audit.log sourcetype: linux:audit configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - - name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 +- name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: - - proctitle - - msg - - type +- proctitle +- msg +- type example_log: 'type=PROCTITLE msg=audit(1722944427.844:4146): proctitle=63686D6F640037373700312E7368' diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml index 8b1c94b0f2..e44ecf9e3e 100644 --- a/data_sources/linux_auditd_service_stop.yml +++ b/data_sources/linux_auditd_service_stop.yml @@ -7,36 +7,36 @@ description: Logs events related to the stoppage of a service on a Linux system, details about the service name, the process initiating the stop, and associated timestamps. mitre_components: - - Service Modification - - Service Metadata - - OS API Execution - - Application Log Content +- Service Modification +- Service Metadata +- OS API Execution +- Application Log Content separator: type separator_value: SERVICE_STOP source: /var/log/audit/audit.log sourcetype: linux:audit configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - - name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 +- name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: - - msg - - type - - pid - - uid - - auid - - ses - - subj - - msg - - comm - - exe - - hostname - - addr - - terminal - - res - - UID - - AUID -example_log: "type=SERVICE_STOP msg=audit(1722957155.494:4802): pid=1 uid=0 auid=4294967295 - ses=4294967295 subj=unconfined msg='unit=atd comm=\"systemd\" exe=\"/usr/lib/systemd/systemd\"\ - \ hostname=? addr=? terminal=? res=success'UID=\"root\" AUID=\"unset\"" +- msg +- type +- pid +- uid +- auid +- ses +- subj +- msg +- comm +- exe +- hostname +- addr +- terminal +- res +- UID +- AUID +example_log: 'type=SERVICE_STOP msg=audit(1722957155.494:4802): pid=1 uid=0 auid=4294967295 + ses=4294967295 subj=unconfined msg=''unit=atd comm="systemd" exe="/usr/lib/systemd/systemd" + hostname=? addr=? terminal=? res=success''UID="root" AUID="unset"' diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml index c753a66b54..dcc8e48779 100644 --- a/data_sources/linux_auditd_syscall.yml +++ b/data_sources/linux_auditd_syscall.yml @@ -6,59 +6,59 @@ author: Teoderick Contreras, Splunk description: Logs system calls made by processes on a Linux system, including details about the syscall number, arguments, return values, and associated process metadata. mitre_components: - - OS API Execution - - Process Metadata - - Application Log Content - - Host Status +- OS API Execution +- Process Metadata +- Application Log Content +- Host Status source: /var/log/audit/audit.log sourcetype: linux:audit separator: type separator_value: syscall configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - - name: Splunk Add-on for Unix and Linux - url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 +- name: Splunk Add-on for Unix and Linux + url: https://splunkbase.splunk.com/app/833 + version: 9.2.0 fields: - - msg - - type - - msg - - arch - - syscall - - success - - exit - - a1 - - a2 - - a3 - - items - - ppid - - pid - - auid - - uid - - gid - - euid - - suid - - fsuid - - egid - - sgid - - fsgid - - tty - - ses - - comm - - exe - - subj - - key - - ARCH - - SYSCALL - - AUID - - UID - - GID - - EUID - - SUID - - FSUID - - EGID - - SGID - - FSGID +- msg +- type +- msg +- arch +- syscall +- success +- exit +- a1 +- a2 +- a3 +- items +- ppid +- pid +- auid +- uid +- gid +- euid +- suid +- fsuid +- egid +- sgid +- fsgid +- tty +- ses +- comm +- exe +- subj +- key +- ARCH +- SYSCALL +- AUID +- UID +- GID +- EUID +- SUID +- FSUID +- EGID +- SGID +- FSGID example_log: 'type=SYSCALL msg=audit(1723035666.627:3663): arch=c000003e syscall=59 success=yes exit=0 a0=556a6d697a58 a1=556a6d68ad00 a2=556a6d69c980 a3=0 items=2 ppid=1300 pid=1301 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index e6f8b78160..77d0e1f105 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -6,49 +6,49 @@ author: Patrick Bareiss, Splunk description: Logs authentication and authorization events on a Linux system, including login attempts, SSH connections, and privilege escalation activities. mitre_components: - - User Account Authentication - - Logon Session Creation - - Logon Session Metadata - - User Account Metadata - - Application Log Content +- User Account Authentication +- Logon Session Creation +- Logon Session Metadata +- User Account Metadata +- Application Log Content source: /var/log/secure sourcetype: linux_secure supported_TA: [] fields: - - _time - - action - - app - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - eventtype - - host - - index - - linecount - - pid - - process - - punct - - source - - sourcetype - - splunk_server - - src - - src_port - - sshd_protocol - - tag - - tag::action - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_name - - vendor_action - - vendor_product +- _time +- action +- app +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- eventtype +- host +- index +- linecount +- pid +- process +- punct +- source +- sourcetype +- splunk_server +- src +- src_port +- sshd_protocol +- tag +- tag::action +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_name +- vendor_action +- vendor_product example_log: 'May 27 09:28:36 ip-172-31-24-46 sshd[5617]: Accepted password for mikael from 84.202.159.161 port 63487 ssh2' diff --git a/data_sources/ms365_defender_incident_alerts.yml b/data_sources/ms365_defender_incident_alerts.yml index 80e582df46..4f6665ecbc 100644 --- a/data_sources/ms365_defender_incident_alerts.yml +++ b/data_sources/ms365_defender_incident_alerts.yml @@ -6,236 +6,185 @@ author: Bhavin Patel, Splunk description: Logs security incidents and correlated alerts in Microsoft 365 Defender, including details about affected assets, threat types, and remediation steps. mitre_components: - - Host Status - - User Account Metadata - - Application Log Content - - Malware Metadata - - Active Directory Object Access +- Host Status +- User Account Metadata +- Application Log Content +- Malware Metadata +- Active Directory Object Access source: ms365_defender_incident_alerts sourcetype: ms365:defender:incident:alerts supported_TA: - - name: Splunk Add-on for Microsoft Security - url: https://splunkbase.splunk.com/app/6207 - version: 2.4.1 +- name: Splunk Add-on for Microsoft Security + url: https://splunkbase.splunk.com/app/6207 + version: 2.4.1 fields: - - actorName - - alertId - - app - - assignedTo - - body - - category - - classification - - creationTime - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - description - - dest - - detectionSource - - detectorId - - determination - - devices{}.aadDeviceId - - devices{}.defenderAvStatus - - devices{}.deviceDnsName - - devices{}.firstSeen - - devices{}.healthStatus - - devices{}.loggedOnUsers{}.accountName - - devices{}.loggedOnUsers{}.domainName - - devices{}.mdatpDeviceId - - devices{}.onboardingStatus - - devices{}.osBuild - - devices{}.osPlatform - - devices{}.osProcessor - - devices{}.rbacGroupName - - devices{}.riskScore - - devices{}.version - - devices{}.vmMetadata - - devices{}.vmMetadata.cloudProvider - - devices{}.vmMetadata.resourceId - - devices{}.vmMetadata.subscriptionId - - devices{}.vmMetadata.vmId - - entities{}.aadUserId - - entities{}.accountName - - entities{}.applicationId - - entities{}.applicationName - - entities{}.detectionStatus - - entities{}.deviceId - - entities{}.domainName - - entities{}.entityType - - entities{}.evidenceCreationTime - - entities{}.fileName - - entities{}.filePath - - entities{}.ipAddress - - entities{}.parentProcessCreationTime - - entities{}.parentProcessFileName - - entities{}.parentProcessFilePath - - entities{}.parentProcessId - - entities{}.processCommandLine - - entities{}.processCreationTime - - entities{}.processId - - entities{}.remediationStatus - - entities{}.remediationStatusDetails - - entities{}.sha1 - - entities{}.sha256 - - entities{}.userPrincipalName - - entities{}.userSid - - entities{}.verdict - - eventtype - - firstActivity - - host - - id - - incidentId - - index - - investigationId - - investigationState - - lastActivity - - lastUpdatedTime - - linecount - - mitreTechniques{} - - mitre_technique_id - - providerAlertId - - resolvedTime - - serviceSource - - severity - - signature - - signature_id - - source - - sourcetype - - splunk_server - - splunk_server_group - - src - - status - - subject - - tag - - tag::app - - tag::eventtype - - threatFamilyName - - timeendpos - - timestartpos - - title - - type - - user - - user_name - - _bkt - - _cd - - _eventtype_color - - _indextime - - _raw - - _serial - - _si - - _sourcetype - - _subsecond - - _time -example_log: |- - { - "alertId": "da638001130101730338_582949328", - "providerAlertId": "da638001130101730338_582949328", - "incidentId": 486, - "serviceSource": "MicrosoftDefenderForEndpoint", - "creationTime": "2022-09-30T05:36:50.1732198Z", - "lastUpdatedTime": "2022-11-19T01:35:42.7033333Z", - "resolvedTime": "2022-10-01T01:36:00.5066667Z", - "firstActivity": "2022-09-30T05:06:43.8196597Z", - "lastActivity": "2022-09-30T05:06:43.8196597Z", - "title": "Suspicious URL clicked", - "description": "A user opened a potentially malicious URL. This alert was triggered based on a Microsoft Defender for Office 365 alert.", - "category": "InitialAccess", - "status": "Resolved", - "severity": "High", - "investigationId": null, - "investigationState": "UnsupportedAlertType", - "classification": "TruePositive", - "determination": "SecurityTesting", - "detectionSource": "MTP", - "detectorId": "359b36eb-337c-4f1c-b280-8c5e08f9c4a0", - "assignedTo": "msftadmin@metal.m365dpoc.com", - "actorName": null, - "threatFamilyName": null, - "mitreTechniques": [ - "T1566.002" - ], - "devices": [ - { - "mdatpDeviceId": "c7e147cb0eb3534a4dcea5acb8e61c933713b145", - "aadDeviceId": null, - "deviceDnsName": "metal-win10v.metal.m365dpoc.com", - "osPlatform": "Windows10", - "version": "1809", - "osProcessor": "x64", - "osBuild": 17763, - "healthStatus": "Active", - "riskScore": "High", - "rbacGroupName": "Full Auto Clients", - "firstSeen": "2022-08-08T08:51:02.455Z", - "tags": [ - "Full auto" - ], - "defenderAvStatus": "Updated", - "onboardingStatus": "Onboarded", - "vmMetadata": { - "vmId": "17881b39-b03f-4a2c-9b56-078be1330bd0", - "cloudProvider": "Unknown", - "resourceId": "/subscriptions/29e73d07-8740-4164-a257-592a19a7b77c/resourceGroups/MSDXV2/providers/Microsoft.Compute/virtualMachines/MSDXV2-Win10V", - "subscriptionId": "29e73d07-8740-4164-a257-592a19a7b77c" - }, - "loggedOnUsers": [ - { - "accountName": "hetfield", - "domainName": "MSDXV2" - } - ] - } - ], - "entities": [ - { - "entityType": "Process", - "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z", - "verdict": "Suspicious", - "remediationStatus": "None", - "sha1": "6cbce4a295c163791b60fc23d285e6d84f28ee4c", - "sha256": "de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c", - "fileName": "powershell.exe", - "filePath": "", - "processId": 7068, - "processCommandLine": "powershell.exe -command \" $Process = New-Object System.Diagnostics.Process; $Process.StartInfo.FileName = 'https://nam12.safelinks.protection.outlook.com/?url=http%3A%2F%2Fgcajebahdi.corporatelogon.xyz%2Fab%2Fjnkmbkkdnlgedc&data=05%7C01%7Chetfield%40metal.m365dpoc.com%7Cca409616a82145bd6a5f08daa2a10255%7C1a49212958c8401191cd245285f5345c%7C0%7C0%7C638001109710345383%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=FyEjRS5qOd2SkJELlueibuxLFMYNjL7fz8EbuOAvFwg%3D&reserved=0'; $Process.StartInfo.UseShellExecute = $true; $Process.Start() | Out-Null; \" ", - "processCreationTime": "2022-09-30T05:06:43.3390523Z", - "parentProcessId": 7116, - "parentProcessCreationTime": "2022-09-30T05:06:43.3100364Z", - "accountName": "hetfield", - "userSid": "S-1-5-21-2300221942-1987151257-321556088-1104" - }, - { - "entityType": "File", - "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z", - "verdict": "Suspicious", - "remediationStatus": "None", - "sha1": "6cbce4a295c163791b60fc23d285e6d84f28ee4c", - "sha256": "de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c", - "fileName": "powershell.exe", - "filePath": "" - }, - { - "entityType": "User", - "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z", - "verdict": "Suspicious", - "remediationStatus": "None", - "accountName": "hetfield", - "domainName": "metal.m365dpoc", - "userSid": "S-1-5-21-2300221942-1987151257-321556088-1104", - "aadUserId": "e848b07a-87af-4448-9979-09f0b809c8d4", - "userPrincipalName": "daftpunk" - }, - { - "entityType": "Url", - "evidenceCreationTime": "2022-09-30T05:36:50.2133333Z", - "verdict": "Suspicious", - "remediationStatus": "None", - "url": "http://gcajebahdi.corporatelogon.xyz/ab/jnkmbkkdnlgedc" - } - ] - } +- actorName +- alertId +- app +- assignedTo +- body +- category +- classification +- creationTime +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- description +- dest +- detectionSource +- detectorId +- determination +- devices{}.aadDeviceId +- devices{}.defenderAvStatus +- devices{}.deviceDnsName +- devices{}.firstSeen +- devices{}.healthStatus +- devices{}.loggedOnUsers{}.accountName +- devices{}.loggedOnUsers{}.domainName +- devices{}.mdatpDeviceId +- devices{}.onboardingStatus +- devices{}.osBuild +- devices{}.osPlatform +- devices{}.osProcessor +- devices{}.rbacGroupName +- devices{}.riskScore +- devices{}.version +- devices{}.vmMetadata +- devices{}.vmMetadata.cloudProvider +- devices{}.vmMetadata.resourceId +- devices{}.vmMetadata.subscriptionId +- devices{}.vmMetadata.vmId +- entities{}.aadUserId +- entities{}.accountName +- entities{}.applicationId +- entities{}.applicationName +- entities{}.detectionStatus +- entities{}.deviceId +- entities{}.domainName +- entities{}.entityType +- entities{}.evidenceCreationTime +- entities{}.fileName +- entities{}.filePath +- entities{}.ipAddress +- entities{}.parentProcessCreationTime +- entities{}.parentProcessFileName +- entities{}.parentProcessFilePath +- entities{}.parentProcessId +- entities{}.processCommandLine +- entities{}.processCreationTime +- entities{}.processId +- entities{}.remediationStatus +- entities{}.remediationStatusDetails +- entities{}.sha1 +- entities{}.sha256 +- entities{}.userPrincipalName +- entities{}.userSid +- entities{}.verdict +- eventtype +- firstActivity +- host +- id +- incidentId +- index +- investigationId +- investigationState +- lastActivity +- lastUpdatedTime +- linecount +- mitreTechniques{} +- mitre_technique_id +- providerAlertId +- resolvedTime +- serviceSource +- severity +- signature +- signature_id +- source +- sourcetype +- splunk_server +- splunk_server_group +- src +- status +- subject +- tag +- tag::app +- tag::eventtype +- threatFamilyName +- timeendpos +- timestartpos +- title +- type +- user +- user_name +- _bkt +- _cd +- _eventtype_color +- _indextime +- _raw +- _serial +- _si +- _sourcetype +- _subsecond +- _time +example_log: "{\n \"alertId\": \"da638001130101730338_582949328\",\n \"providerAlertId\"\ + : \"da638001130101730338_582949328\",\n \"incidentId\": 486,\n \"serviceSource\"\ + : \"MicrosoftDefenderForEndpoint\",\n \"creationTime\": \"2022-09-30T05:36:50.1732198Z\"\ + ,\n \"lastUpdatedTime\": \"2022-11-19T01:35:42.7033333Z\",\n \"resolvedTime\"\ + : \"2022-10-01T01:36:00.5066667Z\",\n \"firstActivity\": \"2022-09-30T05:06:43.8196597Z\"\ + ,\n \"lastActivity\": \"2022-09-30T05:06:43.8196597Z\",\n \"title\": \"Suspicious\ + \ URL clicked\",\n \"description\": \"A user opened a potentially malicious URL.\ + \ This alert was triggered based on a Microsoft Defender for Office 365 alert.\"\ + ,\n \"category\": \"InitialAccess\",\n \"status\": \"Resolved\",\n \"severity\"\ + : \"High\",\n \"investigationId\": null,\n \"investigationState\": \"UnsupportedAlertType\"\ + ,\n \"classification\": \"TruePositive\",\n \"determination\": \"SecurityTesting\"\ + ,\n \"detectionSource\": \"MTP\",\n \"detectorId\": \"359b36eb-337c-4f1c-b280-8c5e08f9c4a0\"\ + ,\n \"assignedTo\": \"msftadmin@metal.m365dpoc.com\",\n \"actorName\": null,\n\ + \ \"threatFamilyName\": null,\n \"mitreTechniques\": [\n \"T1566.002\"\n ],\n\ + \ \"devices\": [\n {\n \"mdatpDeviceId\": \"c7e147cb0eb3534a4dcea5acb8e61c933713b145\"\ + ,\n \"aadDeviceId\": null,\n \"deviceDnsName\": \"metal-win10v.metal.m365dpoc.com\"\ + ,\n \"osPlatform\": \"Windows10\",\n \"version\": \"1809\",\n \"\ + osProcessor\": \"x64\",\n \"osBuild\": 17763,\n \"healthStatus\": \"Active\"\ + ,\n \"riskScore\": \"High\",\n \"rbacGroupName\": \"Full Auto Clients\"\ + ,\n \"firstSeen\": \"2022-08-08T08:51:02.455Z\",\n \"tags\": [\n \ + \ \"Full auto\"\n ],\n \"defenderAvStatus\": \"Updated\",\n \"\ + onboardingStatus\": \"Onboarded\",\n \"vmMetadata\": {\n \"vmId\": \"\ + 17881b39-b03f-4a2c-9b56-078be1330bd0\",\n \"cloudProvider\": \"Unknown\"\ + ,\n \"resourceId\": \"/subscriptions/29e73d07-8740-4164-a257-592a19a7b77c/resourceGroups/MSDXV2/providers/Microsoft.Compute/virtualMachines/MSDXV2-Win10V\"\ + ,\n \"subscriptionId\": \"29e73d07-8740-4164-a257-592a19a7b77c\"\n },\n\ + \ \"loggedOnUsers\": [\n {\n \"accountName\": \"hetfield\"\ + ,\n \"domainName\": \"MSDXV2\"\n }\n ]\n }\n ],\n \"entities\"\ + : [\n {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\":\ + \ \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\ + remediationStatus\": \"None\",\n \"sha1\": \"6cbce4a295c163791b60fc23d285e6d84f28ee4c\"\ + ,\n \"sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\"\ + ,\n \"fileName\": \"powershell.exe\",\n \"filePath\": \"\",\n \"\ + processId\": 7068,\n \"processCommandLine\": \"powershell.exe -command \\\"\ + \ $Process = New-Object\ + \ System.Diagnostics.Process; \ + \ $Process.StartInfo.FileName = 'https://nam12.safelinks.protection.outlook.com/?url=http%3A%2F%2Fgcajebahdi.corporatelogon.xyz%2Fab%2Fjnkmbkkdnlgedc&data=05%7C01%7Chetfield%40metal.m365dpoc.com%7Cca409616a82145bd6a5f08daa2a10255%7C1a49212958c8401191cd245285f5345c%7C0%7C0%7C638001109710345383%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=FyEjRS5qOd2SkJELlueibuxLFMYNjL7fz8EbuOAvFwg%3D&reserved=0';\ + \ $Process.StartInfo.UseShellExecute\ + \ = $true; $Process.Start()\ + \ | Out-Null; \\\" \ + \ \",\n \"processCreationTime\"\ + : \"2022-09-30T05:06:43.3390523Z\",\n \"parentProcessId\": 7116,\n \"\ + parentProcessCreationTime\": \"2022-09-30T05:06:43.3100364Z\",\n \"accountName\"\ + : \"hetfield\",\n \"userSid\": \"S-1-5-21-2300221942-1987151257-321556088-1104\"\ + \n },\n {\n \"entityType\": \"File\",\n \"evidenceCreationTime\"\ + : \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\ + remediationStatus\": \"None\",\n \"sha1\": \"6cbce4a295c163791b60fc23d285e6d84f28ee4c\"\ + ,\n \"sha256\": \"de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1b160ab32c\"\ + ,\n \"fileName\": \"powershell.exe\",\n \"filePath\": \"\"\n },\n \ + \ {\n \"entityType\": \"User\",\n \"evidenceCreationTime\": \"2022-09-30T05:36:50.2133333Z\"\ + ,\n \"verdict\": \"Suspicious\",\n \"remediationStatus\": \"None\",\n\ + \ \"accountName\": \"hetfield\",\n \"domainName\": \"metal.m365dpoc\"\ + ,\n \"userSid\": \"S-1-5-21-2300221942-1987151257-321556088-1104\",\n \ + \ \"aadUserId\": \"e848b07a-87af-4448-9979-09f0b809c8d4\",\n \"userPrincipalName\"\ + : \"daftpunk\"\n },\n {\n \"entityType\": \"Url\",\n \"evidenceCreationTime\"\ + : \"2022-09-30T05:36:50.2133333Z\",\n \"verdict\": \"Suspicious\",\n \"\ + remediationStatus\": \"None\",\n \"url\": \"http://gcajebahdi.corporatelogon.xyz/ab/jnkmbkkdnlgedc\"\ + \n }\n ]\n}" diff --git a/data_sources/ms_defender_atp_alerts.yml b/data_sources/ms_defender_atp_alerts.yml index f1f68b0b7e..f7429f3de6 100644 --- a/data_sources/ms_defender_atp_alerts.yml +++ b/data_sources/ms_defender_atp_alerts.yml @@ -6,424 +6,274 @@ author: Bryan Pluta, Bhavin Patel, Splunk description: Logs security alerts generated by Microsoft Defender for Endpoint, including information about detected threats, impacted devices, and recommended actions. mitre_components: - - Host Status - - Malware Metadata - - Process Metadata - - User Account Metadata - - Application Log Content +- Host Status +- Malware Metadata +- Process Metadata +- User Account Metadata +- Application Log Content source: ms_defender_atp_alerts sourcetype: ms:defender:atp:alerts supported_TA: - - name: Splunk Add-on for Microsoft Security - url: https://splunkbase.splunk.com/app/6207 - version: 2.4.1 +- name: Splunk Add-on for Microsoft Security + url: https://splunkbase.splunk.com/app/6207 + version: 2.4.1 fields: - - column - - accountName - - action - - activity - - activityType - - actor - - actorName - - alertId - - app - - assignedTo - - body - - category - - classification - - creationTime - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - description - - dest - - detectionSource - - detectorId - - determination - - devices{}.aadDeviceId - - devices{}.defenderAvStatus - - devices{}.deviceDnsName - - devices{}.firstSeen - - devices{}.healthStatus - - devices{}.loggedOnUsers{}.accountName - - devices{}.loggedOnUsers{}.domainName - - devices{}.mdatpDeviceId - - devices{}.onboardingStatus - - devices{}.osBuild - - devices{}.osPlatform - - devices{}.osProcessor - - devices{}.rbacGroupName - - devices{}.riskScore - - devices{}.version - - devices{}.vmMetadata - - devices{}.vmMetadata.cloudProvider - - devices{}.vmMetadata.resourceId - - devices{}.vmMetadata.subscriptionId - - devices{}.vmMetadata.vmId - - entities{}.aadUserId - - entities{}.accountName - - entities{}.applicationId - - entities{}.applicationName - - entities{}.detectionStatus - - entities{}.deviceId - - entities{}.domainName - - entities{}.entityType - - entities{}.evidenceCreationTime - - entities{}.fileName - - entities{}.filePath - - entities{}.ipAddress - - entities{}.parentProcessCreationTime - - entities{}.parentProcessFileName - - entities{}.parentProcessFilePath - - entities{}.parentProcessId - - entities{}.processCommandLine - - entities{}.processCreationTime - - entities{}.processId - - entities{}.remediationStatus - - entities{}.remediationStatusDetails - - entities{}.sha1 - - entities{}.sha256 - - entities{}.userPrincipalName - - entities{}.userSid - - entities{}.verdict - - eventtype - - firstActivity - - host - - id - - incidentId - - index - - investigationId - - investigationState - - lastActivity - - lastUpdatedTime - - linecount - - mitreTechniques{} - - mitre_technique_id - - providerAlertId - - resolvedTime - - serviceSource - - severity - - signature - - signature_id - - source - - sourcetype - - splunk_server - - splunk_server_group - - src - - status - - subject - - tag - - tag::app - - tag::eventtype - - threatFamilyName - - timeendpos - - timestartpos - - title - - type - - user - - user_name - - _time -example_log: |- - { - "id": "da47dc5671-e560-4229-984b-457564996b31_1", - "incidentId": 989, - "investigationId": null, - "assignedTo": null, - "severity": "High", - "status": "New", - "classification": null, - "determination": null, - "investigationState": "UnsupportedAlertType", - "detectionSource": "WindowsDefenderAtp", - "detectorId": "9c3a70ec-e18a-4f92-865a-530f73130b7c", - "category": "LateralMovement", - "threatFamilyName": null, - "title": "Ongoing hands-on-keyboard attack via Impacket toolkit", - "description": "Suspicious execution of a command via Impacket was observed on this device. This tool connects to other hosts to explore network shares and execute commands. Attackers might be attempting to move laterally across the network using this tool. This usage of Impacket has often been observed in hands-on-keyboard attacks, where ransomware and other payloads are installed on target devices.", - "alertCreationTime": "2023-01-24T05:33:37.3245808Z", - "firstEventTime": "2023-01-24T05:31:07.5276179Z", - "lastEventTime": "2023-01-24T13:02:50.7831636Z", - "lastUpdateTime": "2023-01-24T13:07:13.3233333Z", - "resolvedTime": null, - "machineId": "302293d9f276eae65553e5042156bce93cbc7148", - "computerDnsName": "diytestmachine", - "rbacGroupName": "UnassignedGroup", - "aadTenantId": "1a492129-58c8-4011-91cd-245285f5345c", - "threatName": null, - "mitreTechniques": [ - "T1021.002", - "T1047", - "T1059.003" - ], - "relatedUser": { - "userName": "User1", - "domainName": "DIYTESTMACHINE" - }, - "loggedOnUsers": [ - { - "accountName": "administrator1", - "domainName": "DIYTESTMACHINE" - } - ], - "comments": [], - "evidence": [ - { - "entityType": "Process", - "evidenceCreationTime": "2023-01-24T05:45:51.6833333Z", - "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c", - "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3", - "fileName": "WmiPrvSE.exe", - "filePath": "C:\\Windows\\System32\\wbem", - "processId": 4476, - "processCommandLine": "wmiprvse.exe -secured -Embedding", - "processCreationTime": "2023-01-24T05:43:32.4631151Z", - "parentProcessId": 896, - "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z", - "parentProcessFileName": "svchost.exe", - "parentProcessFilePath": "C:\\Windows\\System32", - "ipAddress": null, - "url": null, - "registryKey": null, - "registryHive": null, - "registryValueType": null, - "registryValue": null, - "registryValueName": null, - "accountName": "NETWORK SERVICE", - "domainName": "NT AUTHORITY", - "userSid": "S-1-5-20", - "aadUserId": null, - "userPrincipalName": null, - "detectionStatus": "Detected" - }, - { - "entityType": "User", - "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z", - "sha1": null, - "sha256": null, - "fileName": null, - "filePath": null, - "processId": null, - "processCommandLine": null, - "processCreationTime": null, - "parentProcessId": null, - "parentProcessCreationTime": null, - "parentProcessFileName": null, - "parentProcessFilePath": null, - "ipAddress": null, - "url": null, - "registryKey": null, - "registryHive": null, - "registryValueType": null, - "registryValue": null, - "registryValueName": null, - "accountName": "User1", - "domainName": "DIYTESTMACHINE", - "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002", - "aadUserId": null, - "userPrincipalName": null, - "detectionStatus": null - }, - { - "entityType": "Process", - "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z", - "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c", - "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3", - "fileName": "WmiPrvSE.exe", - "filePath": "C:\\Windows\\System32\\wbem", - "processId": 7824, - "processCommandLine": "wmiprvse.exe -secured -Embedding", - "processCreationTime": "2023-01-24T05:30:50.8649791Z", - "parentProcessId": 896, - "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z", - "parentProcessFileName": "svchost.exe", - "parentProcessFilePath": "C:\\Windows\\System32", - "ipAddress": null, - "url": null, - "registryKey": null, - "registryHive": null, - "registryValueType": null, - "registryValue": null, - "registryValueName": null, - "accountName": "NETWORK SERVICE", - "domainName": "NT AUTHORITY", - "userSid": "S-1-5-20", - "aadUserId": null, - "userPrincipalName": null, - "detectionStatus": "Detected" - }, - { - "entityType": "Process", - "evidenceCreationTime": "2023-01-24T13:07:13.2233333Z", - "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d", - "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450", - "fileName": "cmd.exe", - "filePath": "C:\\Windows\\System32", - "processId": 5500, - "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674565222.7012053 2>&1", - "processCreationTime": "2023-01-24T13:02:50.4661885Z", - "parentProcessId": 756, - "parentProcessCreationTime": "2023-01-24T13:00:35.0107475Z", - "parentProcessFileName": "WmiPrvSE.exe", - "parentProcessFilePath": "C:\\Windows\\System32\\wbem", - "ipAddress": null, - "url": null, - "registryKey": null, - "registryHive": null, - "registryValueType": null, - "registryValue": null, - "registryValueName": null, - "accountName": "User1", - "domainName": "DIYTESTMACHINE", - "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002", - "aadUserId": null, - "userPrincipalName": null, - "detectionStatus": "Detected" - }, - { - "entityType": "Process", - "evidenceCreationTime": "2023-01-24T05:33:37.4166667Z", - "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d", - "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450", - "fileName": "cmd.exe", - "filePath": "C:\\Windows\\System32", - "processId": 8964, - "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538248.357367 2>&1", - "processCreationTime": "2023-01-24T05:31:04.0743902Z", - "parentProcessId": 7824, - "parentProcessCreationTime": "2023-01-24T05:30:50.8649791Z", - "parentProcessFileName": "WmiPrvSE.exe", - "parentProcessFilePath": "C:\\Windows\\System32\\wbem", - "ipAddress": null, - "url": null, - "registryKey": null, - "registryHive": null, - "registryValueType": null, - "registryValue": null, - "registryValueName": null, - "accountName": "User1", - "domainName": "DIYTESTMACHINE", - "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002", - "aadUserId": null, - "userPrincipalName": null, - "detectionStatus": "Detected" - }, - { - "entityType": "Process", - "evidenceCreationTime": "2023-01-24T05:39:47.1733333Z", - "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d", - "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450", - "fileName": "cmd.exe", - "filePath": "C:\\Windows\\System32", - "processId": 884, - "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538583.8648584 2>&1", - "processCreationTime": "2023-01-24T05:36:38.826505Z", - "parentProcessId": 7736, - "parentProcessCreationTime": "2023-01-24T05:36:26.0524655Z", - "parentProcessFileName": "WmiPrvSE.exe", - "parentProcessFilePath": "C:\\Windows\\System32\\wbem", - "ipAddress": null, - "url": null, - "registryKey": null, - "registryHive": null, - "registryValueType": null, - "registryValue": null, - "registryValueName": null, - "accountName": "User1", - "domainName": "DIYTESTMACHINE", - "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002", - "aadUserId": null, - "userPrincipalName": null, - "detectionStatus": "Detected" - }, - { - "entityType": "Process", - "evidenceCreationTime": "2023-01-24T13:07:13.2233333Z", - "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c", - "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3", - "fileName": "WmiPrvSE.exe", - "filePath": "C:\\Windows\\System32\\wbem", - "processId": 756, - "processCommandLine": "wmiprvse.exe -secured -Embedding", - "processCreationTime": "2023-01-24T13:00:35.0107475Z", - "parentProcessId": 908, - "parentProcessCreationTime": "2023-01-24T08:20:44.6877667Z", - "parentProcessFileName": "svchost.exe", - "parentProcessFilePath": "C:\\Windows\\System32", - "ipAddress": null, - "url": null, - "registryKey": null, - "registryHive": null, - "registryValueType": null, - "registryValue": null, - "registryValueName": null, - "accountName": "NETWORK SERVICE", - "domainName": "NT AUTHORITY", - "userSid": "S-1-5-20", - "aadUserId": null, - "userPrincipalName": null, - "detectionStatus": "Detected" - }, - { - "entityType": "Process", - "evidenceCreationTime": "2023-01-24T05:45:51.6833333Z", - "sha1": "f1efb0fddc156e4c61c5f78a54700e4e7984d55d", - "sha256": "b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450", - "fileName": "cmd.exe", - "filePath": "C:\\Windows\\System32", - "processId": 1140, - "processCommandLine": "cmd.exe /Q /c powershell -NoProfile -ExecutionPolicy Bypass -File \"C:\\Users\\administrator1\\Desktop\\SharedFolder\\payload.ps1\" 1> \\\\127.0.0.1\\SharedFolder\\__1674538878.1586335 2>&1", - "processCreationTime": "2023-01-24T05:43:49.9375398Z", - "parentProcessId": 4476, - "parentProcessCreationTime": "2023-01-24T05:43:32.4631151Z", - "parentProcessFileName": "WmiPrvSE.exe", - "parentProcessFilePath": "C:\\Windows\\System32\\wbem", - "ipAddress": null, - "url": null, - "registryKey": null, - "registryHive": null, - "registryValueType": null, - "registryValue": null, - "registryValueName": null, - "accountName": "User1", - "domainName": "DIYTESTMACHINE", - "userSid": "S-1-5-21-4215714199-1288013905-3478400915-1002", - "aadUserId": null, - "userPrincipalName": null, - "detectionStatus": "Detected" - }, - { - "entityType": "Process", - "evidenceCreationTime": "2023-01-24T05:39:47.1733333Z", - "sha1": "3ea7cc066317ac45f963c2227c4c7c50aa16eb7c", - "sha256": "2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3", - "fileName": "WmiPrvSE.exe", - "filePath": "C:\\Windows\\System32\\wbem", - "processId": 7736, - "processCommandLine": "wmiprvse.exe -secured -Embedding", - "processCreationTime": "2023-01-24T05:36:26.0524655Z", - "parentProcessId": 896, - "parentProcessCreationTime": "2023-01-24T04:44:17.1940386Z", - "parentProcessFileName": "svchost.exe", - "parentProcessFilePath": "C:\\Windows\\System32", - "ipAddress": null, - "url": null, - "registryKey": null, - "registryHive": null, - "registryValueType": null, - "registryValue": null, - "registryValueName": null, - "accountName": "NETWORK SERVICE", - "domainName": "NT AUTHORITY", - "userSid": "S-1-5-20", - "aadUserId": null, - "userPrincipalName": null, - "detectionStatus": "Detected" - } - ], - "domains": [] - } +- column +- accountName +- action +- activity +- activityType +- actor +- actorName +- alertId +- app +- assignedTo +- body +- category +- classification +- creationTime +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- description +- dest +- detectionSource +- detectorId +- determination +- devices{}.aadDeviceId +- devices{}.defenderAvStatus +- devices{}.deviceDnsName +- devices{}.firstSeen +- devices{}.healthStatus +- devices{}.loggedOnUsers{}.accountName +- devices{}.loggedOnUsers{}.domainName +- devices{}.mdatpDeviceId +- devices{}.onboardingStatus +- devices{}.osBuild +- devices{}.osPlatform +- devices{}.osProcessor +- devices{}.rbacGroupName +- devices{}.riskScore +- devices{}.version +- devices{}.vmMetadata +- devices{}.vmMetadata.cloudProvider +- devices{}.vmMetadata.resourceId +- devices{}.vmMetadata.subscriptionId +- devices{}.vmMetadata.vmId +- entities{}.aadUserId +- entities{}.accountName +- entities{}.applicationId +- entities{}.applicationName +- entities{}.detectionStatus +- entities{}.deviceId +- entities{}.domainName +- entities{}.entityType +- entities{}.evidenceCreationTime +- entities{}.fileName +- entities{}.filePath +- entities{}.ipAddress +- entities{}.parentProcessCreationTime +- entities{}.parentProcessFileName +- entities{}.parentProcessFilePath +- entities{}.parentProcessId +- entities{}.processCommandLine +- entities{}.processCreationTime +- entities{}.processId +- entities{}.remediationStatus +- entities{}.remediationStatusDetails +- entities{}.sha1 +- entities{}.sha256 +- entities{}.userPrincipalName +- entities{}.userSid +- entities{}.verdict +- eventtype +- firstActivity +- host +- id +- incidentId +- index +- investigationId +- investigationState +- lastActivity +- lastUpdatedTime +- linecount +- mitreTechniques{} +- mitre_technique_id +- providerAlertId +- resolvedTime +- serviceSource +- severity +- signature +- signature_id +- source +- sourcetype +- splunk_server +- splunk_server_group +- src +- status +- subject +- tag +- tag::app +- tag::eventtype +- threatFamilyName +- timeendpos +- timestartpos +- title +- type +- user +- user_name +- _time +example_log: "{\n\"id\": \"da47dc5671-e560-4229-984b-457564996b31_1\",\n\"incidentId\"\ + : 989,\n\"investigationId\": null,\n\"assignedTo\": null,\n\"severity\": \"High\"\ + ,\n\"status\": \"New\",\n\"classification\": null,\n\"determination\": null,\n\"\ + investigationState\": \"UnsupportedAlertType\",\n\"detectionSource\": \"WindowsDefenderAtp\"\ + ,\n\"detectorId\": \"9c3a70ec-e18a-4f92-865a-530f73130b7c\",\n\"category\": \"LateralMovement\"\ + ,\n\"threatFamilyName\": null,\n\"title\": \"Ongoing hands-on-keyboard attack via\ + \ Impacket toolkit\",\n\"description\": \"Suspicious execution of a command via\ + \ Impacket was observed on this device. This tool connects to other hosts to explore\ + \ network shares and execute commands. Attackers might be attempting to move laterally\ + \ across the network using this tool. This usage of Impacket has often been observed\ + \ in hands-on-keyboard attacks, where ransomware and other payloads are installed\ + \ on target devices.\",\n\"alertCreationTime\": \"2023-01-24T05:33:37.3245808Z\"\ + ,\n\"firstEventTime\": \"2023-01-24T05:31:07.5276179Z\",\n\"lastEventTime\": \"\ + 2023-01-24T13:02:50.7831636Z\",\n\"lastUpdateTime\": \"2023-01-24T13:07:13.3233333Z\"\ + ,\n\"resolvedTime\": null,\n\"machineId\": \"302293d9f276eae65553e5042156bce93cbc7148\"\ + ,\n\"computerDnsName\": \"diytestmachine\",\n\"rbacGroupName\": \"UnassignedGroup\"\ + ,\n\"aadTenantId\": \"1a492129-58c8-4011-91cd-245285f5345c\",\n\"threatName\": null,\n\ + \"mitreTechniques\": [\n \"T1021.002\",\n \"T1047\",\n \"T1059.003\"\n],\n\"\ + relatedUser\": {\n \"userName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\"\ + \n},\n\"loggedOnUsers\": [\n {\n \"accountName\": \"administrator1\",\n \"\ + domainName\": \"DIYTESTMACHINE\"\n }\n],\n\"comments\": [],\n\"evidence\": [\n\ + \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:45:51.6833333Z\"\ + ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\ + \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\ + fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\ + wbem\",\n \"processId\": 4476,\n \"processCommandLine\": \"wmiprvse.exe -secured\ + \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:43:32.4631151Z\",\n\ + \ \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\ + ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\ + : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\ + \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ + : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ + accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \ + \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\ + : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\ + User\",\n \"evidenceCreationTime\": \"2023-01-24T05:33:37.4166667Z\",\n \"\ + sha1\": null,\n \"sha256\": null,\n \"fileName\": null,\n \"filePath\"\ + : null,\n \"processId\": null,\n \"processCommandLine\": null,\n \"processCreationTime\"\ + : null,\n \"parentProcessId\": null,\n \"parentProcessCreationTime\": null,\n\ + \ \"parentProcessFileName\": null,\n \"parentProcessFilePath\": null,\n \ + \ \"ipAddress\": null,\n \"url\": null,\n \"registryKey\": null,\n \"\ + registryHive\": null,\n \"registryValueType\": null,\n \"registryValue\":\ + \ null,\n \"registryValueName\": null,\n \"accountName\": \"User1\",\n \ + \ \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\": \"S-1-5-21-4215714199-1288013905-3478400915-1002\"\ + ,\n \"aadUserId\": null,\n \"userPrincipalName\": null,\n \"detectionStatus\"\ + : null\n },\n {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\"\ + : \"2023-01-24T05:33:37.4166667Z\",\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\"\ + ,\n \"sha256\": \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\"\ + ,\n \"fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\ + \\wbem\",\n \"processId\": 7824,\n \"processCommandLine\": \"wmiprvse.exe\ + \ -secured -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:30:50.8649791Z\"\ + ,\n \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\ + ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\ + : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\ + \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ + : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ + accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \ + \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\ + : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\ + Process\",\n \"evidenceCreationTime\": \"2023-01-24T13:07:13.2233333Z\",\n \ + \ \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\": \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\"\ + ,\n \"fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\"\ + ,\n \"processId\": 5500,\n \"processCommandLine\": \"cmd.exe /Q /c powershell\ + \ -NoProfile -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\\ + Desktop\\\\SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\ + \\__1674565222.7012053 2>&1\",\n \"processCreationTime\": \"2023-01-24T13:02:50.4661885Z\"\ + ,\n \"parentProcessId\": 756,\n \"parentProcessCreationTime\": \"2023-01-24T13:00:35.0107475Z\"\ + ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\ + : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\ + : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ + : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ + accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\ + : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\ + \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\ + \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:33:37.4166667Z\"\ + ,\n \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\":\ + \ \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\",\n \"\ + fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\",\n \ + \ \"processId\": 8964,\n \"processCommandLine\": \"cmd.exe /Q /c powershell -NoProfile\ + \ -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\Desktop\\\\\ + SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\\__1674538248.357367\ + \ 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:31:04.0743902Z\",\n \"\ + parentProcessId\": 7824,\n \"parentProcessCreationTime\": \"2023-01-24T05:30:50.8649791Z\"\ + ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\ + : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\ + : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ + : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ + accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\ + : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\ + \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\ + \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:39:47.1733333Z\"\ + ,\n \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\":\ + \ \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\",\n \"\ + fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\",\n \ + \ \"processId\": 884,\n \"processCommandLine\": \"cmd.exe /Q /c powershell -NoProfile\ + \ -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\Desktop\\\\\ + SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\\__1674538583.8648584\ + \ 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:36:38.826505Z\",\n \"\ + parentProcessId\": 7736,\n \"parentProcessCreationTime\": \"2023-01-24T05:36:26.0524655Z\"\ + ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\ + : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\ + : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ + : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ + accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\ + : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\ + \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\ + \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T13:07:13.2233333Z\"\ + ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\ + \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\ + fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\ + wbem\",\n \"processId\": 756,\n \"processCommandLine\": \"wmiprvse.exe -secured\ + \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T13:00:35.0107475Z\",\n\ + \ \"parentProcessId\": 908,\n \"parentProcessCreationTime\": \"2023-01-24T08:20:44.6877667Z\"\ + ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\ + : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\ + \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ + : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ + accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \ + \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\ + : null,\n \"detectionStatus\": \"Detected\"\n },\n {\n \"entityType\": \"\ + Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:45:51.6833333Z\",\n \ + \ \"sha1\": \"f1efb0fddc156e4c61c5f78a54700e4e7984d55d\",\n \"sha256\": \"b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450\"\ + ,\n \"fileName\": \"cmd.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\"\ + ,\n \"processId\": 1140,\n \"processCommandLine\": \"cmd.exe /Q /c powershell\ + \ -NoProfile -ExecutionPolicy Bypass -File \\\"C:\\\\Users\\\\administrator1\\\\\ + Desktop\\\\SharedFolder\\\\payload.ps1\\\" 1> \\\\\\\\127.0.0.1\\\\SharedFolder\\\ + \\__1674538878.1586335 2>&1\",\n \"processCreationTime\": \"2023-01-24T05:43:49.9375398Z\"\ + ,\n \"parentProcessId\": 4476,\n \"parentProcessCreationTime\": \"2023-01-24T05:43:32.4631151Z\"\ + ,\n \"parentProcessFileName\": \"WmiPrvSE.exe\",\n \"parentProcessFilePath\"\ + : \"C:\\\\Windows\\\\System32\\\\wbem\",\n \"ipAddress\": null,\n \"url\"\ + : null,\n \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ + : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ + accountName\": \"User1\",\n \"domainName\": \"DIYTESTMACHINE\",\n \"userSid\"\ + : \"S-1-5-21-4215714199-1288013905-3478400915-1002\",\n \"aadUserId\": null,\n\ + \ \"userPrincipalName\": null,\n \"detectionStatus\": \"Detected\"\n },\n\ + \ {\n \"entityType\": \"Process\",\n \"evidenceCreationTime\": \"2023-01-24T05:39:47.1733333Z\"\ + ,\n \"sha1\": \"3ea7cc066317ac45f963c2227c4c7c50aa16eb7c\",\n \"sha256\":\ + \ \"2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3\",\n \"\ + fileName\": \"WmiPrvSE.exe\",\n \"filePath\": \"C:\\\\Windows\\\\System32\\\\\ + wbem\",\n \"processId\": 7736,\n \"processCommandLine\": \"wmiprvse.exe -secured\ + \ -Embedding\",\n \"processCreationTime\": \"2023-01-24T05:36:26.0524655Z\",\n\ + \ \"parentProcessId\": 896,\n \"parentProcessCreationTime\": \"2023-01-24T04:44:17.1940386Z\"\ + ,\n \"parentProcessFileName\": \"svchost.exe\",\n \"parentProcessFilePath\"\ + : \"C:\\\\Windows\\\\System32\",\n \"ipAddress\": null,\n \"url\": null,\n\ + \ \"registryKey\": null,\n \"registryHive\": null,\n \"registryValueType\"\ + : null,\n \"registryValue\": null,\n \"registryValueName\": null,\n \"\ + accountName\": \"NETWORK SERVICE\",\n \"domainName\": \"NT AUTHORITY\",\n \ + \ \"userSid\": \"S-1-5-20\",\n \"aadUserId\": null,\n \"userPrincipalName\"\ + : null,\n \"detectionStatus\": \"Detected\"\n }\n],\n\"domains\": []\n}" diff --git a/data_sources/nginx_access.yml b/data_sources/nginx_access.yml index e24bb4163c..c7b491e28c 100644 --- a/data_sources/nginx_access.yml +++ b/data_sources/nginx_access.yml @@ -6,74 +6,74 @@ author: Patrick Bareiss, Splunk description: Logs HTTP/S access events on an Nginx server, including details such as client IP, request method, URI, response status, and user agent. mitre_components: - - Network Traffic Content - - Network Traffic Flow - - Response Metadata - - Application Log Content - - User Account Metadata +- Network Traffic Content +- Network Traffic Flow +- Response Metadata +- Application Log Content +- User Account Metadata source: /var/log/nginx/access.log sourcetype: nginx:plus:kv supported_TA: [] fields: - - _time - - action - - app - - bytes - - bytes_in - - bytes_out - - category - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_ip - - dest_port - - eventtype - - host - - http_content_type - - http_method - - http_referer - - http_user_agent - - http_user_agent_length - - http_x_forwarded_for - - http_x_header - - https - - index - - linecount - - nginx_version - - product - - protocol - - punct - - request_time - - response_time - - server - - site - - source - - sourcetype - - splunk_server - - src - - src_ip - - status - - status_description - - status_type - - tag - - tag::eventtype - - time_local - - timeendpos - - timestartpos - - uri_path - - url - - url_domain - - url_length - - vendor - - vendor_product - - version - - web_server +- _time +- action +- app +- bytes +- bytes_in +- bytes_out +- category +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_ip +- dest_port +- eventtype +- host +- http_content_type +- http_method +- http_referer +- http_user_agent +- http_user_agent_length +- http_x_forwarded_for +- http_x_header +- https +- index +- linecount +- nginx_version +- product +- protocol +- punct +- request_time +- response_time +- server +- site +- source +- sourcetype +- splunk_server +- src +- src_ip +- status +- status_description +- status_type +- tag +- tag::eventtype +- time_local +- timeendpos +- timestartpos +- uri_path +- url +- url_domain +- url_length +- vendor +- vendor_product +- version +- web_server example_log: site="www.example.com" server="www.example.com" dest_port="443" dest_ip="192.0.2.1" src="198.51.100.1" src_ip="198.51.100.1" user="-" time_local="22/Feb/2024:13:00:00 -0500" protocol="HTTP/1.1" status="200" bytes_out="1073741000" bytes_in="234" http_referer="-" diff --git a/data_sources/o365.yml b/data_sources/o365.yml index 3bda514d41..36c3c9bc2a 100644 --- a/data_sources/o365.yml +++ b/data_sources/o365.yml @@ -6,15 +6,15 @@ author: Patrick Bareiss, Splunk description: Logs management activities in Microsoft 365, including administrative actions, user activities, and configuration changes across various services. mitre_components: - - User Account Metadata - - Cloud Service Modification - - Application Log Content - - Configuration Modification - - Active Directory Object Modification +- User Account Metadata +- Cloud Service Modification +- Application Log Content +- Configuration Modification +- Active Directory Object Modification source: o365 sourcetype: o365:management:activity separator: Operation supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 diff --git a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml index a6e90c409a..d97086d833 100644 --- a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml +++ b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml @@ -6,88 +6,88 @@ author: Patrick Bareiss, Splunk description: Logs the assignment of an application role grant to a user in Microsoft 365, including details about the role, user, and application involved. mitre_components: - - User Account Modification - - Group Modification - - Cloud Service Modification - - Cloud Service Metadata +- User Account Modification +- Group Modification +- Cloud Service Modification +- Cloud Service Metadata source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add app role assignment grant to user. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - ActorIpAddress - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - ClientIP - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ModifiedProperties{}.Name - - ModifiedProperties{}.NewValue - - ModifiedProperties{}.OldValue - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - additionalDetails - - app - - authentication_service - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - extendedAuditEventCategory - - extended_properties - - host - - index - - linecount - - object - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - src - - src_ip - - src_user - - status - - timeendpos - - timestartpos - - user - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- ActorIpAddress +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- ClientIP +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ModifiedProperties{}.Name +- ModifiedProperties{}.NewValue +- ModifiedProperties{}.OldValue +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- additionalDetails +- app +- authentication_service +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- extendedAuditEventCategory +- extended_properties +- host +- index +- linecount +- object +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- src +- src_ip +- src_user +- status +- timeendpos +- timestartpos +- user +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"Actor": [{"ID": "rodsoto@rodsoto.onmicrosoft.com", "Type": 5}, {"ID": "10037FFEA938FB92", "Type": 3}, {"ID": "74658136-14ec-4630-ad9b-26e160ff0fc6", "Type": 2}, {"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484", "Type": 2}, {"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484", diff --git a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml index 720652a539..250a21a230 100644 --- a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml +++ b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml @@ -7,87 +7,87 @@ description: Logs the assignment of an application role to a service principal i Microsoft 365, including details about the role, service principal, and application involved. mitre_components: - - Cloud Service Modification - - Cloud Service Metadata - - User Account Metadata - - Group Modification +- Cloud Service Modification +- Cloud Service Metadata +- User Account Metadata +- Group Modification source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add app role assignment to service principal. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ModifiedProperties{}.Name - - ModifiedProperties{}.NewValue - - ModifiedProperties{}.OldValue - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - additionalDetails - - app - - authentication_service - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - eventtype - - extendedAuditEventCategory - - host - - index - - linecount - - object - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_agent - - user_agent_change - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ModifiedProperties{}.Name +- ModifiedProperties{}.NewValue +- ModifiedProperties{}.OldValue +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- additionalDetails +- app +- authentication_service +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- eventtype +- extendedAuditEventCategory +- host +- index +- linecount +- object +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_agent +- user_agent_change +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2024-02-08T21:49:53", "Id": "a6bee61d-8b3f-42e1-b4fa-778fb05c43ac", "Operation": "Add app role assignment to service principal.", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "RecordType": 8, "ResultStatus": "Success", diff --git a/data_sources/o365_add_mailboxpermission.yml b/data_sources/o365_add_mailboxpermission.yml index 09a36817fe..191c1d0e6b 100644 --- a/data_sources/o365_add_mailboxpermission.yml +++ b/data_sources/o365_add_mailboxpermission.yml @@ -7,79 +7,79 @@ description: Logs the addition of mailbox permissions in Microsoft 365, includin details about the mailbox, granted permissions, and the user or administrator performing the action. mitre_components: - - User Account Modification - - User Account Metadata - - Active Directory Object Modification - - Application Log Content +- User Account Modification +- User Account Metadata +- Active Directory Object Modification +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add-MailboxPermission supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - AccessRights - - AppId - - ClientAppId - - ClientIP - - CreationTime - - ExternalAccess - - Id - - Identity - - InheritanceType - - ObjectId - - Operation - - OrganizationId - - OrganizationName - - OriginatingServer - - Parameters{}.Name - - Parameters{}.Value - - RecordType - - ResultStatus - - SessionId - - User - - UserId - - UserKey - - UserType - - Version - - Workload - - app - - authentication_service - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - host - - index - - linecount - - object - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - src - - src_ip - - status - - timeendpos - - timestartpos - - user - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- AccessRights +- AppId +- ClientAppId +- ClientIP +- CreationTime +- ExternalAccess +- Id +- Identity +- InheritanceType +- ObjectId +- Operation +- OrganizationId +- OrganizationName +- OriginatingServer +- Parameters{}.Name +- Parameters{}.Value +- RecordType +- ResultStatus +- SessionId +- User +- UserId +- UserKey +- UserType +- Version +- Workload +- app +- authentication_service +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- host +- index +- linecount +- object +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- src +- src_ip +- status +- timeendpos +- timestartpos +- user +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"AppId": "", "ClientAppId": "", "ClientIP": "18.159.234.121:30395", "CreationTime": "2020-12-15T10:18:53", "ExternalAccess": false, "Id": "bb6e31a3-e98f-493d-bbff-08d8a0e2d2b0", "ObjectId": "jhernan", "Operation": "Add-MailboxPermission", "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08", diff --git a/data_sources/o365_add_member_to_role_.yml b/data_sources/o365_add_member_to_role_.yml index 7a6ea65406..29145e6d5b 100644 --- a/data_sources/o365_add_member_to_role_.yml +++ b/data_sources/o365_add_member_to_role_.yml @@ -6,90 +6,90 @@ author: Patrick Bareiss, Splunk description: Logs the addition of a member to a role in Microsoft 365, including details about the role, the added member, and the user or administrator performing the action. mitre_components: - - Group Modification - - Group Metadata - - User Account Metadata - - Cloud Service Modification +- Group Modification +- Group Metadata +- User Account Metadata +- Cloud Service Modification source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add member to role. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ModifiedProperties{}.Name - - ModifiedProperties{}.NewValue - - ModifiedProperties{}.OldValue - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - action - - additionalDetails - - app - - authentication_service - - change_type - - command - - dataset_name - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - eventtype - - extendedAuditEventCategory - - host - - index - - linecount - - object - - object_attrs - - object_category - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ModifiedProperties{}.Name +- ModifiedProperties{}.NewValue +- ModifiedProperties{}.OldValue +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- action +- additionalDetails +- app +- authentication_service +- change_type +- command +- dataset_name +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- eventtype +- extendedAuditEventCategory +- host +- index +- linecount +- object +- object_attrs +- object_category +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2023-10-20T16:50:46", "Id": "30a8b107-b190-406c-9b80-c3f5c3a29129", "Operation": "Add member to role.", "OrganizationId": "d8211c86-3244-409b-8c4f-ae27ed34b4a5", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com", diff --git a/data_sources/o365_add_owner_to_application_.yml b/data_sources/o365_add_owner_to_application_.yml index 5c3b3c7f4b..dd7f2632d4 100644 --- a/data_sources/o365_add_owner_to_application_.yml +++ b/data_sources/o365_add_owner_to_application_.yml @@ -7,92 +7,92 @@ description: Logs the addition of an owner to an application in Microsoft 365, i details about the application, the new owner, and the user or administrator performing the action. mitre_components: - - User Account Modification - - Group Modification - - Cloud Service Modification - - Cloud Service Metadata +- User Account Modification +- Group Modification +- Cloud Service Modification +- Cloud Service Metadata source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add owner to application. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ModifiedProperties{}.Name - - ModifiedProperties{}.NewValue - - ModifiedProperties{}.OldValue - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - action - - additionalDetails - - app - - authentication_service - - change_type - - command - - dataset_name - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - eventtype - - extendedAuditEventCategory - - host - - index - - linecount - - object - - object_attrs - - object_category - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_agent - - user_agent_change - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ModifiedProperties{}.Name +- ModifiedProperties{}.NewValue +- ModifiedProperties{}.OldValue +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- action +- additionalDetails +- app +- authentication_service +- change_type +- command +- dataset_name +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- eventtype +- extendedAuditEventCategory +- host +- index +- linecount +- object +- object_attrs +- object_category +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_agent +- user_agent_change +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2023-09-07T13:42:04", "Id": "6e2c723b-8f6e-47f4-8c60-fa23ef3fccee", "Operation": "Add owner to application.", "OrganizationId": "48203edf-5d2c-45f2-8123-a368cc8b0e51", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com", diff --git a/data_sources/o365_add_service_principal_.yml b/data_sources/o365_add_service_principal_.yml index 806ce7eda5..8f4af7e270 100644 --- a/data_sources/o365_add_service_principal_.yml +++ b/data_sources/o365_add_service_principal_.yml @@ -6,92 +6,92 @@ author: Patrick Bareiss, Splunk description: Logs the addition of a new service principal in Microsoft 365, including details about the associated application and the action initiator. mitre_components: - - Cloud Service Creation - - Cloud Service Metadata - - User Account Metadata - - Active Directory Object Creation +- Cloud Service Creation +- Cloud Service Metadata +- User Account Metadata +- Active Directory Object Creation source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Add service principal. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ModifiedProperties{}.Name - - ModifiedProperties{}.NewValue - - ModifiedProperties{}.OldValue - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - action - - additionalDetails - - app - - authentication_service - - change_type - - command - - dataset_name - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - eventtype - - extendedAuditEventCategory - - host - - index - - linecount - - object_attrs - - object_category - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - src_user - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_agent - - user_agent_change - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ModifiedProperties{}.Name +- ModifiedProperties{}.NewValue +- ModifiedProperties{}.OldValue +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- action +- additionalDetails +- app +- authentication_service +- change_type +- command +- dataset_name +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- eventtype +- extendedAuditEventCategory +- host +- index +- linecount +- object_attrs +- object_category +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- src_user +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_agent +- user_agent_change +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2024-02-07T22:31:14", "Id": "f624ed92-b4a2-4d42-aa8b-20a261d06b7f", "Operation": "Add service principal.", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com", diff --git a/data_sources/o365_change_user_license_.yml b/data_sources/o365_change_user_license_.yml index cec6ea1cc1..d26262857c 100644 --- a/data_sources/o365_change_user_license_.yml +++ b/data_sources/o365_change_user_license_.yml @@ -6,88 +6,88 @@ author: Patrick Bareiss, Splunk description: Logs changes to user licenses in Microsoft 365, including additions, removals, or updates to service plans associated with a user account. mitre_components: - - User Account Modification - - User Account Metadata - - Cloud Service Modification - - Configuration Modification +- User Account Modification +- User Account Metadata +- Cloud Service Modification +- Configuration Modification source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Change user license. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - action - - additionalDetails - - app - - authentication_service - - change_type - - command - - dataset_name - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - eventtype - - extendedAuditEventCategory - - host - - index - - linecount - - object - - object_attrs - - object_category - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - src_user - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- action +- additionalDetails +- app +- authentication_service +- change_type +- command +- dataset_name +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- eventtype +- extendedAuditEventCategory +- host +- index +- linecount +- object +- object_attrs +- object_category +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- src_user +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2023-09-11T15:55:46", "Id": "1e39f32d-081d-4494-994a-533b57f91df7", "Operation": "Change user license.", "OrganizationId": "bbad9541-eb53-4533-bcef-2b76182c3b75", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com", diff --git a/data_sources/o365_consent_to_application_.yml b/data_sources/o365_consent_to_application_.yml index 9a8aacafcd..5698a08a0d 100644 --- a/data_sources/o365_consent_to_application_.yml +++ b/data_sources/o365_consent_to_application_.yml @@ -7,84 +7,84 @@ description: Logs user or administrator consent to an application's permissions Microsoft 365, including details about the application, granted permissions, and the consenting user or process. mitre_components: - - User Account Modification - - Cloud Service Modification - - Cloud Service Metadata - - Configuration Modification +- User Account Modification +- Cloud Service Modification +- Cloud Service Metadata +- Configuration Modification source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Consent to application. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ModifiedProperties{}.Name - - ModifiedProperties{}.NewValue - - ModifiedProperties{}.OldValue - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - additionalDetails - - app - - authentication_service - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - extendedAuditEventCategory - - host - - index - - linecount - - object - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - status - - timeendpos - - timestartpos - - user - - user_agent - - user_agent_change - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ModifiedProperties{}.Name +- ModifiedProperties{}.NewValue +- ModifiedProperties{}.OldValue +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- additionalDetails +- app +- authentication_service +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- extendedAuditEventCategory +- host +- index +- linecount +- object +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- status +- timeendpos +- timestartpos +- user +- user_agent +- user_agent_change +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2023-09-05T21:05:31", "Id": "5822e126-1fbc-4269-9ad6-4c1879cdbcf3", "Operation": "Consent to application.", "OrganizationId": "9c00a473-1b2c-4bc2-9215-84df3f57aee5", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com", diff --git a/data_sources/o365_disable_strong_authentication_.yml b/data_sources/o365_disable_strong_authentication_.yml index bd40f2eca5..8682551f6c 100644 --- a/data_sources/o365_disable_strong_authentication_.yml +++ b/data_sources/o365_disable_strong_authentication_.yml @@ -7,85 +7,85 @@ description: Logs the disabling of strong authentication (e.g., multi-factor aut for a user or group in Microsoft 365, including details about the affected accounts and the action initiator. mitre_components: - - User Account Modification - - Group Modification - - Configuration Modification - - Application Log Content +- User Account Modification +- Group Modification +- Configuration Modification +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Disable Strong Authentication. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - ActorIpAddress - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - ClientIP - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ModifiedProperties{}.Name - - ModifiedProperties{}.NewValue - - ModifiedProperties{}.OldValue - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - additionalDetails - - app - - authentication_service - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - extendedAuditEventCategory - - extended_properties - - host - - index - - linecount - - object - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - status - - timeendpos - - timestartpos - - user - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- ActorIpAddress +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- ClientIP +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ModifiedProperties{}.Name +- ModifiedProperties{}.NewValue +- ModifiedProperties{}.OldValue +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- additionalDetails +- app +- authentication_service +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- extendedAuditEventCategory +- extended_properties +- host +- index +- linecount +- object +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- status +- timeendpos +- timestartpos +- user +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"Actor": [{"ID": "rodsoto@rodsoto.onmicrosoft.com", "Type": 5}, {"ID": "10037FFEA938FB92", "Type": 3}, {"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484", "Type": 2}, {"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484", "Type": 2}, {"ID": "User", diff --git a/data_sources/o365_mailitemsaccessed.yml b/data_sources/o365_mailitemsaccessed.yml index 49429c5898..e1c6afc695 100644 --- a/data_sources/o365_mailitemsaccessed.yml +++ b/data_sources/o365_mailitemsaccessed.yml @@ -6,81 +6,81 @@ author: Patrick Bareiss, Splunk description: Logs access to mailbox items in Microsoft 365, including details about the user accessing the items, the accessed content, and the method of access. mitre_components: - - File Access - - User Account Metadata - - Application Log Content - - Active Directory Object Access +- File Access +- User Account Metadata +- Application Log Content +- Active Directory Object Access source: o365 sourcetype: o365:management:activity separator: Operation separator_value: MailItemsAccessed supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - AppId - - ClientAppId - - ClientIPAddress - - ClientInfoString - - CreationTime - - ExternalAccess - - Folders{}.FolderItems{}.InternetMessageId - - Folders{}.FolderItems{}.SizeInBytes - - Folders{}.Id - - Folders{}.Path - - Id - - InternalLogonType - - IsThrottled - - LogonType - - LogonUserSid - - MailAccessType - - MailboxGuid - - MailboxOwnerSid - - MailboxOwnerUPN - - Operation - - OperationCount - - OperationProperties{}.Name - - OperationProperties{}.Value - - OrganizationId - - OrganizationName - - OriginatingServer - - RecordType - - ResultStatus - - UserId - - UserKey - - UserType - - Version - - Workload - - app - - authentication_service - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dvc - - host - - index - - linecount - - punct - - signature - - source - - sourcetype - - splunk_server - - status - - timeendpos - - timestartpos - - user - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- AppId +- ClientAppId +- ClientIPAddress +- ClientInfoString +- CreationTime +- ExternalAccess +- Folders{}.FolderItems{}.InternetMessageId +- Folders{}.FolderItems{}.SizeInBytes +- Folders{}.Id +- Folders{}.Path +- Id +- InternalLogonType +- IsThrottled +- LogonType +- LogonUserSid +- MailAccessType +- MailboxGuid +- MailboxOwnerSid +- MailboxOwnerUPN +- Operation +- OperationCount +- OperationProperties{}.Name +- OperationProperties{}.Value +- OrganizationId +- OrganizationName +- OriginatingServer +- RecordType +- ResultStatus +- UserId +- UserKey +- UserType +- Version +- Workload +- app +- authentication_service +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dvc +- host +- index +- linecount +- punct +- signature +- source +- sourcetype +- splunk_server +- status +- timeendpos +- timestartpos +- user +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2024-02-01T16:07:34", "Id": "9cef02e9-4bfa-4c73-be7d-9dad68b9cea8", "Operation": "MailItemsAccessed", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "RecordType": 50, "ResultStatus": "Succeeded", "UserKey": "100320030DF47B14", "UserType": diff --git a/data_sources/o365_modifyfolderpermissions.yml b/data_sources/o365_modifyfolderpermissions.yml index aca4f79957..77b5ee58cf 100644 --- a/data_sources/o365_modifyfolderpermissions.yml +++ b/data_sources/o365_modifyfolderpermissions.yml @@ -6,99 +6,99 @@ author: Patrick Bareiss, Splunk description: Logs modifications to folder permissions in Microsoft 365, including updates to access levels, user assignments, and sharing settings. mitre_components: - - User Account Modification - - File Access - - Active Directory Object Modification - - Application Log Content +- User Account Modification +- File Access +- Active Directory Object Modification +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: ModifyFolderPermissions supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - AppId - - ClientIP - - ClientIPAddress - - ClientInfoString - - CreationTime - - ExternalAccess - - Id - - InternalLogonType - - Item.Id - - Item.ParentFolder.Id - - Item.ParentFolder.MemberRights - - Item.ParentFolder.MemberSid - - Item.ParentFolder.MemberUpn - - Item.ParentFolder.Name - - Item.ParentFolder.Path - - LogonType - - LogonUserSid - - MailboxGuid - - MailboxOwnerSid - - MailboxOwnerUPN - - Operation - - OrganizationId - - OrganizationName - - OriginatingServer - - RecordType - - ResultStatus - - SessionId - - UserId - - UserKey - - UserType - - Version - - Workload - - action - - app - - authentication_service - - change_type - - client_info_str - - command - - dataset_name - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - eventtype - - host - - index - - linecount - - object - - object_attrs - - object_category - - object_id - - punct - - record_type - - result - - signature - - source - - sourcetype - - splunk_server - - src - - src_ip - - status - - tag - - tag::eventtype - - tenant_id - - timeendpos - - timestartpos - - user - - user_agent - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- AppId +- ClientIP +- ClientIPAddress +- ClientInfoString +- CreationTime +- ExternalAccess +- Id +- InternalLogonType +- Item.Id +- Item.ParentFolder.Id +- Item.ParentFolder.MemberRights +- Item.ParentFolder.MemberSid +- Item.ParentFolder.MemberUpn +- Item.ParentFolder.Name +- Item.ParentFolder.Path +- LogonType +- LogonUserSid +- MailboxGuid +- MailboxOwnerSid +- MailboxOwnerUPN +- Operation +- OrganizationId +- OrganizationName +- OriginatingServer +- RecordType +- ResultStatus +- SessionId +- UserId +- UserKey +- UserType +- Version +- Workload +- action +- app +- authentication_service +- change_type +- client_info_str +- command +- dataset_name +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- eventtype +- host +- index +- linecount +- object +- object_attrs +- object_category +- object_id +- punct +- record_type +- result +- signature +- source +- sourcetype +- splunk_server +- src +- src_ip +- status +- tag +- tag::eventtype +- tenant_id +- timeendpos +- timestartpos +- user +- user_agent +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2023-09-07T18:19:07", "Id": "ff065c17-e638-4013-20ab-08dbafceeca1", "Operation": "ModifyFolderPermissions", "OrganizationId": "e17879dd-24ec-44a6-be92-9dcbf6969220", "RecordType": 2, "ResultStatus": "Succeeded", "UserKey": "10032002CC029AE9", "UserType": diff --git a/data_sources/o365_set_company_information_.yml b/data_sources/o365_set_company_information_.yml index e3da9d7ddd..7348172690 100644 --- a/data_sources/o365_set_company_information_.yml +++ b/data_sources/o365_set_company_information_.yml @@ -6,93 +6,93 @@ author: Patrick Bareiss, Splunk description: Logs updates to organizational settings and company information in Microsoft 365, including changes to contact details, branding, and configuration policies. mitre_components: - - Cloud Service Modification - - Configuration Modification - - Cloud Service Metadata - - Application Log Content +- Cloud Service Modification +- Configuration Modification +- Cloud Service Metadata +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Set Company Information. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - ActorIpAddress - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - ClientIP - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ModifiedProperties{}.Name - - ModifiedProperties{}.NewValue - - ModifiedProperties{}.OldValue - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - action - - additionalDetails - - app - - authentication_service - - change_type - - command - - dataset_name - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - eventtype - - extendedAuditEventCategory - - extended_properties - - host - - index - - linecount - - object - - object_attrs - - object_category - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- ActorIpAddress +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- ClientIP +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ModifiedProperties{}.Name +- ModifiedProperties{}.NewValue +- ModifiedProperties{}.OldValue +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- action +- additionalDetails +- app +- authentication_service +- change_type +- command +- dataset_name +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- eventtype +- extendedAuditEventCategory +- extended_properties +- host +- index +- linecount +- object +- object_attrs +- object_category +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"Actor": [{"ID": "bpatel@rodsoto.onmicrosoft.com", "Type": 5}, {"ID": "100320010208B5DC", "Type": 3}, {"ID": "User_425b75db-38be-4c7b-a474-5f0709247370", "Type": 2}, {"ID": "425b75db-38be-4c7b-a474-5f0709247370", "Type": 2}, {"ID": "User", diff --git a/data_sources/o365_set_mailbox.yml b/data_sources/o365_set_mailbox.yml index 9da03f53f4..2cf75ed058 100644 --- a/data_sources/o365_set_mailbox.yml +++ b/data_sources/o365_set_mailbox.yml @@ -6,89 +6,89 @@ author: Patrick Bareiss, Splunk description: Logs changes to mailbox properties in Microsoft 365, including updates to permissions, storage quotas, and configuration settings. mitre_components: - - User Account Modification - - Active Directory Object Modification - - User Account Metadata - - Application Log Content +- User Account Modification +- Active Directory Object Modification +- User Account Metadata +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Set-Mailbox supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - AppId - - ClientAppId - - ClientIP - - CreationTime - - ExternalAccess - - Id - - Identity - - ObjectId - - Operation - - OrganizationId - - OrganizationName - - OriginatingServer - - Parameters{}.Name - - Parameters{}.Value - - Params - - RecordType - - ResultStatus - - SessionId - - UserId - - UserKey - - UserType - - Version - - Workload - - action - - app - - authentication_service - - change_type - - command - - dataset_name - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - eventtype - - host - - index - - linecount - - object - - object_attrs - - object_category - - object_id - - punct - - record_type - - result - - signature - - source - - sourcetype - - splunk_server - - src - - src_ip - - src_user - - src_user_type - - status - - tag - - tag::eventtype - - tenant_id - - timeendpos - - timestartpos - - user - - user_id - - vendor_account - - vendor_product +- _time +- AppId +- ClientAppId +- ClientIP +- CreationTime +- ExternalAccess +- Id +- Identity +- ObjectId +- Operation +- OrganizationId +- OrganizationName +- OriginatingServer +- Parameters{}.Name +- Parameters{}.Value +- Params +- RecordType +- ResultStatus +- SessionId +- UserId +- UserKey +- UserType +- Version +- Workload +- action +- app +- authentication_service +- change_type +- command +- dataset_name +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- eventtype +- host +- index +- linecount +- object +- object_attrs +- object_category +- object_id +- punct +- record_type +- result +- signature +- source +- sourcetype +- splunk_server +- src +- src_ip +- src_user +- src_user_type +- status +- tag +- tag::eventtype +- tenant_id +- timeendpos +- timestartpos +- user +- user_id +- vendor_account +- vendor_product example_log: '{"AppId": "", "ClientAppId": "", "ClientIP": "18.192.200.190:52816", "CreationTime": "2020-12-16T12:32:28", "ExternalAccess": false, "Id": "a6a52406-0912-448d-36eb-08d8a1bea6be", "ObjectId": "bpatel", "Operation": "Set-Mailbox", "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08", diff --git a/data_sources/o365_update_application_.yml b/data_sources/o365_update_application_.yml index 2b04a3230b..4e9728c9e5 100644 --- a/data_sources/o365_update_application_.yml +++ b/data_sources/o365_update_application_.yml @@ -6,92 +6,92 @@ author: Patrick Bareiss, Splunk description: Logs updates made to applications in Microsoft 365, including changes to configurations, permissions, and role assignments. mitre_components: - - Cloud Service Modification - - Configuration Modification - - Cloud Service Metadata - - Application Log Content +- Cloud Service Modification +- Configuration Modification +- Cloud Service Metadata +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Update application. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ModifiedProperties{}.Name - - ModifiedProperties{}.NewValue - - ModifiedProperties{}.OldValue - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - action - - additionalDetails - - app - - authentication_service - - change_type - - command - - dataset_name - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - eventtype - - extendedAuditEventCategory - - host - - index - - linecount - - object - - object_attrs - - object_category - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_agent - - user_agent_change - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ModifiedProperties{}.Name +- ModifiedProperties{}.NewValue +- ModifiedProperties{}.OldValue +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- action +- additionalDetails +- app +- authentication_service +- change_type +- command +- dataset_name +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- eventtype +- extendedAuditEventCategory +- host +- index +- linecount +- object +- object_attrs +- object_category +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_agent +- user_agent_change +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2023-09-01T17:16:20", "Id": "c428c85c-4fa0-4e97-9033-6a76d9dee45d", "Operation": "Update application.", "OrganizationId": "58aee3b9-7433-46a0-b54e-2429487992a0", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com", diff --git a/data_sources/o365_update_authorization_policy_.yml b/data_sources/o365_update_authorization_policy_.yml index 90825eca41..1c0d97242a 100644 --- a/data_sources/o365_update_authorization_policy_.yml +++ b/data_sources/o365_update_authorization_policy_.yml @@ -6,84 +6,84 @@ author: Patrick Bareiss, Splunk description: Logs changes to authorization policies in Microsoft 365, including updates to access controls, permissions, and security settings. mitre_components: - - Cloud Service Modification - - Configuration Modification - - User Account Metadata - - Application Log Content +- Cloud Service Modification +- Configuration Modification +- User Account Metadata +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Update authorization policy. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ModifiedProperties{}.Name - - ModifiedProperties{}.NewValue - - ModifiedProperties{}.OldValue - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - additionalDetails - - app - - authentication_service - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - extendedAuditEventCategory - - host - - index - - linecount - - object - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - status - - timeendpos - - timestartpos - - user - - user_agent - - user_agent_change - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ModifiedProperties{}.Name +- ModifiedProperties{}.NewValue +- ModifiedProperties{}.OldValue +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- additionalDetails +- app +- authentication_service +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- extendedAuditEventCategory +- host +- index +- linecount +- object +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- status +- timeendpos +- timestartpos +- user +- user_agent +- user_agent_change +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2023-10-26T19:22:20", "Id": "83774e72-313f-4d1f-8609-7d0c7bb3b4ff", "Operation": "Update authorization policy.", "OrganizationId": "a417c578-c7ee-480d-a225-d48057e74df5", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com", diff --git a/data_sources/o365_update_user_.yml b/data_sources/o365_update_user_.yml index f733a674a4..c9d47f5456 100644 --- a/data_sources/o365_update_user_.yml +++ b/data_sources/o365_update_user_.yml @@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk description: Logs updates to user account properties in Microsoft 365, including changes to roles, permissions, and profile information. mitre_components: - - User Account Modification - - User Account Metadata - - Active Directory Object Modification - - Application Log Content +- User Account Modification +- User Account Metadata +- Active Directory Object Modification +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: Update user. supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - Actor{}.ID - - Actor{}.Type - - AzureActiveDirectoryEventType - - CreationTime - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - ModifiedProperties{}.Name - - ModifiedProperties{}.NewValue - - ModifiedProperties{}.OldValue - - ObjectId - - Operation - - OrganizationId - - RecordType - - ResultStatus - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserId - - UserKey - - UserType - - Version - - Workload - - action - - additionalDetails - - app - - authentication_service - - change_type - - command - - dataset_name - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - eventtype - - extendedAuditEventCategory - - host - - index - - linecount - - object - - object_attrs - - object_category - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - src_user - - status - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_id - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- Actor{}.ID +- Actor{}.Type +- AzureActiveDirectoryEventType +- CreationTime +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- ModifiedProperties{}.Name +- ModifiedProperties{}.NewValue +- ModifiedProperties{}.OldValue +- ObjectId +- Operation +- OrganizationId +- RecordType +- ResultStatus +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserId +- UserKey +- UserType +- Version +- Workload +- action +- additionalDetails +- app +- authentication_service +- change_type +- command +- dataset_name +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- eventtype +- extendedAuditEventCategory +- host +- index +- linecount +- object +- object_attrs +- object_category +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- src_user +- status +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_id +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2023-10-20T19:32:59", "Id": "d06df1c6-b3f2-4595-90b9-99b8f91811c3", "Operation": "Update user.", "OrganizationId": "99825d50-9544-4061-8e46-68923805cbf2", "RecordType": 8, "ResultStatus": "Success", "UserKey": "10032002CC029AE9@splunkresearch1.onmicrosoft.com", diff --git a/data_sources/o365_userloggedin.yml b/data_sources/o365_userloggedin.yml index f9169deaee..4e5fbdcea2 100644 --- a/data_sources/o365_userloggedin.yml +++ b/data_sources/o365_userloggedin.yml @@ -6,91 +6,91 @@ author: Patrick Bareiss, Splunk description: Logs successful login events by users in Microsoft 365, including details about the user account, IP address, and session metadata. mitre_components: - - User Account Authentication - - Logon Session Creation - - User Account Metadata - - Logon Session Metadata +- User Account Authentication +- Logon Session Creation +- User Account Metadata +- Logon Session Metadata source: o365 sourcetype: o365:management:activity separator: Operation separator_value: UserLoggedIn supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - ActorIpAddress - - Actor{}.ID - - Actor{}.Type - - ApplicationId - - AzureActiveDirectoryEventType - - BrowserType - - ClientIP - - CreationTime - - DeviceProperties{}.Name - - DeviceProperties{}.Value - - ErrorNumber - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - OS - - ObjectId - - Operation - - OrganizationId - - RecordType - - RequestType - - ResultStatus - - ResultStatusDetail - - SessionId - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserAgent - - UserId - - UserKey - - UserType - - Version - - Workload - - app - - authentication_service - - command - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - host - - index - - linecount - - object - - punct - - record_type - - signature - - source - - sourcetype - - splunk_server - - src - - src_ip - - status - - timeendpos - - timestartpos - - user - - user_agent - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- ActorIpAddress +- Actor{}.ID +- Actor{}.Type +- ApplicationId +- AzureActiveDirectoryEventType +- BrowserType +- ClientIP +- CreationTime +- DeviceProperties{}.Name +- DeviceProperties{}.Value +- ErrorNumber +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- OS +- ObjectId +- Operation +- OrganizationId +- RecordType +- RequestType +- ResultStatus +- ResultStatusDetail +- SessionId +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserAgent +- UserId +- UserKey +- UserType +- Version +- Workload +- app +- authentication_service +- command +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- host +- index +- linecount +- object +- punct +- record_type +- signature +- source +- sourcetype +- splunk_server +- src +- src_ip +- status +- timeendpos +- timestartpos +- user +- user_agent +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2023-12-04T20:42:05", "Id": "52d72a62-132b-487b-bb7f-c4c119f90700", "Operation": "UserLoggedIn", "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "RecordType": 15, "ResultStatus": "Success", "UserKey": "2d2f9e2c-8350-4d98-852e-3f06daaf7185", diff --git a/data_sources/o365_userloginfailed.yml b/data_sources/o365_userloginfailed.yml index 8f3df80a3f..1a571c469a 100644 --- a/data_sources/o365_userloginfailed.yml +++ b/data_sources/o365_userloginfailed.yml @@ -6,100 +6,100 @@ author: Patrick Bareiss, Splunk description: Logs failed login attempts by users in Microsoft 365, including details about the user account, IP address, and reason for failure. mitre_components: - - User Account Authentication - - Logon Session Metadata - - User Account Metadata - - Application Log Content +- User Account Authentication +- Logon Session Metadata +- User Account Metadata +- Application Log Content source: o365 sourcetype: o365:management:activity separator: Operation separator_value: UserLoginFailed supported_TA: - - name: Splunk Add-on for Microsoft Office 365 - url: https://splunkbase.splunk.com/app/4055 - version: 4.7.0 +- name: Splunk Add-on for Microsoft Office 365 + url: https://splunkbase.splunk.com/app/4055 + version: 4.7.0 fields: - - _time - - ActorContextId - - ActorIpAddress - - Actor{}.ID - - Actor{}.Type - - ApplicationId - - AzureActiveDirectoryEventType - - BrowserType - - ClientIP - - CreationTime - - DeviceProperties{}.Name - - DeviceProperties{}.Value - - ErrorNumber - - ExtendedProperties{}.Name - - ExtendedProperties{}.Value - - Id - - InterSystemsId - - IntraSystemId - - IsCompliantAndManaged - - LogonError - - OS - - ObjectId - - Operation - - OrganizationId - - RecordType - - RequestType - - ResultStatus - - ResultStatusDetail - - SupportTicketId - - TargetContextId - - Target{}.ID - - Target{}.Type - - UserAgent - - UserAuthenticationMethod - - UserId - - UserKey - - UserType - - Version - - Workload - - action - - app - - authentication_method - - authentication_service - - command - - dataset_name - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_name - - dvc - - event_type - - eventtype - - host - - index - - linecount - - object - - punct - - reason - - record_type - - result - - signature - - source - - sourcetype - - splunk_server - - src - - src_ip - - status - - tag - - tag::action - - tag::eventtype - - user - - user_agent - - user_type - - vendor_account - - vendor_product +- _time +- ActorContextId +- ActorIpAddress +- Actor{}.ID +- Actor{}.Type +- ApplicationId +- AzureActiveDirectoryEventType +- BrowserType +- ClientIP +- CreationTime +- DeviceProperties{}.Name +- DeviceProperties{}.Value +- ErrorNumber +- ExtendedProperties{}.Name +- ExtendedProperties{}.Value +- Id +- InterSystemsId +- IntraSystemId +- IsCompliantAndManaged +- LogonError +- OS +- ObjectId +- Operation +- OrganizationId +- RecordType +- RequestType +- ResultStatus +- ResultStatusDetail +- SupportTicketId +- TargetContextId +- Target{}.ID +- Target{}.Type +- UserAgent +- UserAuthenticationMethod +- UserId +- UserKey +- UserType +- Version +- Workload +- action +- app +- authentication_method +- authentication_service +- command +- dataset_name +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_name +- dvc +- event_type +- eventtype +- host +- index +- linecount +- object +- punct +- reason +- record_type +- result +- signature +- source +- sourcetype +- splunk_server +- src +- src_ip +- status +- tag +- tag::action +- tag::eventtype +- user +- user_agent +- user_type +- vendor_account +- vendor_product example_log: '{"CreationTime": "2023-10-10T17:08:65", "Id": "4593aac8-855f-4341-9d2a-4289146eb800", "Operation": "UserLoginFailed", "OrganizationId": "d541aae6-6b73-4a7c-aaf0-a4de30c872bc", "RecordType": 15, "ResultStatus": "Failed", "UserKey": "57e4bd36-9722-4a4a-9729-7203d8e00b72", diff --git a/data_sources/okta.yml b/data_sources/okta.yml index 4c4de15b28..3d83e462b9 100644 --- a/data_sources/okta.yml +++ b/data_sources/okta.yml @@ -6,14 +6,14 @@ author: Patrick Bareiss, Splunk description: Logs authentication and administrative activities captured by Okta, including user login attempts, session management, and configuration changes. mitre_components: - - User Account Authentication - - Logon Session Creation - - User Account Metadata - - Configuration Modification - - Application Log Content +- User Account Authentication +- Logon Session Creation +- User Account Metadata +- Configuration Modification +- Application Log Content source: Okta sourcetype: OktaIM2:log supported_TA: - - name: Splunk Add-on for Okta Identity Cloud - url: https://splunkbase.splunk.com/app/6553 - version: 3.0.0 +- name: Splunk Add-on for Okta Identity Cloud + url: https://splunkbase.splunk.com/app/6553 + version: 3.0.0 diff --git a/data_sources/osquery.yml b/data_sources/osquery.yml index b2b1828e0f..b14df40563 100644 --- a/data_sources/osquery.yml +++ b/data_sources/osquery.yml @@ -6,68 +6,68 @@ author: Patrick Bareiss, Splunk description: Logs system queries performed using osquery, including details about processes, file access, network activity, and system configurations. mitre_components: - - Process Metadata - - File Access - - Network Traffic Content - - Host Status - - Application Log Content +- Process Metadata +- File Access +- Network Traffic Content +- Host Status +- Application Log Content source: osquery sourcetype: osquery:results supported_TA: [] fields: - - _time - - calendarTime - - columns.cdhash - - columns.child_pid - - columns.cmdline - - columns.cmdline_count - - columns.cwd - - columns.egid - - columns.env - - columns.env_count - - columns.euid - - columns.event_type - - columns.exit_code - - columns.gid - - columns.global_seq_num - - columns.original_parent - - columns.parent - - columns.path - - columns.pid - - columns.platform_binary - - columns.seq_num - - columns.signing_id - - columns.team_id - - columns.time - - columns.uid - - columns.username - - columns.version - - counter - - dest - - epoch - - eventtype - - host - - hostIdentifier - - index - - linecount - - name - - numerics - - parent_process_id - - process_current_directory - - process_id - - process_path - - punct - - source - - sourcetype - - splunk_server - - src - - subject - - tag - - tag::eventtype - - timestamp - - unixTime - - user_id - - vendor_product +- _time +- calendarTime +- columns.cdhash +- columns.child_pid +- columns.cmdline +- columns.cmdline_count +- columns.cwd +- columns.egid +- columns.env +- columns.env_count +- columns.euid +- columns.event_type +- columns.exit_code +- columns.gid +- columns.global_seq_num +- columns.original_parent +- columns.parent +- columns.path +- columns.pid +- columns.platform_binary +- columns.seq_num +- columns.signing_id +- columns.team_id +- columns.time +- columns.uid +- columns.username +- columns.version +- counter +- dest +- epoch +- eventtype +- host +- hostIdentifier +- index +- linecount +- name +- numerics +- parent_process_id +- process_current_directory +- process_id +- process_path +- punct +- source +- sourcetype +- splunk_server +- src +- subject +- tag +- tag::eventtype +- timestamp +- unixTime +- user_id +- vendor_product example_log: '{"name":"es_process_events","hostIdentifier":"HackBook.local","calendarTime":"Tue Mar 29 13:03:51 2022 UTC","unixTime":1648559031,"epoch":0,"counter":82,"numerics":false,"columns":{"cdhash":"f63c5fbfcf1484b20aa4407a26e087fe3fe28146","child_pid":"","cmdline":"plutil --help ","cmdline_count":"2","cwd":"/Users/patrick","egid":"20","env":"TERM_SESSION_ID=w0t1p0:93AA9D79-7028-49F1-A93D-4EAEFB7BA6E3 diff --git a/data_sources/palo_alto_network_threat.yml b/data_sources/palo_alto_network_threat.yml index 48d799c14e..10e7c74e79 100644 --- a/data_sources/palo_alto_network_threat.yml +++ b/data_sources/palo_alto_network_threat.yml @@ -6,40 +6,39 @@ author: Patrick Bareiss, Splunk description: Logs detected threats identified by Palo Alto Networks devices, including details about malware, intrusion attempts, and malicious network activity. mitre_components: - - Malware Metadata - - Network Traffic Content - - Network Traffic Flow - - Application Log Content - - Host Status +- Malware Metadata +- Network Traffic Content +- Network Traffic Flow +- Application Log Content +- Host Status source: pan:threat sourcetype: pan:threat supported_TA: - - name: Palo Alto Networks Add-on - url: https://splunkbase.splunk.com/app/2757 - version: 8.1.3 +- name: Palo Alto Networks Add-on + url: https://splunkbase.splunk.com/app/2757 + version: 8.1.3 fields: - - _time - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - host - - index - - linecount - - punct - - source - - sourcetype - - splunk_server - - timeendpos - - timestartpos +- _time +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- host +- index +- linecount +- punct +- source +- sourcetype +- splunk_server +- timeendpos +- timestartpos example_log: May 10 11:08:39 sjc.example.com 1,2022/05/10 11:08:38,013201004583,THREAT,url,2305,2022/05/10 11:08:38,2.18.4.7,1.2.3.4,2.18.4.7,1.2.3.4,service-globalprotect,,,web-browsing,vsys1,UNTRUST,UNTRUST,ethernet1/20,loopback.1,Zero,2022/05/10 11:08:38,1535535,1,32880,443,32880,20077,0x1403000,tcp,allow,"sr.example.com/mgmt/tm/util/bash",(9999),allow-URL,informational,client-to-server,7081856864553612091,0xa000000000000000,United States,United States,0,,0,,,1,"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 - (KHTML, like Gecko) Chrome/36.0.1944.0 - Safari/537.36",,,,,,,0,177,204,178,382,,sjc1-fw-01,,,,post,0,,0,,N/A,unknown,AppThreat-0-0,0x0,0,4294967295,," + (KHTML, like Gecko) Chrome/36.0.1944.0 Safari/537.36",,,,,,,0,177,204,178,382,,sjc1-fw-01,,,,post,0,,0,,N/A,unknown,AppThreat-0-0,0x0,0,4294967295,," allow-URL,computer-and-internet-info,low-risk",5283cb95-6902-41db-96c6-ef807361eba5,0, diff --git a/data_sources/palo_alto_network_traffic.yml b/data_sources/palo_alto_network_traffic.yml index c4673e3fe7..09515ca80d 100644 --- a/data_sources/palo_alto_network_traffic.yml +++ b/data_sources/palo_alto_network_traffic.yml @@ -6,39 +6,37 @@ author: Patrick Bareiss, Splunk description: Logs network traffic events captured by Palo Alto Networks devices, including details about sessions, protocols, and source and destination IPs. mitre_components: - - Network Traffic Content - - Network Traffic Flow - - Network Connection Creation - - Response Metadata - - Application Log Content +- Network Traffic Content +- Network Traffic Flow +- Network Connection Creation +- Response Metadata +- Application Log Content source: screenconnect_palo_traffic sourcetype: pan:traffic supported_TA: - - name: Palo Alto Networks Add-on - url: https://splunkbase.splunk.com/app/2757 - version: 8.1.3 +- name: Palo Alto Networks Add-on + url: https://splunkbase.splunk.com/app/2757 + version: 8.1.3 fields: - - _time - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - host - - index - - linecount - - punct - - source - - sourcetype - - splunk_server - - timeendpos - - timestartpos +- _time +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- host +- index +- linecount +- punct +- source +- sourcetype +- splunk_server +- timeendpos +- timestartpos example_log: 577 <14>1 2024-02-22T12:33:50-05:00 PALO220.ATTACK_RANGE.LAN - - - - - 1,2024/02/22 12:33:50,012801036556,TRAFFIC,end,2305,2024/02/22 - 12:33:50,192.168.1.205,147.28.146.44,201.17.96.104,147.28.146.44,No_Vuln_Filtering_OUT,,,screenconnect,vsys1,Trust,Untrust,ethernet1/2,ethernet1/1,splunk_range,2024/02/22 + 1,2024/02/22 12:33:50,012801036556,TRAFFIC,end,2305,2024/02/22 12:33:50,192.168.1.205,147.28.146.44,201.17.96.104,147.28.146.44,No_Vuln_Filtering_OUT,,,screenconnect,vsys1,Trust,Untrust,ethernet1/2,ethernet1/1,splunk_range,2024/02/22 12:33:50,14740,1,50624,443,11024,443,0x40005e,tcp,allow,7419,6609,810,25,2024/02/22 - 12:32:29,65,any,0,376156893,0x0,192.168.0.0-192.168.255.255,United - States,0,14,11,tcp-fin,0,0,0,0,,PALO220,from-policy,,,0,,0,,N/A,0,0,0,0,0862e58b-4a54-436b-b3ac-ea3eccf8403b,0,0,,,,,,, + 12:32:29,65,any,0,376156893,0x0,192.168.0.0-192.168.255.255,United States,0,14,11,tcp-fin,0,0,0,0,,PALO220,from-policy,,,0,,0,,N/A,0,0,0,0,0862e58b-4a54-436b-b3ac-ea3eccf8403b,0,0,,,,,,, diff --git a/data_sources/pingid.yml b/data_sources/pingid.yml index 5b7648219f..bde7518b61 100644 --- a/data_sources/pingid.yml +++ b/data_sources/pingid.yml @@ -6,41 +6,41 @@ author: Patrick Bareiss, Splunk description: Logs authentication and multi-factor authentication (MFA) events managed by PingID, including user logins, device enrollments, and MFA challenges. mitre_components: - - User Account Authentication - - Logon Session Metadata - - User Account Metadata - - Application Log Content - - Host Status +- User Account Authentication +- Logon Session Metadata +- User Account Metadata +- Application Log Content +- Host Status source: XmlWinEventLog:Security sourcetype: XmlWinEventLog supported_TA: [] fields: - - _time - - actors{}.name - - actors{}.type - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - extracted_source - - host - - id - - index - - linecount - - punct - - recorded - - resources{}.ipaddress - - resources{}.websession - - result.message - - result.status - - source - - sourcetype - - splunk_server - - timeendpos - - timestartpos +- _time +- actors{}.name +- actors{}.type +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- extracted_source +- host +- id +- index +- linecount +- punct +- recorded +- resources{}.ipaddress +- resources{}.websession +- result.message +- result.status +- source +- sourcetype +- splunk_server +- timeendpos +- timestartpos example_log: '{"source":"PINGID","id":"b2eb1fef-651b-11ee-b38b-0ac7a554ed19","recorded":"2023-10-05T14:10:53.538Z","actors":[{"type":"user","name":"victim_user"}],"resources":[{"ipaddress":"174.235.80.142","websession":"webs_ijkF-T_bAC_G3w2TfvdpAEQeC545KFlqVFOsolCXdjo"}],"result":{"status":"SUCCESS","message":"Device Paired SMS \"Mobile 1\""}}' diff --git a/data_sources/powershell_installed_iis_modules.yml b/data_sources/powershell_installed_iis_modules.yml index 3e466057a5..ddb49cbdf7 100644 --- a/data_sources/powershell_installed_iis_modules.yml +++ b/data_sources/powershell_installed_iis_modules.yml @@ -6,22 +6,22 @@ author: Patrick Bareiss, Splunk description: Logs the list of installed IIS modules retrieved using PowerShell, including details about their names and statuses. mitre_components: - - Service Metadata - - Configuration Modification - - OS API Execution - - Application Log Content +- Service Metadata +- Configuration Modification +- OS API Execution +- Application Log Content source: powershell://AppCmdModules sourcetype: Pwsh:InstalledIISModules supported_TA: [] fields: - - _time - - Schema - - host - - index - - linecount - - punct - - source - - sourcetype - - splunk_server - - timestamp +- _time +- Schema +- host +- index +- linecount +- punct +- source +- sourcetype +- splunk_server +- timestamp example_log: Schema="Microsoft.IIs.PowerShell.Framework.ConfigurationElementSchema" diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index 67794c1e47..99f3ace10f 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -6,92 +6,91 @@ author: Patrick Bareiss, Splunk description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution. mitre_components: - - Script Execution - - Command Execution - - Process Metadata - - OS API Execution - - Application Log Content +- Script Execution +- Command Execution +- Process Metadata +- OS API Execution +- Application Log Content source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 4104 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - ActivityID - - Channel - - Computer - - EventCode - - EventData_Xml - - EventID - - EventRecordID - - Guid - - Keywords - - Level - - MessageNumber - - MessageTotal - - Name - - Opcode - - Path - - ProcessID - - RecordNumber - - ScriptBlockId - - ScriptBlockText - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - UserID - - Version - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - punct - - signature_id - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user_id - - vendor_product +- _time +- ActivityID +- Channel +- Computer +- EventCode +- EventData_Xml +- EventID +- EventRecordID +- Guid +- Keywords +- Level +- MessageNumber +- MessageTotal +- Name +- Opcode +- Path +- ProcessID +- RecordNumber +- ScriptBlockId +- ScriptBlockText +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- UserID +- Version +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- punct +- signature_id +- source +- sourcetype +- splunk_server +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user_id +- vendor_product field_mappings: - - data_model: cim - data_set: Endpoint.Processes - mapping: - Computer: Processes.dest - Path: Processes.process_path - ScriptBlockId: Processes.process_id - ScriptBlockText: Processes.process - UserID: Processes.user_id - - data_model: ocsf - mapping: - Computer: device.hostname - Path: process.file.path - ScriptBlockId: process.uid - ScriptBlockText: process.cmd_line - UserID: actor.user.uid +- data_model: cim + data_set: Endpoint.Processes + mapping: + Computer: Processes.dest + Path: Processes.process_path + ScriptBlockId: Processes.process_id + ScriptBlockText: Processes.process + UserID: Processes.user_id +- data_model: ocsf + mapping: + Computer: device.hostname + Path: process.file.path + ScriptBlockId: process.uid + ScriptBlockText: process.cmd_line + UserID: actor.user.uid example_log: 4104152150x04104152150x0112748Microsoft-Windows-PowerShell/Operationalwin-dc-mhaag-attack-range-270.attackrange.local154100x8000000000000000154100x80000000000000004522Microsoft-Windows-Sysmon/Operationalwin-dc-6764986.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-6764986.attackrange.local-2020-10-08 11:03:46.615{96128EA2-F212-5F7E-E400-000000007F01}2296C:\Windows\System32\cmd.exeMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{96128EA2-F211-5F7E-DF00-000000007F01}4624C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"powershell.exe" -noninteractive -encodedcommand - WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbwBuAGYAaQByAG0AOgAkAGYAYQBsAHMAZQAgAC0AVABpAG0AZQBvAHUAdABTAGUAYwBvAG4AZABzACAAMwAwADAAIAAtAEUAeABlAGMAdQB0AGkAbwBuAEwAbwBnAFAAYQB0AGgAIABDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAYQB0AGMAXwBlAHgAZQBjAHUAdABpAG8AbgAuAGMAcwB2AA== + Name='ParentCommandLine'>"powershell.exe" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbwBuAGYAaQByAG0AOgAkAGYAYQBsAHMAZQAgAC0AVABpAG0AZQBvAHUAdABTAGUAYwBvAG4AZABzACAAMwAwADAAIAAtAEUAeABlAGMAdQB0AGkAbwBuAEwAbwBnAFAAYQB0AGgAIABDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAYQB0AGMAXwBlAHgAZQBjAHUAdABpAG8AbgAuAGMAcwB2AA== diff --git a/data_sources/sysmon_eventid_10.yml b/data_sources/sysmon_eventid_10.yml index 6197a6a241..844e023f1a 100644 --- a/data_sources/sysmon_eventid_10.yml +++ b/data_sources/sysmon_eventid_10.yml @@ -6,104 +6,102 @@ author: Patrick Bareiss, Splunk description: Logs events where one process accesses another process, typically for memory reads or injections, including details about the source and target processes. mitre_components: - - Process Access - - Process Metadata - - Application Log Content - - OS API Execution +- Process Access +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 10 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - - name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 +- name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: - - _time - - CallTrace - - Channel - - Computer - - EventChannel - - EventCode - - EventData_Xml - - EventDescription - - EventID - - EventRecordID - - GrantedAccess - - Guid - - Keywords - - Level - - Name - - Opcode - - ProcessID - - RecordID - - RecordNumber - - RuleName - - SecurityID - - SourceImage - - SourceProcessGUID - - SourceProcessId - - SourceThreadId - - SystemTime - - System_Props_Xml - - TargetImage - - TargetProcessGUID - - TargetProcessId - - Task - - ThreadID - - TimeCreated - - UserID - - UtcTime - - Version - - action - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - dvc_nt_host - - event_id - - eventtype - - granted_access - - host - - id - - index - - linecount - - os - - parent_process_exec - - parent_process_guid - - parent_process_id - - parent_process_name - - parent_process_path - - process_exec - - process_guid - - process_id - - process_name - - process_path - - punct - - signature - - signature_id - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user_id - - vendor_product +- _time +- CallTrace +- Channel +- Computer +- EventChannel +- EventCode +- EventData_Xml +- EventDescription +- EventID +- EventRecordID +- GrantedAccess +- Guid +- Keywords +- Level +- Name +- Opcode +- ProcessID +- RecordID +- RecordNumber +- RuleName +- SecurityID +- SourceImage +- SourceProcessGUID +- SourceProcessId +- SourceThreadId +- SystemTime +- System_Props_Xml +- TargetImage +- TargetProcessGUID +- TargetProcessId +- Task +- ThreadID +- TimeCreated +- UserID +- UtcTime +- Version +- action +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- dvc_nt_host +- event_id +- eventtype +- granted_access +- host +- id +- index +- linecount +- os +- parent_process_exec +- parent_process_guid +- parent_process_id +- parent_process_name +- parent_process_path +- process_exec +- process_guid +- process_id +- process_name +- process_path +- punct +- signature +- signature_id +- source +- sourcetype +- splunk_server +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user_id +- vendor_product example_log: 10341000x800000000000000010341000x8000000000000000150624412Microsoft-Windows-Sysmon/Operationalwin-dc-128.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-128.attackrange.local-2022-02-01 21:01:44.670{3BF36828-9F6D-61F9-390A-02000000CF01}1272956C:\Tools\Rubeus.exe11241100x800000000000000011241100x80000000000000007712490Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-84.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-84.attackrange.localDownloads2023-02-08 13:01:11.053{0F9A6540-A70E-63E2-3091-00000000BD02}9332C:\Users\Administrator\Downloads\mimikatz_trunk\x64\mimikatz.exe9332C:\Users\Administrator\Downloads\mimikatz_trunk\x64\mimikatz.exeC:\Users\Administrator\Downloads\mimikatz_trunk\x64\CURRENT_USER_My_4_atomic@art2.local.pfx2023-02-08 13:01:11.053 diff --git a/data_sources/sysmon_eventid_12.yml b/data_sources/sysmon_eventid_12.yml index 57e13fb712..b1fe5f0b54 100644 --- a/data_sources/sysmon_eventid_12.yml +++ b/data_sources/sysmon_eventid_12.yml @@ -6,102 +6,99 @@ author: Patrick Bareiss, Splunk description: Logs the creation of a new registry key, including details about the key name, registry path, and associated process metadata. mitre_components: - - Windows Registry Key Creation - - Process Metadata - - Application Log Content - - OS API Execution +- Windows Registry Key Creation +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 12 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - - name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 +- name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: - - _time - - Channel - - Computer - - EventChannel - - EventCode - - EventData_Xml - - EventDescription - - EventID - - EventRecordID - - EventType - - Guid - - Image - - Keywords - - Level - - Name - - Opcode - - ProcessGuid - - ProcessID - - ProcessId - - RecordID - - RecordNumber - - RuleName - - SecurityID - - SystemTime - - System_Props_Xml - - TargetObject - - Task - - ThreadID - - TimeCreated - - UserID - - UtcTime - - Version - - action - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - object_category - - object_path - - process_exec - - process_guid - - process_id - - process_name - - process_path - - punct - - registry_hive - - registry_key_name - - registry_path - - severity_id - - signature - - signature_id - - source - - sourcetype - - splunk_server - - status - - tag - - tag::eventtype - - tag::object_category - - timeendpos - - timestartpos - - user_id - - vendor_product +- _time +- Channel +- Computer +- EventChannel +- EventCode +- EventData_Xml +- EventDescription +- EventID +- EventRecordID +- EventType +- Guid +- Image +- Keywords +- Level +- Name +- Opcode +- ProcessGuid +- ProcessID +- ProcessId +- RecordID +- RecordNumber +- RuleName +- SecurityID +- SystemTime +- System_Props_Xml +- TargetObject +- Task +- ThreadID +- TimeCreated +- UserID +- UtcTime +- Version +- action +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- object_category +- object_path +- process_exec +- process_guid +- process_id +- process_name +- process_path +- punct +- registry_hive +- registry_key_name +- registry_path +- severity_id +- signature +- signature_id +- source +- sourcetype +- splunk_server +- status +- tag +- tag::eventtype +- tag::object_category +- timeendpos +- timestartpos +- user_id +- vendor_product example_log: 12241200x800000000000000012241200x80000000000000001055579Microsoft-Windows-Sysmon/Operationalwin-dc-890.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-890.attackrange.local-DeleteKey2021-07-12 08:10:32.592{466BC892-F8F2-60EB-107E-00000000CF01}10188C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10188C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-2333072374-3391925831-3197092227-1112_Classes\exefile\shell\runas\command diff --git a/data_sources/sysmon_eventid_13.yml b/data_sources/sysmon_eventid_13.yml index d533ac7a5c..e586cf23e2 100644 --- a/data_sources/sysmon_eventid_13.yml +++ b/data_sources/sysmon_eventid_13.yml @@ -6,116 +6,114 @@ author: Patrick Bareiss, Splunk description: Logs changes to a registry key, including details about the modified key, value, and associated process. mitre_components: - - Windows Registry Key Modification - - Process Metadata - - Application Log Content - - OS API Execution +- Windows Registry Key Modification +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 13 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - - name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 +- name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: - - _time - - Channel - - Computer - - Details - - EventChannel - - EventCode - - EventData_Xml - - EventDescription - - EventID - - EventRecordID - - EventType - - Guid - - Image - - Keywords - - Level - - Name - - Opcode - - ProcessGuid - - ProcessID - - ProcessId - - RecordID - - RecordNumber - - RegistryValueData - - RegistryValueType - - RuleName - - SecurityID - - SystemTime - - System_Props_Xml - - TargetObject - - Task - - ThreadID - - TimeCreated - - UserID - - UtcTime - - Version - - action - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - object_category - - object_path - - process_exec - - process_guid - - process_id - - process_name - - process_path - - punct - - registry_hive - - registry_key_name - - registry_path - - registry_value_data - - registry_value_name - - registry_value_type - - severity_id - - signature - - signature_id - - source - - sourcetype - - splunk_server - - status - - tag - - tag::eventtype - - tag::object_category - - timeendpos - - timestartpos - - user_id - - vendor_product +- _time +- Channel +- Computer +- Details +- EventChannel +- EventCode +- EventData_Xml +- EventDescription +- EventID +- EventRecordID +- EventType +- Guid +- Image +- Keywords +- Level +- Name +- Opcode +- ProcessGuid +- ProcessID +- ProcessId +- RecordID +- RecordNumber +- RegistryValueData +- RegistryValueType +- RuleName +- SecurityID +- SystemTime +- System_Props_Xml +- TargetObject +- Task +- ThreadID +- TimeCreated +- UserID +- UtcTime +- Version +- action +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- object_category +- object_path +- process_exec +- process_guid +- process_id +- process_name +- process_path +- punct +- registry_hive +- registry_key_name +- registry_path +- registry_value_data +- registry_value_name +- registry_value_type +- severity_id +- signature +- signature_id +- source +- sourcetype +- splunk_server +- status +- tag +- tag::eventtype +- tag::object_category +- timeendpos +- timestartpos +- user_id +- vendor_product field_mappings: - - data_model: cim - data_set: Endpoint.Registry - mapping: - Computer: Registry.dest - ProcessGuid: Registry.process_guid - ProcessId: Registry.process_id - TargetObject: Registry.registry_path - Details: Registry.registry_value_data +- data_model: cim + data_set: Endpoint.Registry + mapping: + Computer: Registry.dest + ProcessGuid: Registry.process_guid + ProcessId: Registry.process_id + TargetObject: Registry.registry_path + Details: Registry.registry_value_data example_log: 13241300x800000000000000013241300x8000000000000000810987Microsoft-Windows-Sysmon/Operationalwin-host-623.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-host-623.attackrange.local-SetValue2021-07-12 08:11:04.547{0C1E0330-048F-60E8-0B00-00000000D001}628C:\Windows\system32\lsass.exe15241500x800000000000000015241500x8000000000000000667860Microsoft-Windows-Sysmon/Operationalproject-mumbai-hostMicrosoft-Windows-Sysmon/Operationalproject-mumbai-host-2021-04-28 20:11:34.709{ED2ECF8A-C154-6089-F967-00000000BB01}7000C:\Users\DefaultAccount\AppData\Roaming\Telegram Desktop\Telegram.exeC:\Users\DefaultAccount\Downloads\Telegram Desktop\Good(NLA).txt:Zone.Identifier2021-04-28 - 20:11:33.238MD5=C785C55D5FA3443A11B8417209C4B524,SHA256=D07777E0DC36EBECCE3FA9644F0F44DC4A0B7EDE0CBC1F5D33E8D6CB07AF5B5C,IMPHASH=00000000000000000000000000000000MD5=C785C55D5FA3443A11B8417209C4B524,SHA256=D07777E0DC36EBECCE3FA9644F0F44DC4A0B7EDE0CBC1F5D33E8D6CB07AF5B5C,IMPHASH=00000000000000000000000000000000[ZoneTransfer] ZoneId=3 diff --git a/data_sources/sysmon_eventid_17.yml b/data_sources/sysmon_eventid_17.yml index 17f9cba91f..b871828540 100644 --- a/data_sources/sysmon_eventid_17.yml +++ b/data_sources/sysmon_eventid_17.yml @@ -5,92 +5,90 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Sysmon EventID 17 logs details about the detection of a named pipe. mitre_components: - - Named Pipe Metadata +- Named Pipe Metadata source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 17 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - - name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 +- name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: - - _time - - Channel - - Computer - - EventChannel - - EventCode - - EventData_Xml - - EventDescription - - EventID - - EventRecordID - - EventType - - Guid - - Image - - Keywords - - Level - - Name - - Opcode - - PipeName - - ProcessGuid - - ProcessID - - ProcessId - - RecordID - - RecordNumber - - RuleName - - SecurityID - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - TimeCreated - - UserID - - UtcTime - - Version - - action - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - os - - pipe_name - - process_exec - - process_guid - - process_id - - process_name - - process_path - - punct - - severity_id - - signature - - signature_id - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user_id - - vendor_product +- _time +- Channel +- Computer +- EventChannel +- EventCode +- EventData_Xml +- EventDescription +- EventID +- EventRecordID +- EventType +- Guid +- Image +- Keywords +- Level +- Name +- Opcode +- PipeName +- ProcessGuid +- ProcessID +- ProcessId +- RecordID +- RecordNumber +- RuleName +- SecurityID +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- TimeCreated +- UserID +- UtcTime +- Version +- action +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- os +- pipe_name +- process_exec +- process_guid +- process_id +- process_name +- process_path +- punct +- severity_id +- signature +- signature_id +- source +- sourcetype +- splunk_server +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user_id +- vendor_product example_log: 17141700x800000000000000017141700x8000000000000000162168Microsoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.local-CreatePipe2021-04-19 21:00:18.288{761B69BB-EF62-607D-B211-00000000BA01}6960\MSSE-1516-server18141800x800000000000000018141800x8000000000000000162173Microsoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.local-ConnectPipe2021-04-19 21:00:19.312{761B69BB-EF62-607D-B211-00000000BA01}6960\MSSE-1516-server20342000x800000000000000020342000x80000000000000006249Microsoft-Windows-Sysmon/Operationalwin-dc-935.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-935.attackrange.local-WmiConsumerEvent2020-12-08 13:54:48.514DeletedATTACKRANGE\Administrator "AtomicRedTeam-WMIPersistence-Example"21342100x800000000000000021342100x8000000000000000151644Microsoft-Windows-Sysmon/Operationalwin-host-14.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-host-14.attackrange.local-WmiBindingEvent2021-06-16 21:46:50.222ModifiedWIN-HOST-14\Administrator "CommandLineEventConsumer.Name=\"Evil diff --git a/data_sources/sysmon_eventid_22.yml b/data_sources/sysmon_eventid_22.yml index a40a8dc863..c8c1f78cdd 100644 --- a/data_sources/sysmon_eventid_22.yml +++ b/data_sources/sysmon_eventid_22.yml @@ -6,94 +6,92 @@ author: Patrick Bareiss, Splunk description: Logs DNS query events, including details about the queried domain, source IP, query type, and response data. mitre_components: - - Passive DNS - - Active DNS - - Network Traffic Content - - Network Traffic Flow - - Application Log Content +- Passive DNS +- Active DNS +- Network Traffic Content +- Network Traffic Flow +- Application Log Content source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 22 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - - name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 +- name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: - - _time - - Channel - - Computer - - EventChannel - - EventCode - - EventData_Xml - - EventDescription - - EventID - - EventRecordID - - Guid - - Image - - Keywords - - Level - - Name - - Opcode - - ProcessGuid - - ProcessID - - ProcessId - - QueryName - - QueryResults - - QueryStatus - - RecordID - - RecordNumber - - RuleName - - SecurityID - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - TimeCreated - - UserID - - UtcTime - - Version - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - process_exec - - process_guid - - process_name - - punct - - query - - query_count - - reply_code_id - - signature - - signature_id - - source - - sourcetype - - splunk_server - - src - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user_id - - vendor_product +- _time +- Channel +- Computer +- EventChannel +- EventCode +- EventData_Xml +- EventDescription +- EventID +- EventRecordID +- Guid +- Image +- Keywords +- Level +- Name +- Opcode +- ProcessGuid +- ProcessID +- ProcessId +- QueryName +- QueryResults +- QueryStatus +- RecordID +- RecordNumber +- RuleName +- SecurityID +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- TimeCreated +- UserID +- UtcTime +- Version +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- process_exec +- process_guid +- process_name +- punct +- query +- query_count +- reply_code_id +- signature +- signature_id +- source +- sourcetype +- splunk_server +- src +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user_id +- vendor_product example_log: 22542200x800000000000000022542200x8000000000000000113892Microsoft-Windows-Sysmon/Operationalwin-dc-299.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-299.attackrange.local-2021-03-24 12:25:12.840{3CFDEE80-2F7D-605B-F50A-00000000AE01}717250.220.65.3.spam.dnsbl.sorbs.net23542300x800000000000000023542300x8000000000000000281771Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-865.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-865.attackrange.local-2023-02-01 10:57:09.814{F522A29C-446D-63DA-9F01-00000000BB02}2428ATTACKRANGE\Administrator354300x8000000000000000354300x8000000000000000156837Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-403.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-403.attackrange.local-2022-09-15 12:56:19.679{6820D070-1F1B-6323-E113-000000007402}5728C:\Temp\agent_tesla-deob.exe534500x8000000000000000534500x800000000000000039965Microsoft-Windows-Sysmon/Operationalwin-dc-654.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-654.attackrange.local-2021-03-16 14:01:44.004{26337912-BA32-6050-3506-00000000AE01}8672C:\Users\Public\steam.exe diff --git a/data_sources/sysmon_eventid_6.yml b/data_sources/sysmon_eventid_6.yml index d019cb51cf..c9d0d5d247 100644 --- a/data_sources/sysmon_eventid_6.yml +++ b/data_sources/sysmon_eventid_6.yml @@ -6,97 +6,94 @@ author: Patrick Bareiss, Splunk description: Logs the loading of a driver into the kernel or user mode, including details about the driver name, file path, and associated process metadata. mitre_components: - - Driver Load - - Process Metadata - - Application Log Content - - OS API Execution +- Driver Load +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 6 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - - name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 +- name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: - - _time - - Channel - - Computer - - EventChannel - - EventCode - - EventData_Xml - - EventDescription - - EventID - - EventRecordID - - Guid - - Hashes - - ImageLoaded - - Keywords - - Level - - MD5 - - Name - - Opcode - - ProcessID - - RecordID - - RecordNumber - - RuleName - - SHA256 - - SecurityID - - Signature - - SignatureStatus - - Signed - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - TimeCreated - - UserID - - UtcTime - - Version - - action - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - os - - process_hash - - process_path - - punct - - service_signature_exists - - service_signature_verified - - signature - - signature_id - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user_id - - vendor_product +- _time +- Channel +- Computer +- EventChannel +- EventCode +- EventData_Xml +- EventDescription +- EventID +- EventRecordID +- Guid +- Hashes +- ImageLoaded +- Keywords +- Level +- MD5 +- Name +- Opcode +- ProcessID +- RecordID +- RecordNumber +- RuleName +- SHA256 +- SecurityID +- Signature +- SignatureStatus +- Signed +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- TimeCreated +- UserID +- UtcTime +- Version +- action +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- os +- process_hash +- process_path +- punct +- service_signature_exists +- service_signature_verified +- signature +- signature_id +- source +- sourcetype +- splunk_server +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user_id +- vendor_product example_log: 644600x8000000000000000644600x800000000000000015708989Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-702.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-702.attackrange.local-2022-04-04 - 17:37:04.640C:\Program - Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\npf.sysC:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\npf.sysMD5=DE7FCC77F4A503AF4CA6A47D49B3713D,SHA256=4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6trueRiverbed Technology, Inc.Valid diff --git a/data_sources/sysmon_eventid_7.yml b/data_sources/sysmon_eventid_7.yml index 23a3dcf3a1..8c5dcd335e 100644 --- a/data_sources/sysmon_eventid_7.yml +++ b/data_sources/sysmon_eventid_7.yml @@ -6,120 +6,117 @@ author: Patrick Bareiss, Splunk description: Logs the loading of an image (module) into a process, including details about the image name, file path, and hash information. mitre_components: - - Module Load - - Process Metadata - - File Metadata - - Application Log Content - - OS API Execution +- Module Load +- Process Metadata +- File Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 7 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - - name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 +- name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: - - _time - - Channel - - Company - - Computer - - Description - - EventChannel - - EventCode - - EventData_Xml - - EventDescription - - EventID - - EventRecordID - - FileVersion - - Guid - - Hashes - - IMPHASH - - Image - - ImageLoaded - - Keywords - - Level - - MD5 - - Name - - Opcode - - OriginalFileName - - ProcessGuid - - ProcessID - - ProcessId - - Product - - RecordID - - RecordNumber - - RuleName - - SHA256 - - SecurityID - - Signature - - SignatureStatus - - Signed - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - TimeCreated - - User - - UserID - - UtcTime - - Version - - action - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - os - - parent_process_exec - - parent_process_guid - - parent_process_id - - parent_process_name - - parent_process_path - - process_exec - - process_hash - - process_name - - process_path - - punct - - service_dll_signature_exists - - service_dll_signature_verified - - signature - - signature_id - - source - - sourcetype - - splunk_server - - tag - - tag::action - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_id - - vendor_product +- _time +- Channel +- Company +- Computer +- Description +- EventChannel +- EventCode +- EventData_Xml +- EventDescription +- EventID +- EventRecordID +- FileVersion +- Guid +- Hashes +- IMPHASH +- Image +- ImageLoaded +- Keywords +- Level +- MD5 +- Name +- Opcode +- OriginalFileName +- ProcessGuid +- ProcessID +- ProcessId +- Product +- RecordID +- RecordNumber +- RuleName +- SHA256 +- SecurityID +- Signature +- SignatureStatus +- Signed +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- TimeCreated +- User +- UserID +- UtcTime +- Version +- action +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- os +- parent_process_exec +- parent_process_guid +- parent_process_id +- parent_process_name +- parent_process_path +- process_exec +- process_hash +- process_name +- process_path +- punct +- service_dll_signature_exists +- service_dll_signature_verified +- signature +- signature_id +- source +- sourcetype +- splunk_server +- tag +- tag::action +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_id +- vendor_product example_log: 734700x8000000000000000734700x800000000000000045273Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.localMicrosoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2023-09-12 08:06:31.433{8814F3F5-1C07-6500-9600-000000000E03}4440C:\Users\Administrator\AppData\Local\Temp\server.exeC:\Users\Administrator\AppData\Local\Temp\server.exe-----MD5=696CBE2CB6F7FAC5ED6262BCA51238BB,SHA256=43005D86607DC94C7D378AA1B8844947BAA03860652F2F2340266061AF12E524,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744--MD5=696CBE2CB6F7FAC5ED6262BCA51238BB,SHA256=43005D86607DC94C7D378AA1B8844947BAA03860652F2F2340266061AF12E524,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744false-UnavailableATTACKRANGE\Administrator diff --git a/data_sources/sysmon_eventid_8.yml b/data_sources/sysmon_eventid_8.yml index 086d972abf..bb8b3a983b 100644 --- a/data_sources/sysmon_eventid_8.yml +++ b/data_sources/sysmon_eventid_8.yml @@ -6,106 +6,104 @@ author: Patrick Bareiss, Splunk description: Logs the creation of a new thread in a process, including details about the thread ID, start address, and source process. mitre_components: - - Process Modification - - Process Metadata - - Application Log Content - - OS API Execution +- Process Modification +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID separator_value: 8 configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - - name: Splunk Add-on for Sysmon - url: https://splunkbase.splunk.com/app/5709 - version: 4.0.2 +- name: Splunk Add-on for Sysmon + url: https://splunkbase.splunk.com/app/5709 + version: 4.0.2 fields: - - _time - - Channel - - Computer - - EventChannel - - EventCode - - EventData_Xml - - EventDescription - - EventID - - EventRecordID - - Guid - - Keywords - - Level - - Name - - NewThreadId - - Opcode - - ProcessID - - RecordID - - RecordNumber - - RuleName - - SecurityID - - SourceImage - - SourceProcessGuid - - SourceProcessId - - StartAddress - - StartFunction - - StartModule - - SystemTime - - System_Props_Xml - - TargetImage - - TargetProcessGuid - - TargetProcessId - - Task - - ThreadID - - TimeCreated - - UserID - - UtcTime - - Version - - action - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - os - - parent_process_exec - - parent_process_guid - - parent_process_id - - parent_process_name - - parent_process_path - - process_exec - - process_guid - - process_id - - process_name - - process_path - - punct - - signature - - signature_id - - source - - sourcetype - - splunk_server - - src_address - - src_function - - src_module - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user_id - - vendor_product +- _time +- Channel +- Computer +- EventChannel +- EventCode +- EventData_Xml +- EventDescription +- EventID +- EventRecordID +- Guid +- Keywords +- Level +- Name +- NewThreadId +- Opcode +- ProcessID +- RecordID +- RecordNumber +- RuleName +- SecurityID +- SourceImage +- SourceProcessGuid +- SourceProcessId +- StartAddress +- StartFunction +- StartModule +- SystemTime +- System_Props_Xml +- TargetImage +- TargetProcessGuid +- TargetProcessId +- Task +- ThreadID +- TimeCreated +- UserID +- UtcTime +- Version +- action +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- os +- parent_process_exec +- parent_process_guid +- parent_process_id +- parent_process_name +- parent_process_path +- process_exec +- process_guid +- process_id +- process_name +- process_path +- punct +- signature +- signature_id +- source +- sourcetype +- splunk_server +- src_address +- src_function +- src_module +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user_id +- vendor_product example_log: 824800x8000000000000000824800x8000000000000000362233Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-487.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-487.attackrange.local-2022-10-27 13:59:12.427{3381F800-8EB0-635A-1306-000000008A02}4864C:\Windows\SysWOW64\wermgr.exe924900x8000000000000000924900x8000000000000000190607Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-478.attackrange.localMicrosoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-478.attackrange.local-2022-02-25 12:25:33.359{414E8EDF-CABB-6218-F103-000000003702}6068C:\Temp\c.exe\Device\HarddiskVolume1 diff --git a/data_sources/sysmon_for_linux_eventid_1.yml b/data_sources/sysmon_for_linux_eventid_1.yml index 5850fd83d6..e8c72edc4e 100644 --- a/data_sources/sysmon_for_linux_eventid_1.yml +++ b/data_sources/sysmon_for_linux_eventid_1.yml @@ -6,113 +6,111 @@ author: Patrick Bareiss, Splunk description: Logs process creation events on Linux systems, including details about the process name, process ID, command line arguments, and parent process ID. mitre_components: - - Process Creation - - Command Execution - - Process Metadata - - OS API Execution - - Application Log Content +- Process Creation +- Command Execution +- Process Metadata +- OS API Execution +- Application Log Content source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux separator: EventID separator_value: 1 supported_TA: - - name: Splunk Add-on for Sysmon for Linux - url: https://splunkbase.splunk.com/app/6652 - version: 1.0.0 +- name: Splunk Add-on for Sysmon for Linux + url: https://splunkbase.splunk.com/app/6652 + version: 1.0.0 fields: - - _time - - Channel - - CommandLine - - Company - - Computer - - CurrentDirectory - - Description - - EventChannel - - EventCode - - EventData_Xml - - EventDescription - - EventID - - EventRecordID - - FileVersion - - Guid - - Hashes - - Image - - IntegrityLevel - - Keywords - - Level - - LogonGuid - - LogonId - - Name - - Opcode - - OriginalFileName - - ParentCommandLine - - ParentImage - - ParentProcessGuid - - ParentProcessId - - ParentUser - - ProcessGuid - - ProcessID - - ProcessId - - Product - - RecordID - - RuleName - - SystemTime - - System_Props_Xml - - Task - - TerminalSessionId - - ThreadID - - User - - UserId - - UtcTime - - Version - - action - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - eventtype - - host - - index - - linecount - - original_file_name - - os - - parent_process - - parent_process_exec - - parent_process_guid - - parent_process_id - - parent_process_name - - parent_process_path - - process - - process_current_directory - - process_exec - - process_guid - - process_hash - - process_id - - process_integrity_level - - process_name - - process_path - - punct - - signature - - signature_id - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - vendor_product -example_log: 154100x8000000000000000154100x80000000000000001926574Linux-Sysmon/Operationalar-linuxLinux-Sysmon/Operationalar-linux-2022-08-09 10:42:47.757{ec23eae3-3a27-62f2-085e-16549b550000}10268/usr/bin/sudo-11241100x800000000000000011241100x8000000000000000792913Linux-Sysmon/Operationalsysmonlinux-tcontreras-attack-range-4134Linux-Sysmon/Operationalsysmonlinux-tcontreras-attack-range-4134-2021-12-20 16:07:17.929{ec2c97d1-6aa9-61c0-3038-618238560000}5256/opt/splunkforwarder/bin/splunkd4688201331200x80200000000000004688201331200x8020000000000000362027Securityar-win-2.attackrange.localSecurityar-win-2.attackrange.localNT AUTHORITY\SYSTEMAR-WIN-2$ATTACKRANGE0x3e70xa44C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe228202000x80000000000000228202000x800000000000001001307Applicationwin-dc-exch01.attackrange.localc:\temp\msf.dllAMD64C1000000 + ProcessID='0' ThreadID='0'/>Applicationwin-dc-exch01.attackrange.localc:\temp\msf.dllAMD64C1000000 diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index f7588b104a..a3dcec0bda 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -6,70 +6,68 @@ author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process, its termination code, and timestamp. mitre_components: - - Process Termination - - Process Metadata - - Application Log Content - - OS API Execution +- Process Termination +- Process Metadata +- Application Log Content +- OS API Execution source: XmlWinEventLog:Application sourcetype: XmlWinEventLog separator: EventCode separator_value: 3000 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - Channel - - Computer - - Error_Code - - EventCode - - EventData_Xml - - EventRecordID - - EventSourceName - - Guid - - Keywords - - Level - - Name - - Opcode - - ProcessID - - Qualifiers - - RecordNumber - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - UserID - - Version - - dest - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - param1 - - param2 - - param3 - - punct - - signature_id - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - timestamp - - user_id - - vendor_product +- _time +- Channel +- Computer +- Error_Code +- EventCode +- EventData_Xml +- EventRecordID +- EventSourceName +- Guid +- Keywords +- Level +- Name +- Opcode +- ProcessID +- Qualifiers +- RecordNumber +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- UserID +- Version +- dest +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- param1 +- param2 +- param3 +- punct +- signature_id +- source +- sourcetype +- splunk_server +- tag +- tag::eventtype +- timestamp +- user_id +- vendor_product example_log: 300004000x80000000000000300004000x8000000000000021334Applicationwin-host-mhaag-attack-range-117Applicationwin-host-mhaag-attack-range-117C:\Windows\System32\klist.exe001d8c3afcf370d13 diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index 1ace202695..cc9a329fac 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -6,73 +6,71 @@ author: Patrick Bareiss, Splunk description: This event log records events related to cryptographic operations, including the deletion and export of certificates. mitre_components: - - Certificate Registration - - Process Metadata - - Application Log Content - - OS API Execution - - Host Status +- Certificate Registration +- Process Metadata +- Application Log Content +- OS API Execution +- Host Status source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational sourcetype: xmlwineventlog separator: EventCode separator_value: 70 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - Channel - - Computer - - EventCode - - EventID - - EventRecordID - - Guid - - Keywords - - Level - - Name - - Opcode - - ProcessID - - RecordNumber - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - UserData_Xml - - UserID - - Version - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - punct - - signature_id - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user_id - - vendor_product +- _time +- Channel +- Computer +- EventCode +- EventID +- EventRecordID +- Guid +- Keywords +- Level +- Name +- Opcode +- ProcessID +- RecordNumber +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- UserData_Xml +- UserID +- Version +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- punct +- signature_id +- source +- sourcetype +- splunk_server +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user_id +- vendor_product example_log: 70047000x400000000000008070047000x4000000000000080308332Microsoft-Windows-CAPI2/Operationalwin-dc-mhaag-attack-range-84.attackrange.localMicrosoft-Windows-CAPI2/Operationalwin-dc-mhaag-attack-range-84.attackrange.local81028020x400000000000004081028020x40000000000000402400597Microsoft-Windows-CAPI2/Operationalmswin-server.attackrange.localMicrosoft-Windows-CAPI2/Operationalmswin-server.attackrange.local{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}WTD_UI_NONEWTD_STATEACTION_VERIFY2021-01-07T23:21:42.655Z2021-01-07T23:21:42.655ZThe digital signature of the object did not verify.100704000x8000000000000000100704000x80000000000000002Microsoft-Windows-CertificateServicesClient-Lifecycle-System/OperationalDESKTOP-92OQLA1112103000x8000000000000000112103000x80000000000000002975Microsoft-Windows-Windows Defender/Operationalresearchvmhaa112204000x8000000000000000112204000x80000000000000003701Microsoft-Windows-Windows Defender/Operationalresearchvmhaa500704000x8000000000000000500704000x80000000000000003726Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender diff --git a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml index 66a21053dc..c0b00aad8d 100644 --- a/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml +++ b/data_sources/windows_event_log_microsoft_windows_terminalservices_rdpclient_1024.yml @@ -6,47 +6,47 @@ author: Michael Haag, Splunk description: Logs an event when a Remote Desktop Protocol (RDP) client successfully connects to a remote host. mitre_components: - - Network Connection Creation - - Logon Session Creation +- Network Connection Creation +- Logon Session Creation source: WinEventLog:Microsoft-Windows-TerminalServices-RDPClient/Operational sourcetype: WinEventLog separator: EventCode supported_TA: [] fields: - - _time - - Channel - - Computer - - EventCode - - EventData - - EventID - - EventRecordID - - EventType - - Keywords - - Level - - Message - - Opcode - - ProcessID - - RecordNumber - - Security_ID - - Src - - Src_Host - - Src_NT_Domain - - Src_User - - System_TimeCreated - - Task - - ThreadID - - Type - - User - - UserID - - Version - - dest - - dvc - - event_id - - host - - source - - sourcetype - - tag - - user +- _time +- Channel +- Computer +- EventCode +- EventData +- EventID +- EventRecordID +- EventType +- Keywords +- Level +- Message +- Opcode +- ProcessID +- RecordNumber +- Security_ID +- Src +- Src_Host +- Src_NT_Domain +- Src_User +- System_TimeCreated +- Task +- ThreadID +- Type +- User +- UserID +- Version +- dest +- dvc +- event_id +- host +- source +- sourcetype +- tag +- user example_log: 11/21/2024 06:09:16 PM LogName=Microsoft-Windows-TerminalServices-RDPClient/Operational EventCode=1024 EventType=4 ComputerName=ar-win-5.attackrange.local User=NOT_TRANSLATED Sid=S-1-5-21-1731938146-2314223186-1848411941-500 SidType=0 SourceName=Microsoft-Windows-TerminalServices-ClientActiveXCore diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index 74eecb2f6a..a13491e365 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -5,59 +5,59 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when printer drivers are installed or updated on the system. mitre_components: - - Driver Load - - Driver Metadata +- Driver Load +- Driver Metadata source: WinEventLog:Microsoft-Windows-PrintService/Admin sourcetype: WinEventLog separator: EventCode separator_value: 316 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - ComputerName - - EventCode - - EventType - - Keywords - - LogName - - Message - - OpCode - - RecordNumber - - Sid - - SidType - - SourceName - - TaskCategory - - Type - - User - - category - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - punct - - severity - - severity_id - - signature_id - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - timeendpos - - timestartpos - - vendor_product +- _time +- ComputerName +- EventCode +- EventType +- Keywords +- LogName +- Message +- OpCode +- RecordNumber +- Sid +- SidType +- SourceName +- TaskCategory +- Type +- User +- category +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- punct +- severity +- severity_id +- signature_id +- source +- sourcetype +- splunk_server +- tag +- tag::eventtype +- timeendpos +- timestartpos +- vendor_product example_log: 07/01/2021 04:20:47 PM diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index 3f73b548be..2f1c1363e4 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -6,63 +6,63 @@ author: Patrick Bareiss, Splunk description: Logs an event when the print spooler service fails to load a printer plug-in module. mitre_components: - - Module Load - - Application Log Content - - Service Metadata +- Module Load +- Application Log Content +- Service Metadata source: WinEventLog:Microsoft-Windows-PrintService/Admin sourcetype: WinEventLog separator: EventCode separator_value: 808 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - ComputerName - - EventCode - - EventType - - Keywords - - LogName - - Message - - OpCode - - RecordNumber - - Sid - - SidType - - SourceName - - TaskCategory - - Type - - User - - category - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - name - - punct - - severity - - severity_id - - signature - - signature_id - - source - - sourcetype - - splunk_server - - subject - - tag - - tag::eventtype - - timeendpos - - timestartpos - - vendor_product +- _time +- ComputerName +- EventCode +- EventType +- Keywords +- LogName +- Message +- OpCode +- RecordNumber +- Sid +- SidType +- SourceName +- TaskCategory +- Type +- User +- category +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- name +- punct +- severity +- severity_id +- signature +- signature_id +- source +- sourcetype +- splunk_server +- subject +- tag +- tag::eventtype +- timeendpos +- timestartpos +- vendor_product example_log: 07/01/2021 04:20:47 PM diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index 00eb66eec2..17e1e81b90 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -5,63 +5,60 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a Remote Desktop Service session is initialized. mitre_components: - - Network Connection Creation - - Logon Session Creation - - Logon Session Metadata -source: - WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational +- Network Connection Creation +- Logon Session Creation +- Logon Session Metadata +source: WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational sourcetype: wineventlog separator: EventCode separator_value: 1149 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - ActivityID - - Channel - - Computer - - EventCode - - EventID - - EventRecordID - - Guid - - Keywords - - Level - - Name - - Opcode - - ProcessID - - RecordNumber - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - UserData_Xml - - UserID - - Version - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - punct - - signature_id - - source - - sourcetype - - splunk_server - - tag - - tag::eventtype - - timestamp - - user_id - - vendor_product +- _time +- ActivityID +- Channel +- Computer +- EventCode +- EventID +- EventRecordID +- Guid +- Keywords +- Level +- Name +- Opcode +- ProcessID +- RecordNumber +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- UserData_Xml +- UserID +- Version +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- punct +- signature_id +- source +- sourcetype +- splunk_server +- tag +- tag::eventtype +- timestamp +- user_id +- vendor_product example_log: 114904000x1000000000000000114904000x10000000000000002064Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operationalar-win-1.attackrange.localAdministratorATTACKRANGE10.0.1.14 + UserID='S-1-5-20'/>AdministratorATTACKRANGE10.0.1.14 diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index 3c118a5dfc..f926bde8c2 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -5,82 +5,80 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when the event logging service has shut down. mitre_components: - - Host Status - - System Configuration Changes +- Host Status +- System Configuration Changes source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 1100 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - Channel - - Computer - - Error_Code - - EventCode - - EventID - - EventRecordID - - Guid - - Keywords - - Level - - Name - - Opcode - - ProcessID - - RecordNumber - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - UserData_Xml - - Version - - action - - app - - change_type - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - name - - object_attrs - - object_category - - product - - punct - - service - - service_name - - signature - - signature_id - - source - - sourcetype - - splunk_server - - status - - subject - - ta_windows_action - - tag - - tag::eventtype - - timeendpos - - timestartpos - - vendor - - vendor_product +- _time +- Channel +- Computer +- Error_Code +- EventCode +- EventID +- EventRecordID +- Guid +- Keywords +- Level +- Name +- Opcode +- ProcessID +- RecordNumber +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- UserData_Xml +- Version +- action +- app +- change_type +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- name +- object_attrs +- object_category +- product +- punct +- service +- service_name +- signature +- signature_id +- source +- sourcetype +- splunk_server +- status +- subject +- ta_windows_action +- tag +- tag::eventtype +- timeendpos +- timestartpos +- vendor +- vendor_product example_log: 11000410300x402000000000000011000410300x4020000000000000140874Securityar-win-2Securityar-win-2 diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index 3e46c4323f..d66920335f 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -5,88 +5,86 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when the audit log is cleared. mitre_components: - - User Account Modification - - Logon Session Metadata - - File Deletion +- User Account Modification +- Logon Session Metadata +- File Deletion source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 1102 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - Caller_User_Name - - Channel - - Computer - - Error_Code - - EventCode - - EventID - - EventRecordID - - Guid - - Keywords - - Level - - LogFileCleared_Xml - - Name - - Opcode - - ProcessID - - RecordNumber - - SubjectDomainName - - SubjectLogonId - - SubjectUserName - - SubjectUserSid - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - UserData_Xml - - Version - - action - - app - - change_type - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - name - - object_attrs - - object_category - - product - - punct - - signature - - signature_id - - source - - sourcetype - - splunk_server - - src_user - - status - - subject - - ta_windows_action - - tag - - tag::eventtype - - timeendpos - - timestartpos - - vendor - - vendor_product +- _time +- Caller_User_Name +- Channel +- Computer +- Error_Code +- EventCode +- EventID +- EventRecordID +- Guid +- Keywords +- Level +- LogFileCleared_Xml +- Name +- Opcode +- ProcessID +- RecordNumber +- SubjectDomainName +- SubjectLogonId +- SubjectUserName +- SubjectUserSid +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- UserData_Xml +- Version +- action +- app +- change_type +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- name +- object_attrs +- object_category +- product +- punct +- signature +- signature_id +- source +- sourcetype +- splunk_server +- src_user +- status +- subject +- ta_windows_action +- tag +- tag::eventtype +- timeendpos +- timestartpos +- vendor +- vendor_product example_log: 11020410400x402000000000000011020410400x40200000000000001826166Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localATTACKRANGE\AdministratorAdministratorATTACKRANGE0x34a3a27 diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index 62d69f0c10..823b6f2dee 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -5,125 +5,124 @@ date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an account successfully logs on to a system. mitre_components: - - Logon Session Creation - - User Account Authentication - - Logon Session Metadata +- Logon Session Creation +- User Account Authentication +- Logon Session Metadata source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 4624 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - ActivityID - - AuthenticationPackageName - - Caller_Domain - - Caller_User_Name - - Channel - - Computer - - ElevatedToken - - Error_Code - - EventCode - - EventData_Xml - - EventID - - EventRecordID - - Guid - - ImpersonationLevel - - IpAddress - - IpPort - - KeyLength - - Keywords - - Level - - LmPackageName - - LogonGuid - - LogonProcessName - - LogonType - - Logon_ID - - Logon_Type - - Name - - Opcode - - ProcessID - - ProcessId - - ProcessName - - RecordNumber - - RestrictedAdminMode - - Source_Port - - Source_Workstation - - SubjectDomainName - - SubjectLogonId - - SubjectUserName - - SubjectUserSid - - SystemTime - - System_Props_Xml - - TargetDomainName - - TargetLinkedLogonId - - TargetLogonId - - TargetOutboundDomainName - - TargetOutboundUserName - - TargetUserName - - TargetUserSid - - Target_Domain - - Target_User_Name - - Task - - ThreadID - - TransmittedServices - - Version - - VirtualAccount - - WorkstationName - - action - - app - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_nt_domain - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - name - - process - - process_id - - process_name - - process_path - - product - - punct - - session_id - - signature - - signature_id - - source - - sourcetype - - splunk_server - - src_ip - - src_port - - status - - subject - - ta_windows_action - - tag - - tag::action - - tag::app - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_group - - vendor - - vendor_product +- _time +- ActivityID +- AuthenticationPackageName +- Caller_Domain +- Caller_User_Name +- Channel +- Computer +- ElevatedToken +- Error_Code +- EventCode +- EventData_Xml +- EventID +- EventRecordID +- Guid +- ImpersonationLevel +- IpAddress +- IpPort +- KeyLength +- Keywords +- Level +- LmPackageName +- LogonGuid +- LogonProcessName +- LogonType +- Logon_ID +- Logon_Type +- Name +- Opcode +- ProcessID +- ProcessId +- ProcessName +- RecordNumber +- RestrictedAdminMode +- Source_Port +- Source_Workstation +- SubjectDomainName +- SubjectLogonId +- SubjectUserName +- SubjectUserSid +- SystemTime +- System_Props_Xml +- TargetDomainName +- TargetLinkedLogonId +- TargetLogonId +- TargetOutboundDomainName +- TargetOutboundUserName +- TargetUserName +- TargetUserSid +- Target_Domain +- Target_User_Name +- Task +- ThreadID +- TransmittedServices +- Version +- VirtualAccount +- WorkstationName +- action +- app +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_nt_domain +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- name +- process +- process_id +- process_name +- process_path +- product +- punct +- session_id +- signature +- signature_id +- source +- sourcetype +- splunk_server +- src_ip +- src_port +- status +- subject +- ta_windows_action +- tag +- tag::action +- tag::app +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_group +- vendor +- vendor_product example_log: 4624201254400x80200000000000004624201254400x8020000000000000371886Securityar-win-7.attackrange.local4625001254400x80100000000000004625001254400x8010000000000000367348Securityar-win-8.attackrange.local4627001255400x80200000000000004627001255400x8020000000000000186260Securityar-win-dc.attackrange.local4648001254400x80200000000000004648001254400x8020000000000000336567Securitywin-host-mvelazco-02713-447.attackrange.local4662001408000x80100000000000004662001408000x801000000000000021623198276Securityattack_range_dc4663101280000x80200000000000004663101280000x802000000000000010525869Securityar-win-2.attackrange.localSecurityar-win-2.attackrange.localAR-WIN-2\AdministratorAdministratorAR-WIN-20x6cfe7SecurityFileC:\Program diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index 9c507ba8bc..b56a07aae1 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -6,89 +6,88 @@ author: Patrick Bareiss, Splunk description: Logs an event when a user with administrative privileges logs on to a system. mitre_components: - - Logon Session Creation - - User Account Authentication +- Logon Session Creation +- User Account Authentication source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 4672 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - ActivityID - - Caller_Domain - - Caller_User_Name - - Channel - - Computer - - Error_Code - - EventCode - - EventData_Xml - - EventID - - EventRecordID - - Guid - - Keywords - - Level - - Logon_ID - - Name - - Opcode - - PrivilegeList - - ProcessID - - RecordNumber - - SubjectDomainName - - SubjectLogonId - - SubjectUserName - - SubjectUserSid - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - Version - - action - - app - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - name - - product - - punct - - session_id - - signature - - signature_id - - source - - sourcetype - - splunk_server - - src_nt_domain - - src_user - - status - - subject - - ta_windows_action - - tag - - tag::action - - tag::eventtype - - timeendpos - - timestartpos - - vendor - - vendor_product +- _time +- ActivityID +- Caller_Domain +- Caller_User_Name +- Channel +- Computer +- Error_Code +- EventCode +- EventData_Xml +- EventID +- EventRecordID +- Guid +- Keywords +- Level +- Logon_ID +- Name +- Opcode +- PrivilegeList +- ProcessID +- RecordNumber +- SubjectDomainName +- SubjectLogonId +- SubjectUserName +- SubjectUserSid +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- Version +- action +- app +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- name +- product +- punct +- session_id +- signature +- signature_id +- source +- sourcetype +- splunk_server +- src_nt_domain +- src_user +- status +- subject +- ta_windows_action +- tag +- tag::action +- tag::eventtype +- timeendpos +- timestartpos +- vendor +- vendor_product example_log: 4672001254800x80200000000000004672001254800x8020000000000000148946Securityar-win-6.attackrange.local4688201331200x80200000000000004688201331200x8020000000000000432820Securityar-win-1Securityar-win-1NT AUTHORITY\SYSTEMAR-WIN-1$WORKGROUP0x3e70xf84C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe4703001331700x80200000000000004703001331700x8020000000000000328761Securitywin-host-ctus-attack-range-115Securitywin-host-ctus-attack-range-115WIN-HOST-CTUS-A\AdministratorAdministratorWIN-HOST-CTUS-A0x288b91WIN-HOST-CTUS-A\AdministratorAdministrator4719001356800x80200000000000004719001356800x8020000000000000353597Securityar-win-dc.attackrange.local4724001382400x80200000000000004724001382400x8020000000000000276779Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localTRUMAN_CLEMENTSATTACKRANGEATTACKRANGE\TRUMAN_CLEMENTSATTACKRANGE\AdministratorAdministratorATTACKRANGE4725001382400x80200000000000004725001382400x8020000000000000278771Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localWILFORD_SUTTONATTACKRANGEATTACKRANGE\WILFORD_SUTTONATTACKRANGE\AdministratorAdministratorATTACKRANGE4726001382400x80200000000000004726001382400x8020000000000000279283Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localLYNN_WOLFATTACKRANGES-1-5-21-2851375338-1978525053-2422663219-2445ATTACKRANGE\AdministratorAdministratorATTACKRANGE4738001382400x80200000000000004738001382400x80200000000000006389713Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.local-unprivATTACKRANGES-1-5-21-945660386-2529346225-2932127451-1112S-1-5-21-945660386-2529346225-2932127451-500AdministratorATTACKRANGE4739001356900x80200000000000004739001356900x8020000000000000394176Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localLockout PolicyATTACKRANGEATTACKRANGE\NT AUTHORITY\SYSTEMAR-WIN-DC$ATTACKRANGE4741001382500x80200000000000004741001382500x8020000000000000143475Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localAR-WIN-2$ATTACKRANGEATTACKRANGE\AR-WIN-2$ATTACKRANGE\AdministratorAdministratorATTACKRANGE4742001382500x80200000000000004742001382500x8020000000000000901860Securitywin-dc-root-04195-428.attackrange.localSecuritywin-dc-root-04195-428.attackrange.local-WIN-HOST-ROOT-0$ATTACKRANGES-1-5-21-199921393-3534762603-6736986-1111S-1-5-21-199921393-3534762603-6736986-500Administrator4768001433900x80100000000000004768001433900x8010000000000000391562Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localRXETPKZHattackrange.localNULL SIDkrbtgt/attackrange.localNULL SID0x408100104769001433700x80200000000000004769001433700x8020000000000000148521Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localAR-WIN-2$@ATTACKRANGE.LOCALATTACKRANGE.LOCALAR-WIN-2$ATTACKRANGE\AR-WIN-2$0x408100000x174771001433900x80100000000000004771001433900x8010000000000000391511Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localALLISON_WATERSATTACKRANGE\ALLISON_WATERSkrbtgt/attackrange.local0x408100100x182::ffff:10.0.1.154776001433600x80100000000000004776001433600x8010000000000000391615Securitywin-dc-mvelazco-02713-392.attackrange.localSecuritywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0KSYLEFUAWIN-HOST-MVELAZ0xc0000064 diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index eee4c4c3f3..2e6adff3c4 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -6,107 +6,106 @@ author: Patrick Bareiss, Splunk description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action. mitre_components: - - User Account Modification - - User Account Metadata - - Active Directory Object Modification - - Application Log Content +- User Account Modification +- User Account Metadata +- Active Directory Object Modification +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 4781 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - ActivityID - - Caller_Domain - - Caller_User_Name - - CategoryString - - Channel - - Computer - - Error_Code - - EventCode - - EventData_Xml - - EventID - - EventRecordID - - Guid - - Keywords - - Level - - Logon_ID - - Name - - NewTargetUserName - - OldTargetUserName - - Opcode - - PrivilegeList - - ProcessID - - RecordNumber - - SubjectDomainName - - SubjectLogonId - - SubjectUserName - - SubjectUserSid - - SystemTime - - System_Props_Xml - - TargetDomainName - - TargetSid - - Target_Domain - - Task - - ThreadID - - Version - - action - - app - - change_type - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dest_nt_domain - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - name - - object - - object_attrs - - object_category - - object_id - - product - - punct - - result - - session_id - - signature - - signature_id - - source - - sourcetype - - splunk_server - - src_nt_domain - - src_user - - src_user_name - - status - - subject - - ta_windows_action - - ta_windows_security_CategoryString - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user - - user_name - - vendor - - vendor_product +- _time +- ActivityID +- Caller_Domain +- Caller_User_Name +- CategoryString +- Channel +- Computer +- Error_Code +- EventCode +- EventData_Xml +- EventID +- EventRecordID +- Guid +- Keywords +- Level +- Logon_ID +- Name +- NewTargetUserName +- OldTargetUserName +- Opcode +- PrivilegeList +- ProcessID +- RecordNumber +- SubjectDomainName +- SubjectLogonId +- SubjectUserName +- SubjectUserSid +- SystemTime +- System_Props_Xml +- TargetDomainName +- TargetSid +- Target_Domain +- Task +- ThreadID +- Version +- action +- app +- change_type +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dest_nt_domain +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- name +- object +- object_attrs +- object_category +- object_id +- product +- punct +- result +- session_id +- signature +- signature_id +- source +- sourcetype +- splunk_server +- src_nt_domain +- src_user +- src_user_name +- status +- subject +- ta_windows_action +- ta_windows_security_CategoryString +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user +- user_name +- vendor +- vendor_product example_log: 4781001382400x80200000000000004781001382400x8020000000000000148763Securityar-win-dc.attackrange.local4794001382400x80200000000000004794001382400x8020000000000000821077Securitywin-dc-root-17044-552.attackrange.local4798001382400x80200000000000004798001382400x8020000000000000386860Securityar-win-2.attackrange.local4876001280500x80200000000000004876001280500x802000000000000015379961Securitywin-dc-mhaag-attack-range-84.attackrange.local4886001280500x80200000000000004886001280500x802000000000000015379925Securitywin-dc-mhaag-attack-range-84.attackrange.local4887001280500x80200000000000004887001280500x80200000000000001830974609Securitycert_authority.attack_range.local5136001408100x80200000000000005136001408100x80200000000000001997365Securitywin-dc-mvelazco-02713-392.attackrange.local{73C96723-504B-4F15-830A-F4DDB1C48F2E}-ATTACKRANGE\AdministratorAdministratorATTACKRANGE0x95675attackrange.local%%14676CN=DANNIE_CERVANTES,OU=ServiceAccounts,OU=OGC,OU=Stage,DC=attackrange,DC=localattackrange.local%%14676CN=DANNIE_CERVANTES,OU=ServiceAccounts,OU=OGC,OU=Stage,DC=attackrange,DC=local{15AFB68A-679C-4F5B-AC18-4D988B3B3E44}userservicePrincipalName2.5.5.12adm/srv1.attackrange.local%%14674 diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index 9dc78ab362..b7da687fc2 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -6,102 +6,99 @@ author: Patrick Bareiss, Splunk description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: - - Active Directory Object Creation - - Active Directory Object Modification - - User Account Metadata - - Application Log Content +- Active Directory Object Creation +- Active Directory Object Modification +- User Account Metadata +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 5137 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - AppCorrelationID - - Caller_Domain - - Caller_User_Name - - Channel - - Computer - - DSName - - DSType - - Error_Code - - EventCode - - EventData_Xml - - EventID - - EventRecordID - - Guid - - Keywords - - Level - - Logon_ID - - Name - - ObjectClass - - ObjectDN - - ObjectGUID - - OpCorrelationID - - Opcode - - ProcessID - - RecordNumber - - SubjectDomainName - - SubjectLogonId - - SubjectUserName - - SubjectUserSid - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - Version - - action - - app - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - name - - product - - punct - - session_id - - signature - - signature_id - - source - - sourcetype - - splunk_server - - src_nt_domain - - src_user - - status - - subject - - ta_windows_action - - tag - - tag::action - - tag::eventtype - - timeendpos - - timestartpos - - vendor - - vendor_product +- _time +- AppCorrelationID +- Caller_Domain +- Caller_User_Name +- Channel +- Computer +- DSName +- DSType +- Error_Code +- EventCode +- EventData_Xml +- EventID +- EventRecordID +- Guid +- Keywords +- Level +- Logon_ID +- Name +- ObjectClass +- ObjectDN +- ObjectGUID +- OpCorrelationID +- Opcode +- ProcessID +- RecordNumber +- SubjectDomainName +- SubjectLogonId +- SubjectUserName +- SubjectUserSid +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- Version +- action +- app +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- name +- product +- punct +- session_id +- signature +- signature_id +- source +- sourcetype +- splunk_server +- src_nt_domain +- src_user +- status +- subject +- ta_windows_action +- tag +- tag::action +- tag::eventtype +- timeendpos +- timestartpos +- vendor +- vendor_product example_log: 5137001408100x80200000000000005137001408100x8020000000000000170140Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.local{681cac8c-b5a4-48fd-be93-4339996bd94d}-ATTACKRANGE\AdministratorAdministratorATTACKRANGE0x8561aattackrange.local%%14676CN={2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4},CN=Policies,CN=System,DC=attackrange,DC=localattackrange.local%%14676CN={2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4},CN=Policies,CN=System,DC=attackrange,DC=local{3e7ae4de-29a6-41c1-b27c-bf9548b0444c}groupPolicyContainer diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index 4fb8bf8cc6..537ad5db65 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -6,119 +6,117 @@ author: Patrick Bareiss, Splunk description: Logs access to a network share, including details about the user, share path, and the access type. mitre_components: - - Network Share Access - - File Access - - User Account Metadata - - Application Log Content +- Network Share Access +- File Access +- User Account Metadata +- Application Log Content source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode separator_value: 5140 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - AccessList - - AccessMask - - Caller_Domain - - Caller_User_Name - - Channel - - Computer - - Error_Code - - EventCode - - EventData_Xml - - EventID - - EventRecordID - - Guid - - IpAddress - - IpPort - - Keywords - - Level - - Logon_ID - - Name - - ObjectType - - Opcode - - ProcessID - - RecordNumber - - ShareName - - Source_Port - - Source_Workstation - - SubjectDomainName - - SubjectLogonId - - SubjectUserName - - SubjectUserSid - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - Version - - action - - app - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - dvc_nt_host - - event_id - - eventtype - - file_name - - host - - id - - index - - linecount - - name - - product - - punct - - session_id - - signature - - signature_id - - source - - sourcetype - - splunk_server - - src - - src_ip - - src_nt_domain - - src_nt_host - - src_port - - src_user - - status - - subject - - ta_windows_action - - tag - - tag::action - - tag::eventtype - - timeendpos - - timestartpos - - vendor - - vendor_product +- _time +- AccessList +- AccessMask +- Caller_Domain +- Caller_User_Name +- Channel +- Computer +- Error_Code +- EventCode +- EventData_Xml +- EventID +- EventRecordID +- Guid +- IpAddress +- IpPort +- Keywords +- Level +- Logon_ID +- Name +- ObjectType +- Opcode +- ProcessID +- RecordNumber +- ShareName +- Source_Port +- Source_Workstation +- SubjectDomainName +- SubjectLogonId +- SubjectUserName +- SubjectUserSid +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- Version +- action +- app +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- dvc_nt_host +- event_id +- eventtype +- file_name +- host +- id +- index +- linecount +- name +- product +- punct +- session_id +- signature +- signature_id +- source +- sourcetype +- splunk_server +- src +- src_ip +- src_nt_domain +- src_nt_host +- src_port +- src_user +- status +- subject +- ta_windows_action +- tag +- tag::action +- tag::eventtype +- timeendpos +- timestartpos +- vendor +- vendor_product field_mappings: - - data_model: ocsf - mapping: - AccessList: access_list - AccessMask: access_mask - AccessReason: access_result - ShareLocalPath: file - ObjectType: file.type - IpAddress: src_endpoint.ip - IpPort: src_endpoint.port - SubjectDomainName: actor.user.domain - SubjectUserName: actor.user.name - SubjectLogonId: actor.session.uid - SubjectUserSid: actor.user.uid +- data_model: ocsf + mapping: + AccessList: access_list + AccessMask: access_mask + AccessReason: access_result + ShareLocalPath: file + ObjectType: file.type + IpAddress: src_endpoint.ip + IpPort: src_endpoint.port + SubjectDomainName: actor.user.domain + SubjectUserName: actor.user.name + SubjectLogonId: actor.session.uid + SubjectUserSid: actor.user.uid example_log: 5140101280800x80200000000000005140101280800x8020000000000000138541Securityar-win-66.attackrange.localSecurityar-win-66.attackrange.localATTACKRANGE\ELMER_SALASELMER_SALASATTACKRANGE0x2f259bFile10.0.1.16498645141001408100x80200000000000005141001408100x8020000000000000670908Securitywin-dc-range-02713-392.attackrange.local5145001281100x80200000000000005145001281100x80200000000000002018939Securityar-win-dc.attackrange.localSecurityar-win-dc.attackrange.localANONYMOUS LOGONANONYMOUS LOGONATTACKRANGE0x13ef1bFile10.0.1.1550160703604000x8080000000000000703604000x8080000000000000168530Systemar-win-dc.attackrange.localsppsvcstopped7300700070007300760063002F0031000000 + ProcessID='588' ThreadID='2272'/>Systemar-win-dc.attackrange.localsppsvcstopped7300700070007300760063002F0031000000 diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index 3a5f943ee0..0f26b121a0 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -6,86 +6,84 @@ author: Patrick Bareiss, Splunk description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type. mitre_components: - - Service Modification - - Service Metadata - - OS API Execution - - Application Log Content +- Service Modification +- Service Metadata +- OS API Execution +- Application Log Content source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode separator_value: 7040 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - Channel - - Computer - - Error_Code - - EventCode - - EventData_Xml - - EventRecordID - - EventSourceName - - Guid - - Keywords - - Level - - Name - - Opcode - - ProcessID - - Qualifiers - - RecordNumber - - ServiceName - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - UserID - - Version - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - param1 - - param2 - - param3 - - param4 - - product - - punct - - service - - service_name - - signature_id - - source - - sourcetype - - splunk_server - - start_mode - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user_id - - vendor - - vendor_product +- _time +- Channel +- Computer +- Error_Code +- EventCode +- EventData_Xml +- EventRecordID +- EventSourceName +- Guid +- Keywords +- Level +- Name +- Opcode +- ProcessID +- Qualifiers +- RecordNumber +- ServiceName +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- UserID +- Version +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- param1 +- param2 +- param3 +- param4 +- product +- punct +- service +- service_name +- signature_id +- source +- sourcetype +- splunk_server +- start_mode +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user_id +- vendor +- vendor_product example_log: 704004000x8080000000000000704004000x8080000000000000168231Systemar-win-dc.attackrange.localSystemar-win-dc.attackrange.localPrint Spoolerdemand startdisabledSpooler diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index a3f5ce006a..87c78b1a51 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -6,86 +6,84 @@ author: Patrick Bareiss, Splunk description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type. mitre_components: - - Service Creation - - Service Metadata - - OS API Execution - - Process Metadata +- Service Creation +- Service Metadata +- OS API Execution +- Process Metadata source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode separator_value: 7045 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - AccountName - - Channel - - Computer - - Error_Code - - EventCode - - EventData_Xml - - EventRecordID - - EventSourceName - - Guid - - ImagePath - - Keywords - - Level - - Name - - Opcode - - ProcessID - - Qualifiers - - RecordNumber - - ServiceName - - ServiceType - - StartType - - SystemTime - - System_Props_Xml - - Task - - ThreadID - - UserID - - Version - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - product - - punct - - service - - service_name - - signature_id - - source - - sourcetype - - splunk_server - - start_mode - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user_id - - vendor - - vendor_product +- _time +- AccountName +- Channel +- Computer +- Error_Code +- EventCode +- EventData_Xml +- EventRecordID +- EventSourceName +- Guid +- ImagePath +- Keywords +- Level +- Name +- Opcode +- ProcessID +- Qualifiers +- RecordNumber +- ServiceName +- ServiceType +- StartType +- SystemTime +- System_Props_Xml +- Task +- ThreadID +- UserID +- Version +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- product +- punct +- service +- service_name +- signature_id +- source +- sourcetype +- splunk_server +- start_mode +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user_id +- vendor +- vendor_product example_log: 704504000x8080000000000000704504000x8080000000000000168145Systemar-win-dc.attackrange.localSystemar-win-dc.attackrange.localKrbSCMpowershell.exe -WindowStyle Hiddenestno' diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index 4a29c55df5..2348f6b3f8 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -6,80 +6,79 @@ author: Patrick Bareiss, Splunk description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations. mitre_components: - - Scheduled Job Creation - - Scheduled Job Metadata - - Service Creation - - OS API Execution +- Scheduled Job Creation +- Scheduled Job Metadata +- Service Creation +- OS API Execution source: WinEventLog:Microsoft-Windows-TaskScheduler/Operational sourcetype: wineventlog separator: EventCode separator_value: 200 supported_TA: - - name: Splunk Add-on for Microsoft Windows - url: https://splunkbase.splunk.com/app/742 - version: 9.0.1 +- name: Splunk Add-on for Microsoft Windows + url: https://splunkbase.splunk.com/app/742 + version: 9.0.1 fields: - - _time - - ActionName - - ActivityID - - Channel - - Computer - - EnginePID - - Error_Code - - EventCode - - EventData_Xml - - EventID - - EventRecordID - - Guid - - Keywords - - Level - - Name - - Opcode - - ProcessID - - RecordNumber - - SystemTime - - System_Props_Xml - - Task - - TaskInstanceId - - TaskName - - ThreadID - - UserID - - Version - - app - - date_hour - - date_mday - - date_minute - - date_month - - date_second - - date_wday - - date_year - - date_zone - - dest - - dvc - - dvc_nt_host - - event_id - - eventtype - - host - - id - - index - - linecount - - product - - punct - - signature_id - - source - - sourcetype - - splunk_server - - ta_windows_action - - tag - - tag::eventtype - - timeendpos - - timestartpos - - user_id - - vendor - - vendor_product +- _time +- ActionName +- ActivityID +- Channel +- Computer +- EnginePID +- Error_Code +- EventCode +- EventData_Xml +- EventID +- EventRecordID +- Guid +- Keywords +- Level +- Name +- Opcode +- ProcessID +- RecordNumber +- SystemTime +- System_Props_Xml +- Task +- TaskInstanceId +- TaskName +- ThreadID +- UserID +- Version +- app +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- dest +- dvc +- dvc_nt_host +- event_id +- eventtype +- host +- id +- index +- linecount +- product +- punct +- signature_id +- source +- sourcetype +- splunk_server +- ta_windows_action +- tag +- tag::eventtype +- timeendpos +- timestartpos +- user_id +- vendor +- vendor_product example_log: 2001420010x80000000000000002001420010x80000000000000004323Microsoft-Windows-TaskScheduler/Operationalar-win-dc.attackrange.local Date: Tue, 28 Jan 2025 10:42:10 -0800 Subject: [PATCH 04/67] adding a mapping yaml --- deprecated_detection_mapping.yml | 1260 ++++++++++++++++++++++++++++++ 1 file changed, 1260 insertions(+) create mode 100644 deprecated_detection_mapping.yml diff --git a/deprecated_detection_mapping.yml b/deprecated_detection_mapping.yml new file mode 100644 index 0000000000..ca0e64dcb3 --- /dev/null +++ b/deprecated_detection_mapping.yml @@ -0,0 +1,1260 @@ +- deprecated_name: ASL AWS Excessive Security Scanning + deprecated_id: ff2bfdbc-65b7-4434-8f08-d55761d1d446 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: AWS Cloud Provisioning From Previously Unseen Region + deprecated_id: 7971d3df-da82-4648-a6e5-b5637bea5253 + replacement_name: Cloud Provisioning Activity From Previously Unseen Region + replacement_id: 5aba1860-9617-4af9-b19d-aecac16fe4f2 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: First time seen command line argument + deprecated_id: a1b6e73f-98d5-470f-99ac-77aacd578473 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Windows connhost exe started forcefully + deprecated_id: c114aaca-68ee-41c2-ad8c-32bf21db8769 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Detect Mimikatz Using Loaded Images + deprecated_id: 29e307ba-40af-4ab2-91b2-3c6b392bbba0 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Kubernetes Azure detect sensitive role access + deprecated_id: f27349e5-1641-4f6a-9e68-30402be0ad4c + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Web Fraud - Anomalous User Clickspeed + deprecated_id: 31337bbb-bc22-4752-b599-ef192df2dc7a + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: EC2 Instance Started With Previously Unseen Instance Type + deprecated_id: 65541c80-03c7-4e05-83c8-1dcd57a2e1ad + replacement_name: Cloud Compute Instance Created With Previously Unseen Instance + Type + replacement_id: c6ddbf53-9715-49f3-bb4c-fb2e8a309cda + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: EC2 Instance Started With Previously Unseen AMI + deprecated_id: 347ec301-601b-48b9-81aa-9ddf9c829dd3 + replacement_name: Cloud Compute Instance Created With Previously Unseen Image + replacement_id: bc24922d-987c-4645-b288-f8c73ec194c4 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Domain Group Discovery With Net + deprecated_id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349 + replacement_name: Windows Group Discovery Via Net + replacement_id: c5c8e0f3-147a-43da-bf04-4cfaec27dc44 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Kubernetes AWS detect sensitive role access + deprecated_id: b6013a7b-85e0-4a45-b051-10b252d69569 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Winword Spawning Windows Script Host + deprecated_id: 637e1b5c-9be1-11eb-9c32-acde48001122 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: 'The following analytics was deprecated in favour of a more generic approach. + Where instead of creating specific analytic for every potentially suspicious child + of an office product. We group them by threat level. + + This would ease management and false positives tuning.' +- deprecated_name: Winword Spawning PowerShell + deprecated_id: b2c950b8-9be2-11eb-8658-acde48001122 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Attempted Credential Dump From Registry via Reg exe + deprecated_id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911 + replacement_name: Windows Sensitive Registry Hive Dump Via CommandLine + replacement_id: 8bbb7d58-b360-11eb-ba21-acde48001122 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: This analytic had some overlap with another one, hence the deprecation. + It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry + Hive Dump Via CommandLine +- deprecated_name: Detect processes used for System Network Configuration Discovery + deprecated_id: a51bfe1a-94f0-48cc-b1e4-16ae10145893 + replacement_name: Potential System Network Configuration Discovery Activity + replacement_id: 3f0b95e3-3195-46ac-bea3-84fb59e7fac5 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Execution of File With Spaces Before Extension + deprecated_id: ab0353e6-a956-420b-b724-a8b4846d5d5a + replacement_name: Execution of File with Multiple Extensions + replacement_id: b06a555e-dce0-417d-a2eb-28a5d8d66ef7 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Updated to a new detection name +- deprecated_name: EC2 Instance Started In Previously Unseen Region + deprecated_id: ada0f478-84a8-4641-a3f3-d82362d6fd75 + replacement_name: Cloud Compute Instance Created In Previously Unused Region + replacement_id: fa4089e2-50e3-40f7-8469-d2cc1564ca59 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Office Document Spawned Child Process To Download + deprecated_id: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3 + replacement_name: Windows Office Product Spawned Child Process For Download + replacement_id: f02b64b8-cbea-4f75-bf77-7a05111566b1 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Detect new API calls from user roles + deprecated_id: 22773e84-bac0-4595-b086-20d3f335b4f1 + replacement_name: Cloud API Calls From Previously Unseen User Roles + replacement_id: 2181ad1f-1e73-4d0c-9780-e8880482a08f + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Cmdline Tool Not Executed In CMD Shell + deprecated_id: 6c3f7dd8-153c-11ec-ac2d-acde48001122 + replacement_name: Windows Cmdline Tool Execution From Non-Shell Process + replacement_id: 2afa393f-b88d-41b7-9793-623c93a2dfde + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Linux Auditd Find Private Keys + deprecated_id: 80bb9988-190b-4ee0-a3c3-509545a8f678 + replacement_name: Linux Auditd Private Keys and Certificate Enumeration + replacement_id: 892eb674-3344-4143-8e52-4775b1daf3f1 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Detect AWS API Activities From Unapproved Accounts + deprecated_id: ada0f478-84a8-4641-a3f1-d82362d4bd55 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Monitor DNS For Brand Abuse + deprecated_id: 24dd17b1-e2fb-4c31-878c-d4f746595bfa + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Kubernetes GCP detect sensitive object access + deprecated_id: bdb6d596-86a0-4aba-8369-418ae8b9963a + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Kubernetes Azure scan fingerprint + deprecated_id: c5e5bd5c-1013-4841-8b23-e7b3253c840a + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: ASL AWS Password Policy Changes + deprecated_id: 5ade5937-11a2-4363-ba6b-39a3ee8d5b1a + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: O365 Suspicious Admin Email Forwarding + deprecated_id: 7f398cfb-918d-41f4-8db8-2e2474e02c28 + replacement_name: O365 Mailbox Email Forwarding Enabled + replacement_id: 0b6bc75c-05d1-4101-9fc3-97e706168f24 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: AWS Cloud Provisioning From Previously Unseen City + deprecated_id: 344a1778-0b25-490c-adb1-de8beddf59cd + replacement_name: Cloud Provisioning Activity From Previously Unseen City + replacement_id: e7ecc5e0-88df-48b9-91af-51104c68f02f + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Kubernetes AWS detect service accounts forbidden failure access + deprecated_id: a6959c57-fa8f-4277-bb86-7c32fba579d5 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Osquery pack - ColdRoot detection + deprecated_id: a6fffe5e-05c3-4c04-badc-887607fbb8dc + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Windows Modify Registry Reg Restore + deprecated_id: d0072bd2-6d73-4c1b-bc77-ded6d2da3a4e + replacement_name: Windows Registry Entries Restored Via Reg + replacement_id: a17af481-e2ad-494c-9da6-afb4d243a019 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Kubernetes GCP detect most active service accounts by pod + deprecated_id: 7f5c2779-88a0-4824-9caa-0f606c8f260f + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Scheduled tasks used in BadRabbit ransomware + deprecated_id: 1297fb80-f42a-4b4a-9c8b-78c066437cf6 + replacement_name: Scheduled Task Deleted Or Created via CMD + replacement_id: d5af132c-7c17-439c-9d31-13d55340f36c + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Updated to a new detection name +- deprecated_name: Suspicious Rundll32 Rename + deprecated_id: 7360137f-abad-473e-8189-acbdaa34d114 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Remote System Discovery with Net + deprecated_id: 9df16706-04a2-41e2-bbfe-9b38b34409d3 + replacement_name: Windows Network Share Interaction With Net + replacement_id: 4dc3951f-b3f8-4f46-b412-76a483f72277 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: "This analytic was focusing on 2 separate and unrelated type of threats\ + \ or actions. It was split into other analytics, namely:\r\n\r\nWindows Network\ + \ Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows\ + \ Sensitive Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" +- deprecated_name: Remote System Discovery with Net + deprecated_id: 9df16706-04a2-41e2-bbfe-9b38b34409d3 + replacement_name: Windows Sensitive Group Discovery With Net + replacement_id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: DNS Query Requests Resolved by Unauthorized DNS Servers + deprecated_id: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f6 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Suspicious Changes to File Associations + deprecated_id: 1b989a0e-0129-4446-a695-f193a5b746fc + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: GCP Detect high risk permissions by resource and account + deprecated_id: 2e70ef35-2187-431f-aedc-4503dc9b06ba + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Office Product Writing cab or inf + deprecated_id: f48cd1d4-125a-11ec-a447-acde48001122 + replacement_name: Windows Office Product Dropped Cab or Inf File + replacement_id: dbdd251e-dd45-4ec9-a555-f5e151391746 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Identify New User Accounts + deprecated_id: 475b9e27-17e4-46e2-b7e2-648221be3b89 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Office Product Spawn CMD Process + deprecated_id: b8b19420-e892-11eb-9244-acde48001122 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Windows DLL Search Order Hijacking Hunt + deprecated_id: 79c7d0fc-60c7-41be-a616-ccda752efe89 + replacement_name: Windows DLL Search Order Hijacking Hunt with Sysmon + replacement_id: 79c7d1fc-64c7-91be-a616-ccda752efe81 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: ASL AWS CreateAccessKey + deprecated_id: ccb3e4af-23d6-407f-9842-a26212816c9e + replacement_name: ASL AWS Create Access Key + replacement_id: 81a9f2fe-1697-473c-af1d-086b0d8b63c8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Okta ThreatInsight Login Failure with High Unknown users + deprecated_id: 632663b0-4562-4aad-abe9-9f621a049738 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Detect Spike in Security Group Activity + deprecated_id: ada0f478-84a8-4641-a3f1-e32372d4bd53 + replacement_name: Abnormally High Number Of Cloud Security Group API Calls + replacement_id: d4dfb7f3-7a37-498a-b5df-f19334e871af + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Office Product Spawning BITSAdmin + deprecated_id: e8c591f4-a6d7-11eb-8cf7-acde48001122 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Create local admin accounts using net exe + deprecated_id: b89919ed-fe5f-492c-b139-151bb162040e + replacement_name: Windows Create Local Administrator Account Via Net + replacement_id: 2c568c34-bb57-4b43-9d75-19c605b98e70 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Abnormally High AWS Instances Terminated by User - MLTK + deprecated_id: 1c02b86a-cd85-473e-a50b-014a9ac8fe3e + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Windows Office Product Spawning MSDT + deprecated_id: 127eba64-c981-40bf-8589-1830638864a7 + replacement_name: Windows Office Product Spawned MSDT + replacement_id: a3148fad-3734-4b7f-9a71-62f08d39fab1 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Detect Spike in AWS API Activity + deprecated_id: ada0f478-84a8-4641-a3f1-d32362d4bd55 + replacement_name: '' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Office Product Spawning Windows Script Host + deprecated_id: b3628a5b-8d02-42fa-a891-eebf2351cbe1 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Prohibited Software On Endpoint + deprecated_id: a51bfe1a-94f0-48cc-b4e4-b6ae50145893 + replacement_name: Attacker Tools On Endpoint + replacement_id: a51bfe1a-94f0-48cc-b4e4-16a110145893 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: AWS Cloud Provisioning From Previously Unseen Country + deprecated_id: ceb8d3d8-06cb-49eb-beaf-829526e33ff0 + replacement_name: Cloud Provisioning Activity From Previously Unseen Country + replacement_id: 94994255-3acf-4213-9b3f-0494df03bb31 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Detect Critical Alerts from Security Tools + deprecated_id: 483e8a68-f2f7-45be-8fc9-bf725f0e22fd + replacement_name: Microsoft Defender ATP Alerts + replacement_id: 38f034ed-1598-46c8-95e8-14edf05fdf5d + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: As discussed internally, this analytic was too generic for an analyst to + do anything with it. It was deprecated in favor of the more specific approach + provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender + Incident Alerts. Going forward analytics from leveraging alerts from vendors will + have their specific analytics. +- deprecated_name: Detect Critical Alerts from Security Tools + deprecated_id: 483e8a68-f2f7-45be-8fc9-bf725f0e22fd + replacement_name: Microsoft Defender Incident Alerts + replacement_id: 13435b55-afd8-46d4-9045-7d5457f430a5 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Excel Spawning PowerShell + deprecated_id: 42d40a22-9be3-11eb-8f08-acde48001122 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Office Application Spawn rundll32 process + deprecated_id: 958751e4-9c5f-11eb-b103-acde48001122 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Excessive Usage Of Net App + deprecated_id: 45e52536-ae42-11eb-b5c6-acde48001122 + replacement_name: Windows Excessive Usage Of Net App + replacement_id: 355ba810-0a20-4215-8485-9ce3f87f2e38 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Elevated Group Discovery With Net + deprecated_id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a + replacement_name: Windows Sensitive Group Discovery With Net + replacement_id: d9eb7cda-5622-4722-bc88-7f2442f4b5af + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Local Account Discovery with Net + deprecated_id: 5d0d4830-0133-11ec-bae3-acde48001122 + replacement_name: Windows User Discovery Via Net + replacement_id: 7742987e-88c1-476b-a626-a869e088ab72 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Windows Command Shell Fetch Env Variables + deprecated_id: 048839e4-1eaa-43ff-8a22-86d17f6fcc13 + replacement_name: Windows List ENV Variables Via SET Command From Uncommon Parent + replacement_id: aec157f4-8783-4584-aca6-754c4dc7fba9 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Suspicious Email - UBA Anomaly + deprecated_id: 56e877a6-1455-4479-ad16-0550dc1e33f8 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Detect web traffic to dynamic domain providers + deprecated_id: 134da869-e264-4a8f-8d7e-fcd01c18f301 + replacement_name: Detect hosts connecting to dynamic domain providers + replacement_id: a1e761ac-1344-4dbd-88b2-3f34c912d359 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Updated to use a different log source +- deprecated_name: Okta Failed SSO Attempts + deprecated_id: 371a6545-2618-4032-ad84-93386b8698c5 + replacement_name: Okta Unauthorized Access to Application + replacement_id: 5f661629-9750-4cb9-897c-1f05d6db8727 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Kubernetes AWS detect RBAC authorization by account + deprecated_id: de7264ed-3ed9-4fef-bb01-6eefc87cefe8 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Kubernetes Azure detect service accounts forbidden failure access + deprecated_id: 019690d7-420f-4da0-b320-f27b09961514 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Remote Registry Key modifications + deprecated_id: c9f4b923-f8af-4155-b697-1354f5dcbc5e + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: O365 Suspicious User Email Forwarding + deprecated_id: f8dfe015-dbb3-4569-ba75-b13787e06aa4 + replacement_name: O365 Mailbox Email Forwarding Enabled + replacement_id: 0b6bc75c-05d1-4101-9fc3-97e706168f24 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Office Product Spawning MSHTA + deprecated_id: 6078fa20-a6d2-11eb-b662-acde48001122 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Kubernetes AWS detect most active service accounts by pod + deprecated_id: 5b30b25d-7d32-42d8-95ca-64dfcd9076e6 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Correlation by Repository and Risk + deprecated_id: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687 + replacement_name: Risk Rule for Dev Sec Ops by Repository + replacement_id: 161bc0ca-4651-4c13-9c27-27770660cf67 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the datamodel +- deprecated_name: Kubernetes Azure detect RBAC authorization by account + deprecated_id: 47af7d20-0607-4079-97d7-7a29af58b54e + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Clients Connecting to Multiple DNS Servers + deprecated_id: 74ec6f18-604b-4202-a567-86b2066be3ce + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Excessive Service Stop Attempt + deprecated_id: ae8d3f4a-acd7-11eb-8846-acde48001122 + replacement_name: Windows Excessive Service Stop Attempt + replacement_id: 8f3a614f-6b98-4f7d-82dd-d0df38452a8b + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Multiple Okta Users With Invalid Credentials From The Same IP + deprecated_id: 19cba45f-cad3-4032-8911-0c09e0444552 + replacement_name: Okta Multiple Users Failing To Authenticate From Ip + replacement_id: de365ffa-42f5-46b5-b43f-fa72290b8218 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Suspicious writes to System Volume Information + deprecated_id: cd6297cd-2bdd-4aa1-84aa-5d2f84228fac + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Detect new user AWS Console Login + deprecated_id: ada0f478-84a8-4641-a3f3-d82362dffd75 + replacement_name: Detect AWS Console Login by New User + replacement_id: bc91a8cd-35e7-4bb2-6140-e756cc46fd71 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Domain Account Discovery With Net App + deprecated_id: 98f6a534-04c2-11ec-96b2-acde48001122 + replacement_name: Windows User Discovery Via Net + replacement_id: 5d0d4830-0133-11ec-bae3-acde48001122 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: 'This analytic was a TTP that looked only for commands that tries to query + info about the users via net user /do. This had a couple of issues, such as triggering + on creation of users via the /add flag etc.. + + It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122' +- deprecated_name: Detection of DNS Tunnels + deprecated_id: 104658f4-afdc-499f-9719-17a43f9826f4 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Detect DNS requests to Phishing Sites leveraging EvilGinx2 + deprecated_id: 24dd17b1-e2fb-4c31-878c-d4f226595bfa + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Office Document Creating Schedule Task + deprecated_id: cc8b7b74-9d0f-11eb-8342-acde48001122 + replacement_name: Windows Office Product Loading Taskschd DLL + replacement_id: d7297cfa-1f04-4714-bfbe-3679e0666959 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Okta Account Locked Out + deprecated_id: d650c0ae-bdc5-400e-9f0f-f7aa0a010ef1 + replacement_name: Okta Multiple Accounts Locked Out + replacement_id: a511426e-184f-4de6-8711-cfd2af29d1e1 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Unsuccessful Netbackup backups + deprecated_id: a34aae96-ccf8-4aaa-952c-3ea21444444f + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Detect Mimikatz Via PowerShell And EventCode 4703 + deprecated_id: 98917be2-bfc8-475a-8618-a9bb06575188 + replacement_name: Detect Mimikatz With PowerShell Script Block Logging + replacement_id: 8148c29c-c952-11eb-9255-acde48001122 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Updated to a new detection name +- deprecated_name: Winword Spawning Cmd + deprecated_id: 6fcbaedc-a37b-11eb-956b-acde48001122 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: GCP Kubernetes cluster scan detection + deprecated_id: db5957ec-0144-4c56-b512-9dccbe7a2d26 + replacement_name: Kubernetes Scanning by Unauthenticated IP Address + replacement_id: f9cadf4e-df22-4f4e-a08f-9d3344c2165d + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Kubernetes GCP detect suspicious kubectl calls + deprecated_id: a5bed417-070a-41f2-a1e4-82b6aa281557 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: gcp detect oauth token abuse + deprecated_id: a7e9f7bb-8901-4ad0-8d88-0a4ab07b1972 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Correlation by User and Risk + deprecated_id: 610e12dc-b6fa-4541-825e-4a0b3b6f6773 + replacement_name: Risk Rule for Dev Sec Ops by Repository + replacement_id: 161bc0ca-4651-4c13-9c27-27770660cf67 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the datamodel +- deprecated_name: Processes created by netsh + deprecated_id: b89919ed-fe5f-492c-b139-95dbb162041e + replacement_name: Processes launching netsh + replacement_id: b89919ed-fe5f-492c-b139-95dbb162040e + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Updated to a new detection name +- deprecated_name: Office Product Spawning Wmic + deprecated_id: ffc236d6-a6c9-11eb-95f1-acde48001122 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Extraction of Registry Hives + deprecated_id: 8bbb7d58-b360-11eb-ba21-acde48001122 + replacement_name: Windows Sensitive Registry Hive Dump Via CommandLine + replacement_id: 5aaff29d-0cce-405b-9ee8-5d06b49d045e + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Attempt To Stop Security Service + deprecated_id: c8e349c6-b97c-486e-8949-bd7bcd1f3910 + replacement_name: Windows Attempt To Stop Security Service + replacement_id: 9ed27cea-4e27-4eff-b2c6-aac9e78a7517 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Windows MSIExec With Network Connections + deprecated_id: 827409a1-5393-4d8d-8da4-bbb297c262a7 + replacement_name: Windows HTTP Network Communication From MSIExec + replacement_id: b0fd38c7-f71a-43a2-870e-f3ca06bcdd99 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Windows Query Registry Reg Save + deprecated_id: cbee60c1-b776-456f-83c2-faa56bdbe6c6 + replacement_name: Windows Registry Entries Exported Via Reg + replacement_id: 466379bc-0f47-476c-8202-16ef38112e0d + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Cloud Network Access Control List Deleted + deprecated_id: 021abc51-1862-41dd-ad43-43c739c0a983 + replacement_name: AWS Network Access Control List Deleted + replacement_id: ada0f478-84a8-4641-a3f1-d82362d6fd75 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: O365 Suspicious Rights Delegation + deprecated_id: b25d2973-303e-47c8-bacd-52b61604c6a7 + replacement_name: O365 Elevated Mailbox Permission Assigned + replacement_id: 2246c142-a678-45f8-8546-aaed7e0efd30 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Abnormally High AWS Instances Launched by User - MLTK + deprecated_id: dec41ad5-d579-42cb-b4c6-f5dbb778bbe5 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Reg exe used to hide files directories via registry keys + deprecated_id: 61a7d1e6-f5d4-41d9-a9be-39a1ffe69459 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Detect Long DNS TXT Record Response + deprecated_id: 05437c07-62f5-452e-afdc-04dd44815bb9 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Password Policy Discovery with Net + deprecated_id: 09336538-065a-11ec-8665-acde48001122 + replacement_name: Windows Password Policy Discovery with Net + replacement_id: e52f7865-be78-46bf-b7ed-150fbe447613 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: AWS Cloud Provisioning From Previously Unseen IP Address + deprecated_id: 42e15012-ac14-4801-94f4-f1acbe64880b + replacement_name: Cloud Provisioning Activity From Previously Unseen IP Address + replacement_id: f86a8ec9-b042-45eb-92f4-e9ed1d781078 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Network Connection Discovery With Net + deprecated_id: 640337e5-6e41-4b7f-af06-9d9eab5e1e2d + replacement_name: Windows Network Connection Discovery Via Net + replacement_id: 86a5b949-679b-4197-8d4c-9c180a818c45 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Kubernetes Azure detect suspicious kubectl calls + deprecated_id: 4b6d1ba8-0000-4cec-87e6-6cbbd71651b5 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Kubernetes GCP detect sensitive role access + deprecated_id: a46923f6-36b9-4806-a681-31f314907c30 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Detect Webshell Exploit Behavior + deprecated_id: 22597426-6dbd-49bd-bcdc-4ec19857192f + replacement_name: Windows Suspicious Child Process Spawned From WebServer + replacement_id: 2d4470ef-7158-4b47-b68b-1f7f16382156 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: DNS record changed + deprecated_id: 44d3a43e-dcd5-49f7-8356-5209bb369065 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Unsigned Image Loaded by LSASS + deprecated_id: 56ef054c-76ef-45f9-af4a-a634695dcd65 + replacement_name: '' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Detect USB device insertion + deprecated_id: 104658f4-afdc-499f-9719-17a43f9826f5 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Windows Network Share Interaction With Net + deprecated_id: 4dc3951f-b3f8-4f46-b412-76a483f72277 + replacement_name: Windows Network Share Interaction Via Net + replacement_id: e51fbdb0-0be0-474f-92ea-d289f71a695e + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Account Discovery With Net App + deprecated_id: 339805ce-ac30-11eb-b87d-acde48001122 + replacement_name: Windows Excessive Usage Of Net App + replacement_id: 45e52536-ae42-11eb-b5c6-acde48001122 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: This analytic was a TTP that focused on unrelated things and called account + discovery. Since there were other detection that overlapped with it. I choose + to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 + / Windows Excessive Usage Of Net App. +- deprecated_name: Change Default File Association + deprecated_id: 462d17d8-1f71-11ec-ad07-acde48001122 + replacement_name: Windows New Default File Association Value Set + replacement_id: 7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Windows Lateral Tool Transfer RemCom + deprecated_id: e373a840-5bdc-47ef-b2fd-9cc7aaf387f0 + replacement_name: Windows Service Execution RemCom + replacement_id: 7e3d68db-ea4d-419b-adbd-e14a525ecf09 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Updated to a new detection name +- deprecated_name: Office Document Executing Macro Code + deprecated_id: b12c89bc-9d06-11eb-a592-acde48001122 + replacement_name: Windows Office Product Loading VBE7 DLL + replacement_id: 7cfec906-2697-43f7-898b-83634a051d9a + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Okta Account Lockout Events + deprecated_id: 62b70968-a0a5-4724-8ac4-67871e6f544d + replacement_name: Okta Multiple Accounts Locked Out + replacement_id: a511426e-184f-4de6-8711-cfd2af29d1e1 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Abnormally High AWS Instances Launched by User + deprecated_id: 2a9b80d3-6340-4345-b5ad-290bf5d0dac4 + replacement_name: Abnormally High Number Of Cloud Instances Launched + replacement_id: f2361e9f-3928-496c-a556-120cd4223a65 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: EC2 Instance Modified With Previously Unseen User + deprecated_id: 56f91724-cf3f-4666-84e1-e3712fb41e76 + replacement_name: Cloud API Calls From Previously Unseen User Roles + replacement_id: 2181ad1f-1e73-4d0c-9780-e8880482a08f + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Windows Valid Account With Never Expires Password + deprecated_id: 73a931db-1830-48b3-8296-cd9cfa09c3c8 + replacement_name: Windows Set Account Password Policy To Unlimited Via Net + replacement_id: 11f93009-8083-43fd-82a7-821fcbdc8342 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Windows hosts file modification + deprecated_id: 06a6fc63-a72d-41dc-8736-7e3dd9612116 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: MSHTML Module Load in Office Product + deprecated_id: 5f1c168e-118b-11ec-84ff-acde48001122 + replacement_name: Windows Office Product Loaded MSHTML Module + replacement_id: 4cc015c9-687c-40d2-adcc-46350f66e10c + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Abnormally High AWS Instances Terminated by User + deprecated_id: 8d301246-fccf-45e2-a8e7-3655fd14379c + replacement_name: Abnormally High Number Of Cloud Instances Destroyed + replacement_id: ef629fc9-1583-4590-b62a-f2247fbf7bbf + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Web Fraud - Account Harvesting + deprecated_id: bf1d7b5c-df2f-4249-a401-c09fdc221ddf + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Office Spawning Control + deprecated_id: 053e027c-10c7-11ec-8437-acde48001122 + replacement_name: Windows Office Product Spawned Control + replacement_id: 081c485d-ac8d-4bee-ad4c-525772fead4d + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Detect Activity Related to Pass the Hash Attacks + deprecated_id: f5939373-8054-40ad-8c64-cec478a22a4b + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Deleting Of Net Users + deprecated_id: 1c8c6f66-acce-11eb-aafb-acde48001122 + replacement_name: Windows User Deletion Via Net + replacement_id: b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Suspicious File Write + deprecated_id: 57f76b8a-32f0-42ed-b358-d9fa3ca7bac8 + replacement_name: '' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: AWS EKS Kubernetes cluster sensitive object access + deprecated_id: 7f227943-2196-4d4d-8d6a-ac8cb308e61c + replacement_name: Kubernetes Abuse of Secret by Unusual Location + replacement_id: 40a064c1-4ec1-4381-9e35-61192ba8ef82 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Spectre and Meltdown Vulnerable Systems + deprecated_id: 354be8e0-32cd-4da0-8c47-796de13b60ea + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: EC2 Instance Started With Previously Unseen User + deprecated_id: 22773e84-bac0-4595-b086-20d3f735b4f1 + replacement_name: Cloud Compute Instance Created By Previously Unseen User + replacement_id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Office Product Spawning CertUtil + deprecated_id: 6925fe72-a6d5-11eb-9e17-acde48001122 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Kubernetes GCP detect RBAC authorizations by account + deprecated_id: 99487de3-7192-4b41-939d-fbe9acfb1340 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Office Application Drop Executable + deprecated_id: 73ce70c4-146d-11ec-9184-acde48001122 + replacement_name: Windows Office Product Dropped Uncommon File + replacement_id: 7ac0fced-9eae-4381-a748-90dcd1aa9393 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Kubernetes Azure active service accounts by pod namespace + deprecated_id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Kubernetes Azure pod scan fingerprint + deprecated_id: 86aad3e0-732f-4f66-bbbc-70df448e461d + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Detect Spike in Network ACL Activity + deprecated_id: ada0f478-84a8-4641-a1f1-e32372d4bd53 + replacement_name: Abnormally High Number Of Cloud Infrastructure API Calls + replacement_id: 0840ddf1-8c89-46ff-b730-c8d6722478c0 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Suspicious Powershell Command-Line Arguments + deprecated_id: 2cdb91d2-542c-497f-b252-be495e71f38c + replacement_name: Malicious PowerShell Process - Encoded Command + replacement_id: c4db14d9-7909-48b4-a054-aa14d89dbb19 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Office Application Spawn Regsvr32 process + deprecated_id: 2d9fc90c-f11f-11eb-9300-acde48001122 + replacement_name: Windows Office Product Spawned Uncommon Process + replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Detect API activity from users without MFA + deprecated_id: 4d46e8bd-4072-48e4-92db-0325889ef894 + replacement_name: AWS Successful Single-Factor Authentication + replacement_id: a520b1fe-cc9e-4f56-b762-18354594c52f + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Kubernetes Azure detect sensitive object access + deprecated_id: 1bba382b-07fd-4ffa-b390-8002739b76e8 + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Web Fraud - Password Sharing Across Accounts + deprecated_id: 31337a1a-53b9-4e05-96e9-55c934cb71d3 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Disabling Net User Account + deprecated_id: c0325326-acd6-11eb-98c2-acde48001122 + replacement_name: Windows User Disabled Via Net + replacement_id: b0359e05-c87b-4354-83d8-aee0d890243f + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: GCP Detect accounts with high risk roles by project + deprecated_id: 27af8c15-38b0-4408-b339-920170724adb + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Kubernetes GCP detect service accounts forbidden failure access + deprecated_id: 7094808d-432a-48e7-bb3c-77e96c894f3b + replacement_name: '- ' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Extended Period Without Successful Netbackup Backups + deprecated_id: a34aae96-ccf8-4aef-952c-3ea214444440 + replacement_name: '-' + replacement_id: '' + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Office Product Spawning Rundll32 with no DLL + deprecated_id: c661f6be-a38c-11eb-be57-acde48001122 + replacement_name: Windows Office Product Spawned Rundll32 With No DLL + replacement_id: f28e787e-69ca-480e-9f98-ab970e6d4bcc + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Renamed and updated logic +- deprecated_name: Okta ThreatInsight Suspected PasswordSpray Attack + deprecated_id: 25dbad05-6682-4dd5-9ce9-8adecf0d9ae2 + replacement_name: Okta ThreatInsight Threat Detected + replacement_id: 140504ae-5fe2-4d65-b2bc-a211813fbca6 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update +- deprecated_name: Net Localgroup Discovery + deprecated_id: 54f5201e-155b-11ec-a6e2-acde48001122 + replacement_name: Windows Group Discovery Via Net + replacement_id: c5c8e0f3-147a-43da-bf04-4cfaec27dc44 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 + / Windows Group Discovery Via Net +- deprecated_name: Uncommon Processes On Endpoint + deprecated_id: 29ccce64-a10c-4389-a45f-337cb29ba1f7 + replacement_name: Attacker Tools On Endpoint + replacement_id: a51bfe1a-94f0-48cc-b4e4-16a110145893 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: '' +- deprecated_name: Dump LSASS via procdump Rename + deprecated_id: 21276daa-663d-11eb-ae93-0242ac130002 + replacement_name: Dump LSASS via procdump + replacement_id: 3742ebfe-64c2-11eb-ae93-0242ac130002 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Updated to a new detection name +- deprecated_name: Okta Two or More Rejected Okta Pushes + deprecated_id: d93f785e-4c2c-4262-b8c7-12b77a13fd39 + replacement_name: Okta Multiple Failed MFA Requests For User + replacement_id: 826dbaae-a1e6-4c8c-b384-d16898956e73 + date: '2025-01-28' + escu_version: 5.0.0 + migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics + reason: Detections updated to use the new search logic and field names due to the + TA update From f2247bc25127926c490a30ff66de97e2df265905 Mon Sep 17 00:00:00 2001 From: research-bot Date: Tue, 28 Jan 2025 10:42:27 -0800 Subject: [PATCH 05/67] adding a file --- .../deprecated_detection_mapping.yml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename deprecated_detection_mapping.yml => deprecated/deprecated_detection_mapping.yml (100%) diff --git a/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml similarity index 100% rename from deprecated_detection_mapping.yml rename to deprecated/deprecated_detection_mapping.yml From 0db344513f8c513f37e4079d243e1a2393da44e2 Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Fri, 31 Jan 2025 16:00:48 -0800 Subject: [PATCH 06/67] add deprecation info into the detections themselves --- ...ly_high_aws_instances_launched_by_user.yml | 8 ++++ ..._aws_instances_launched_by_user___mltk.yml | 6 +++ ..._high_aws_instances_terminated_by_user.yml | 8 ++++ ...ws_instances_terminated_by_user___mltk.yml | 6 +++ .../account_discovery_with_net_app.yml | 20 ++++++++- .../deprecated/asl_aws_createaccesskey.yml | 8 ++++ .../asl_aws_excessive_security_scanning.yml | 6 +++ .../asl_aws_password_policy_changes.yml | 6 +++ .../attempt_to_stop_security_service.yml | 26 ++++++----- ...dential_dump_from_registry_via_reg_exe.yml | 25 +++++++---- ...ovisioning_from_previously_unseen_city.yml | 12 ++++- ...sioning_from_previously_unseen_country.yml | 22 ++++++--- ...ning_from_previously_unseen_ip_address.yml | 8 ++++ ...isioning_from_previously_unseen_region.yml | 12 ++++- ...rnetes_cluster_sensitive_object_access.yml | 8 ++++ .../change_default_file_association.yml | 25 +++++++---- ...nts_connecting_to_multiple_dns_servers.yml | 6 +++ ...ud_network_access_control_list_deleted.yml | 8 ++++ ...cmdline_tool_not_executed_in_cmd_shell.yml | 7 +++ .../correlation_by_repository_and_risk.yml | 7 +++ .../correlation_by_user_and_risk.yml | 7 +++ ...ate_local_admin_accounts_using_net_exe.yml | 24 ++++++---- .../deprecated/deleting_of_net_users.yml | 23 ++++++---- ...ivity_related_to_pass_the_hash_attacks.yml | 6 +++ ...ct_api_activity_from_users_without_mfa.yml | 8 ++++ ...pi_activities_from_unapproved_accounts.yml | 6 +++ ...ct_critical_alerts_from_security_tools.yml | 45 +++++++++++++++++-- ...to_phishing_sites_leveraging_evilginx2.yml | 12 +++-- .../detect_long_dns_txt_record_response.yml | 6 +++ .../detect_mimikatz_using_loaded_images.yml | 6 +++ ...katz_via_powershell_and_eventcode_4703.yml | 7 +++ .../detect_new_api_calls_from_user_roles.yml | 14 ++++-- .../detect_new_user_aws_console_login.yml | 14 ++++-- ...system_network_configuration_discovery.yml | 26 ++++++----- .../detect_spike_in_aws_api_activity.yml | 7 +++ .../detect_spike_in_network_acl_activity.yml | 8 ++++ ...etect_spike_in_security_group_activity.yml | 8 ++++ .../detect_usb_device_insertion.yml | 6 +++ ...eb_traffic_to_dynamic_domain_providers.yml | 7 +++ .../detect_webshell_exploit_behavior.yml | 26 ++++++----- .../deprecated/detection_of_dns_tunnels.yml | 6 +++ .../deprecated/disabling_net_user_account.yml | 23 ++++++---- ...s_resolved_by_unauthorized_dns_servers.yml | 6 +++ detections/deprecated/dns_record_changed.yml | 6 +++ .../domain_account_discovery_with_net_app.yml | 20 ++++++++- .../domain_group_discovery_with_net.yml | 17 ++++++- .../dump_lsass_via_procdump_rename.yml | 7 +++ ...e_modified_with_previously_unseen_user.yml | 8 ++++ ...ce_started_in_previously_unseen_region.yml | 8 ++++ ...nce_started_with_previously_unseen_ami.yml | 8 ++++ ...d_with_previously_unseen_instance_type.yml | 8 ++++ ...ce_started_with_previously_unseen_user.yml | 8 ++++ .../elevated_group_discovery_with_net.yml | 24 ++++++---- .../deprecated/excel_spawning_powershell.yml | 26 +++++++---- .../excessive_service_stop_attempt.yml | 24 ++++++---- .../deprecated/excessive_usage_of_net_app.yml | 24 ++++++---- ...n_of_file_with_spaces_before_extension.yml | 7 +++ ...d_without_successful_netbackup_backups.yml | 6 +++ .../extraction_of_registry_hives.yml | 25 +++++++---- .../first_time_seen_command_line_argument.yml | 7 +++ ...counts_with_high_risk_roles_by_project.yml | 6 +++ ...sk_permissions_by_resource_and_account.yml | 6 +++ .../gcp_detect_oauth_token_abuse.yml | 6 +++ .../gcp_kubernetes_cluster_scan_detection.yml | 8 ++++ .../deprecated/identify_new_user_accounts.yml | 7 +++ ...ct_most_active_service_accounts_by_pod.yml | 7 +++ ...s_detect_rbac_authorization_by_account.yml | 7 +++ ...netes_aws_detect_sensitive_role_access.yml | 7 +++ ...vice_accounts_forbidden_failure_access.yml | 7 +++ ...tive_service_accounts_by_pod_namespace.yml | 7 +++ ...e_detect_rbac_authorization_by_account.yml | 7 +++ ...s_azure_detect_sensitive_object_access.yml | 7 +++ ...tes_azure_detect_sensitive_role_access.yml | 7 +++ ...vice_accounts_forbidden_failure_access.yml | 7 +++ ..._azure_detect_suspicious_kubectl_calls.yml | 7 +++ .../kubernetes_azure_pod_scan_fingerprint.yml | 7 +++ .../kubernetes_azure_scan_fingerprint.yml | 7 +++ ...ct_most_active_service_accounts_by_pod.yml | 7 +++ ..._detect_rbac_authorizations_by_account.yml | 7 +++ ...tes_gcp_detect_sensitive_object_access.yml | 7 +++ ...netes_gcp_detect_sensitive_role_access.yml | 7 +++ ...vice_accounts_forbidden_failure_access.yml | 7 +++ ...es_gcp_detect_suspicious_kubectl_calls.yml | 7 +++ .../linux_auditd_find_private_keys.yml | 24 ++++++---- .../local_account_discovery_with_net.yml | 24 ++++++---- .../monitor_dns_for_brand_abuse.yml | 7 +++ .../mshtml_module_load_in_office_product.yml | 23 ++++++---- ...h_invalid_credentials_from_the_same_ip.yml | 8 ++++ .../deprecated/net_localgroup_discovery.yml | 18 +++++++- .../network_connection_discovery_with_net.yml | 25 +++++++---- ...o365_suspicious_admin_email_forwarding.yml | 8 ++++ .../o365_suspicious_rights_delegation.yml | 8 ++++ .../o365_suspicious_user_email_forwarding.yml | 8 ++++ .../office_application_drop_executable.yml | 24 ++++++---- ...ice_application_spawn_regsvr32_process.yml | 26 +++++++---- ...ice_application_spawn_rundll32_process.yml | 24 ++++++---- ...office_document_creating_schedule_task.yml | 23 ++++++---- .../office_document_executing_macro_code.yml | 22 +++++---- ...ment_spawned_child_process_to_download.yml | 25 +++++++---- .../office_product_spawn_cmd_process.yml | 18 +++++++- .../office_product_spawning_bitsadmin.yml | 26 +++++++---- .../office_product_spawning_certutil.yml | 25 +++++++---- .../office_product_spawning_mshta.yml | 28 +++++++----- ..._product_spawning_rundll32_with_no_dll.yml | 24 ++++++---- ...e_product_spawning_windows_script_host.yml | 27 +++++++---- .../office_product_spawning_wmic.yml | 28 +++++++----- .../office_product_writing_cab_or_inf.yml | 23 ++++++---- .../deprecated/office_spawning_control.yml | 24 ++++++---- .../deprecated/okta_account_locked_out.yml | 8 ++++ .../okta_account_lockout_events.yml | 8 ++++ .../deprecated/okta_failed_sso_attempts.yml | 8 ++++ ..._login_failure_with_high_unknown_users.yml | 6 +++ ...insight_suspected_passwordspray_attack.yml | 8 ++++ .../okta_two_or_more_rejected_okta_pushes.yml | 8 ++++ .../osquery_pack___coldroot_detection.yml | 6 +++ .../password_policy_discovery_with_net.yml | 26 ++++++----- .../deprecated/processes_created_by_netsh.yml | 7 +++ .../prohibited_software_on_endpoint.yml | 7 +++ ...de_files_directories_via_registry_keys.yml | 7 +++ .../remote_registry_key_modifications.yml | 6 +++ .../remote_system_discovery_with_net.yml | 38 ++++++++++++++-- ...led_tasks_used_in_badrabbit_ransomware.yml | 7 +++ ...pectre_and_meltdown_vulnerable_systems.yml | 6 +++ ...uspicious_changes_to_file_associations.yml | 6 +++ .../suspicious_email___uba_anomaly.yml | 6 +++ .../deprecated/suspicious_file_write.yml | 7 +++ ...ious_powershell_command_line_arguments.yml | 7 +++ .../deprecated/suspicious_rundll32_rename.yml | 6 +++ ...us_writes_to_system_volume_information.yml | 6 +++ .../uncommon_processes_on_endpoint.yml | 7 +++ .../unsigned_image_loaded_by_lsass.yml | 7 +++ .../unsuccessful_netbackup_backups.yml | 6 +++ .../web_fraud___account_harvesting.yml | 6 +++ .../web_fraud___anomalous_user_clickspeed.yml | 6 +++ ...aud___password_sharing_across_accounts.yml | 6 +++ ...dows_command_shell_fetch_env_variables.yml | 24 ++++++---- ...indows_connhost_exe_started_forcefully.yml | 6 +++ ...indows_dll_search_order_hijacking_hunt.yml | 8 ++++ .../windows_hosts_file_modification.yml | 6 +++ .../windows_lateral_tool_transfer_remcom.yml | 7 +++ .../windows_modify_registry_reg_restore.yml | 25 +++++++---- ...ndows_msiexec_with_network_connections.yml | 24 ++++++---- ...ows_network_share_interaction_with_net.yml | 21 ++++++--- .../windows_office_product_spawning_msdt.yml | 27 ++++++----- .../windows_query_registry_reg_save.yml | 23 ++++++---- ...id_account_with_never_expires_password.yml | 24 ++++++---- .../deprecated/winword_spawning_cmd.yml | 29 +++++++----- .../winword_spawning_powershell.yml | 29 +++++++----- .../winword_spawning_windows_script_host.yml | 17 +++++-- 149 files changed, 1545 insertions(+), 404 deletions(-) diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml index e46dec6369..a84ac20e7c 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml @@ -4,6 +4,14 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Instances Launched type: Anomaly description: This search looks for AWS CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml index 9acc4411b2..8279df5c30 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml @@ -4,6 +4,12 @@ version: 5 date: '2024-11-14' author: Jason Brewer, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Anomaly description: This search looks for AWS CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml index ae3c15024b..f028df1a26 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml @@ -4,6 +4,14 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Instances Destroyed type: Anomaly description: This search looks for AWS CloudTrail events where an abnormally high number of instances were successfully terminated by a user in a 10-minute window. diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml index 04f88a704a..adcfe17ca3 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml @@ -4,6 +4,12 @@ version: 5 date: '2024-11-14' author: Jason Brewer, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Anomaly description: This search looks for AWS CloudTrail events where a user successfully terminates an abnormally high number of instances. This search is deprecated and diff --git a/detections/deprecated/account_discovery_with_net_app.yml b/detections/deprecated/account_discovery_with_net_app.yml index ce8d2fa45f..323489ac89 100644 --- a/detections/deprecated/account_discovery_with_net_app.yml +++ b/detections/deprecated/account_discovery_with_net_app.yml @@ -4,8 +4,26 @@ version: 8 date: '2025-01-13' author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: This analytic was a TTP that focused on unrelated things and called account + discovery. Since there were other detection that overlapped with it. I choose + to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 + / Windows Excessive Usage Of Net App. + replacement_content: + - Windows Excessive Usage Of Net App type: TTP -description: The following analytic has been deprecated in favour of the more generic "45e52536-ae42-11eb-b5c6-acde48001122". The following analytic detects potential account discovery activities using the 'net' command, commonly employed by malware like Trickbot for reconnaissance. It leverages Endpoint Detection and Response (EDR) data, focusing on specific command-line patterns and process relationships. This activity is significant as it often precedes further malicious actions, such as lateral movement or privilege escalation. If confirmed malicious, attackers could gain valuable information about user accounts, enabling them to escalate privileges or move laterally within the network, posing a significant security risk. +description: The following analytic has been deprecated in favour of the more generic + "45e52536-ae42-11eb-b5c6-acde48001122". The following analytic detects potential + account discovery activities using the 'net' command, commonly employed by malware + like Trickbot for reconnaissance. It leverages Endpoint Detection and Response (EDR) + data, focusing on specific command-line patterns and process relationships. This + activity is significant as it often precedes further malicious actions, such as + lateral movement or privilege escalation. If confirmed malicious, attackers could + gain valuable information about user accounts, enabling them to escalate privileges + or move laterally within the network, posing a significant security risk. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/asl_aws_createaccesskey.yml b/detections/deprecated/asl_aws_createaccesskey.yml index e7588388f6..33967e66c7 100644 --- a/detections/deprecated/asl_aws_createaccesskey.yml +++ b/detections/deprecated/asl_aws_createaccesskey.yml @@ -4,6 +4,14 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - ASL AWS Create Access Key type: Hunting description: This detection rule monitors for the creation of AWS Identity and Access Management (IAM) access keys. An IAM access key consists of an access key ID and diff --git a/detections/deprecated/asl_aws_excessive_security_scanning.yml b/detections/deprecated/asl_aws_excessive_security_scanning.yml index 0ee3a463e3..483db858df 100644 --- a/detections/deprecated/asl_aws_excessive_security_scanning.yml +++ b/detections/deprecated/asl_aws_excessive_security_scanning.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Anomaly description: This search looks for AWS CloudTrail events and analyse the amount of eventNames which starts with Describe by a single user. This indicates that this diff --git a/detections/deprecated/asl_aws_password_policy_changes.yml b/detections/deprecated/asl_aws_password_policy_changes.yml index d791f17208..6ee31b185c 100644 --- a/detections/deprecated/asl_aws_password_policy_changes.yml +++ b/detections/deprecated/asl_aws_password_policy_changes.yml @@ -4,6 +4,12 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Hunting description: This search looks for AWS CloudTrail events from Amazon Security Lake where a user is making successful API calls to view/update/delete the existing password diff --git a/detections/deprecated/attempt_to_stop_security_service.yml b/detections/deprecated/attempt_to_stop_security_service.yml index 6527800094..864f401149 100644 --- a/detections/deprecated/attempt_to_stop_security_service.yml +++ b/detections/deprecated/attempt_to_stop_security_service.yml @@ -4,17 +4,23 @@ version: 9 date: '2025-01-24' author: Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Attempt To Stop Security Service type: TTP -description: The following analytic has been deprecated. - The following analytic detects attempts to stop security-related services - on an endpoint, which may indicate malicious activity. It leverages data from Endpoint - Detection and Response (EDR) agents, specifically searching for processes involving - the "sc.exe" command with the "stop" parameter. This activity is significant because - disabling security services can undermine the organization's security posture, potentially - leading to unauthorized access, data exfiltration, or further attacks like malware - installation or privilege escalation. If confirmed malicious, this behavior could - compromise the endpoint and the entire network, necessitating immediate investigation - and response. +description: The following analytic has been deprecated. The following analytic detects + attempts to stop security-related services on an endpoint, which may indicate malicious + activity. It leverages data from Endpoint Detection and Response (EDR) agents, specifically + searching for processes involving the "sc.exe" command with the "stop" parameter. + This activity is significant because disabling security services can undermine the + organization's security posture, potentially leading to unauthorized access, data + exfiltration, or further attacks like malware installation or privilege escalation. + If confirmed malicious, this behavior could compromise the endpoint and the entire + network, necessitating immediate investigation and response. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml index 409c21747b..60166bd1f3 100644 --- a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -4,16 +4,25 @@ version: 12 date: '2025-01-15' author: Patrick Bareiss, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: This analytic had some overlap with another one, hence the deprecation. + It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry + Hive Dump Via CommandLine + replacement_content: + - Windows Sensitive Registry Hive Dump Via CommandLine type: TTP description: The following analytic has been deprecated in favour of "8bbb7d58-b360-11eb-ba21-acde48001122". - The following analytic detects the execution of reg.exe with parameters - that export registry keys containing hashed credentials. It leverages data from - Endpoint Detection and Response (EDR) agents, focusing on command-line executions - involving reg.exe or cmd.exe with specific registry paths. This activity is significant - because exporting these keys can allow attackers to obtain hashed credentials, which - they may attempt to crack offline. If confirmed malicious, this could lead to unauthorized - access to sensitive accounts, enabling further compromise and lateral movement within - the network. + The following analytic detects the execution of reg.exe with parameters that export + registry keys containing hashed credentials. It leverages data from Endpoint Detection + and Response (EDR) agents, focusing on command-line executions involving reg.exe + or cmd.exe with specific registry paths. This activity is significant because exporting + these keys can allow attackers to obtain hashed credentials, which they may attempt + to crack offline. If confirmed malicious, this could lead to unauthorized access + to sensitive accounts, enabling further compromise and lateral movement within the + network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml index 91a576d2f0..6b328e1c99 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml @@ -4,6 +4,14 @@ version: 5 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen City type: Anomaly description: This search looks for AWS provisioning activities from previously unseen cities. Provisioning activities are defined broadly as any event that begins with @@ -15,8 +23,8 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI sourceIPAddress | search City=* | stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup append=t previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, - City, Region, Country | outputlookup previously_seen_provisioning_activity_src - | stats min(firstTime) as firstTime max(lastTime) as lastTime by City | eval newCity=if(firstTime + City, Region, Country | outputlookup previously_seen_provisioning_activity_src | + stats min(firstTime) as firstTime max(lastTime) as lastTime by City | eval newCity=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) | where newCity=1 | table City] | spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, City, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_city_filter`' diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml index 986a31d1f0..9fa34711fb 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml @@ -4,6 +4,14 @@ version: 5 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen Country type: Anomaly description: This search looks for AWS provisioning activities from previously unseen countries. Provisioning activities are defined broadly as any event that begins @@ -14,13 +22,13 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI | search Country=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceIPAddress | search Country=* | stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup - append=t previously_seen_provisioning_activity_src | stats min(firstTime) as - firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country | - outputlookup previously_seen_provisioning_activity_src | stats min(firstTime) - as firstTime max(lastTime) as lastTime by Country | eval newCountry=if(firstTime - >= relative_time(now(), "-70m@m"), 1, 0) | where newCountry=1 | table Country] | - spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, - user, src_ip, Country, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter`' + append=t previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime + max(lastTime) as lastTime by sourceIPAddress, City, Region, Country | outputlookup + previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime max(lastTime) + as lastTime by Country | eval newCountry=if(firstTime >= relative_time(now(), "-70m@m"), + 1, 0) | where newCountry=1 | table Country] | spath output=user userIdentity.arn + | rename sourceIPAddress as src_ip | table _time, user, src_ip, Country, eventName, + errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter`' how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously Seen AWS Provisioning diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml index 5568175da0..d90ad488c4 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml @@ -4,6 +4,14 @@ version: 5 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen IP Address type: Anomaly description: This search looks for AWS provisioning activities from previously unseen IP addresses. Provisioning activities are defined broadly as any event that begins diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml index 5efa68a449..b3748cf690 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen Region type: Anomaly description: This search looks for AWS provisioning activities from previously unseen regions. Region in this context is similar to a state in the United States. Provisioning @@ -15,8 +23,8 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI sourceIPAddress | search Region=* | stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup append=t previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, - City, Region, Country | outputlookup previously_seen_provisioning_activity_src - | stats min(firstTime) as firstTime max(lastTime) as lastTime by Region | eval newRegion=if(firstTime + City, Region, Country | outputlookup previously_seen_provisioning_activity_src | + stats min(firstTime) as firstTime max(lastTime) as lastTime by Region | eval newRegion=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) | where newRegion=1 | table Region] | spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, Region, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_region_filter`' diff --git a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml index 866bca7809..016a68160e 100644 --- a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml +++ b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Kubernetes Abuse of Secret by Unusual Location type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets diff --git a/detections/deprecated/change_default_file_association.yml b/detections/deprecated/change_default_file_association.yml index d552a13219..e3de336511 100644 --- a/detections/deprecated/change_default_file_association.yml +++ b/detections/deprecated/change_default_file_association.yml @@ -4,16 +4,23 @@ version: 5 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows New Default File Association Value Set type: TTP -description: The following analytic has been deprecated. - The following analytic detects suspicious registry modifications that - change the default file association to execute a malicious payload. It leverages - data from the Endpoint data model, specifically monitoring registry paths under - "*\\shell\\open\\command\\*" and "*HKCR\\*". This activity is significant because - altering default file associations can allow attackers to execute arbitrary scripts - or payloads when a user opens a file, leading to potential code execution. If confirmed - malicious, this technique can enable attackers to persist on the compromised host - and execute further malicious commands, posing a severe threat to the environment. +description: The following analytic has been deprecated. The following analytic detects + suspicious registry modifications that change the default file association to execute + a malicious payload. It leverages data from the Endpoint data model, specifically + monitoring registry paths under "*\\shell\\open\\command\\*" and "*HKCR\\*". This + activity is significant because altering default file associations can allow attackers + to execute arbitrary scripts or payloads when a user opens a file, leading to potential + code execution. If confirmed malicious, this technique can enable attackers to persist + on the compromised host and execute further malicious commands, posing a severe + threat to the environment. data_source: - Sysmon EventID 12 - Sysmon EventID 13 diff --git a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml index eb01c32ea2..7ea5a6c524 100644 --- a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml +++ b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml @@ -4,6 +4,12 @@ version: 6 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: This search allows you to identify the endpoints that have connected to more than five DNS servers and made DNS Queries over the time frame of the search. diff --git a/detections/deprecated/cloud_network_access_control_list_deleted.yml b/detections/deprecated/cloud_network_access_control_list_deleted.yml index 8a9036b76a..c5a273eb95 100644 --- a/detections/deprecated/cloud_network_access_control_list_deleted.yml +++ b/detections/deprecated/cloud_network_access_control_list_deleted.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Peter Gael, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - AWS Network Access Control List Deleted type: Anomaly description: Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker diff --git a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml index 1df440f488..98e8084d64 100644 --- a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml @@ -4,6 +4,13 @@ version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Cmdline Tool Execution From Non-Shell Process type: TTP description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`, or similar tools are executed by a non-standard parent process, excluding CMD, PowerShell, diff --git a/detections/deprecated/correlation_by_repository_and_risk.yml b/detections/deprecated/correlation_by_repository_and_risk.yml index 2629b408ff..afc868dcee 100644 --- a/detections/deprecated/correlation_by_repository_and_risk.yml +++ b/detections/deprecated/correlation_by_repository_and_risk.yml @@ -4,6 +4,13 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the datamodel + replacement_content: + - Risk Rule for Dev Sec Ops by Repository type: Correlation description: |- This search has been deprecated and updated with Risk Rule for Dev Sec Ops by Repository detection. The following analytic detects by correlating repository and risk score to identify patterns and trends in the data based on the level of risk associated. The analytic adds any null values and calculates the sum of the risk scores for each detection. Then, the analytic captures the source and user information for each detection and sorts the results in ascending order based on the risk score. Finally, the analytic filters the detections with a risk score below 80 and focuses only on high-risk detections.This detection is important because it provides valuable insights into the distribution of high-risk activities across different repositories. It also identifies the most vulnerable repositories that are frequently targeted by potential threats. Additionally, it proactively detects and responds to potential threats, thereby minimizing the impact of attacks and safeguarding critical assets. Finally, it provides a comprehensive view of the risk landscape and helps to make informed decisions to protect the organization's data and infrastructure. False positives might occur so it is important to identify the impact of the attack and prioritize response and mitigation efforts. diff --git a/detections/deprecated/correlation_by_user_and_risk.yml b/detections/deprecated/correlation_by_user_and_risk.yml index 63d9c738ae..0d95f474ec 100644 --- a/detections/deprecated/correlation_by_user_and_risk.yml +++ b/detections/deprecated/correlation_by_user_and_risk.yml @@ -4,6 +4,13 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the datamodel + replacement_content: + - Risk Rule for Dev Sec Ops by Repository type: Correlation description: |- The following analytic detects the correlation between the user and risk score and identifies users with a high risk score that pose a significant security risk such as unauthorized access attempts, suspicious behavior, or potential insider threats. Next, the analytic calculates the sum of the risk scores and groups the results by user, the corresponding signals, and the repository. The results are sorted in descending order based on the risk score and filtered to include records with a risk score greater than 80. Finally, the results are passed through a correlation filter specific to the user and risk. This detection is important because it identifies users who have a high risk score and helps to prioritize investigations and allocate resources. False positives might occur but the impact of such an attack can vary depending on the specific scenario such as data exfiltration, system compromise, or the disruption of critical services. Please investigate this notable event. diff --git a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml index 08cc384790..b4553ed94f 100644 --- a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml +++ b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml @@ -4,16 +4,22 @@ version: 15 date: '2025-01-24' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Create Local Administrator Account Via Net type: TTP -description: The following analytic has been deprecated. - The following analytic detects the creation of local administrator accounts - using the net.exe command. It leverages Endpoint Detection and Response (EDR) data - to identify processes named net.exe or net1.exe with the "/add" parameter and keywords - related to administrator accounts. This activity is significant as it may indicate - an attacker attempting to gain persistent access or escalate privileges. If confirmed - malicious, this could lead to unauthorized access, data theft, or further system - compromise. Review the process details, user context, and related artifacts to determine - the legitimacy of the activity. +description: The following analytic has been deprecated. The following analytic detects + the creation of local administrator accounts using the net.exe command. It leverages + Endpoint Detection and Response (EDR) data to identify processes named net.exe or + net1.exe with the "/add" parameter and keywords related to administrator accounts. + This activity is significant as it may indicate an attacker attempting to gain persistent + access or escalate privileges. If confirmed malicious, this could lead to unauthorized + access, data theft, or further system compromise. Review the process details, user + context, and related artifacts to determine the legitimacy of the activity. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/deleting_of_net_users.yml b/detections/deprecated/deleting_of_net_users.yml index 53d81b2248..7d5ea4007a 100644 --- a/detections/deprecated/deleting_of_net_users.yml +++ b/detections/deprecated/deleting_of_net_users.yml @@ -4,15 +4,22 @@ version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows User Deletion Via Net type: TTP -description: The following analytic has been deprecated. - The following analytic detects the use of net.exe or net1.exe command-line - to delete a user account on a system. It leverages data from Endpoint Detection - and Response (EDR) agents, focusing on process and command-line execution logs. - This activity is significant as it may indicate an attempt to impair user accounts - or cover tracks during lateral movement. If confirmed malicious, this could lead - to unauthorized access removal, disruption of legitimate user activities, or concealment - of adversarial actions, complicating incident response and forensic investigations. +description: The following analytic has been deprecated. The following analytic detects + the use of net.exe or net1.exe command-line to delete a user account on a system. + It leverages data from Endpoint Detection and Response (EDR) agents, focusing on + process and command-line execution logs. This activity is significant as it may + indicate an attempt to impair user accounts or cover tracks during lateral movement. + If confirmed malicious, this could lead to unauthorized access removal, disruption + of legitimate user activities, or concealment of adversarial actions, complicating + incident response and forensic investigations. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml index 0c13a55b87..92df160e8f 100644 --- a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml @@ -4,6 +4,12 @@ version: 9 date: '2024-11-14' author: Bhavin Patel, Patrick Bareiss, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Hunting description: This search looks for specific authentication events from the Windows Security Event logs to detect potential attempts at using the Pass-the-Hash technique. diff --git a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml index e0ad2efcfc..82e5931e6a 100644 --- a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml +++ b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - AWS Successful Single-Factor Authentication type: Hunting description: This search looks for AWS CloudTrail events where a user logged into the AWS account, is making API calls and has not enabled Multi Factor authentication. diff --git a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml index 23e833aac1..b97773f126 100644 --- a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml +++ b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml @@ -4,6 +4,12 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Hunting description: This search looks for successful AWS CloudTrail activity by user accounts that are not listed in the identity table or `aws_service_accounts.csv`. It returns diff --git a/detections/deprecated/detect_critical_alerts_from_security_tools.yml b/detections/deprecated/detect_critical_alerts_from_security_tools.yml index 79ba56809d..a956ec746a 100644 --- a/detections/deprecated/detect_critical_alerts_from_security_tools.yml +++ b/detections/deprecated/detect_critical_alerts_from_security_tools.yml @@ -4,14 +4,51 @@ version: 2 date: '2025-01-13' author: Gowthamaraj Rajendran, Patrick Bareiss, Bhavin Patel, Bryan Pluta, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Microsoft Defender Incident Alerts type: TTP data_source: - Windows Defender Alerts - MS365 Defender Incident Alerts -description: The following analytic has been deprecated in favour of specific and dedicated product analytics such as "Microsoft Defender ATP Alerts". The following analytic is to detect high and critical alerts from endpoint security tools such as Microsoft Defender, Carbon Black, and Crowdstrike. This query aggregates and summarizes critical severity alerts from the Alerts data model, providing details such as the alert signature, application, description, source, destination, and timestamps, while applying custom filters and formatting for enhanced analysis in a SIEM environment.This capability allows security teams to efficiently allocate resources and maintain a strong security posture, while also supporting compliance with regulatory requirements by providing a clear record of critical security events. We tested these detections with logs from Microsoft Defender, however this detection should work for any security alerts that are ingested into the alerts data model. **Note** - We are dynamically creating the risk_score field based on the severity of the alert in the SPL and that supersedes the risk score set in the detection. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Alerts.description) as description values(Alerts.mitre_technique_id) as annotations.mitre_attack.mitre_technique_id values(Alerts.severity) as severity values(Alerts.type) as type values(Alerts.severity_id) as severity_id values(Alerts.signature) as signature values(Alerts.signature_id) as signature_id values(Alerts.dest) as dest from datamodel=Alerts where Alerts.severity IN ("high","critical") by Alerts.src Alerts.user Alerts.id Alerts.vendor sourcetype | `drop_dm_object_name("Alerts")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | eval risk_score=case(severity="informational", 2, severity="low", 5, severity="medium", 10, severity="high", 50, severity="critical" , 100) | `detect_critical_alerts_from_security_tools_filter`' -how_to_implement: In order to properly run this search, you to ingest alerts data from other security products such as Crowdstrike, Microsoft Defender, or Carbon Black using appropriate TAs for that technology. Once ingested, the fields should be mapped to the Alerts data model. Make sure to apply transformation on the data if necessary. The risk_score field is used to calculate the risk score for the alerts and the mitre_technique_id field is used to map the alerts to the MITRE ATT&CK framework is dynamically created by the detection when this is triggered. These fields need not be set in the adaptive response actions. -known_false_positives: False positives may vary by endpoint protection tool; monitor and filter out the alerts that are not relevant to your environment. +description: The following analytic has been deprecated in favour of specific and + dedicated product analytics such as "Microsoft Defender ATP Alerts". The following + analytic is to detect high and critical alerts from endpoint security tools such + as Microsoft Defender, Carbon Black, and Crowdstrike. This query aggregates and + summarizes critical severity alerts from the Alerts data model, providing details + such as the alert signature, application, description, source, destination, and + timestamps, while applying custom filters and formatting for enhanced analysis in + a SIEM environment.This capability allows security teams to efficiently allocate + resources and maintain a strong security posture, while also supporting compliance + with regulatory requirements by providing a clear record of critical security events. + We tested these detections with logs from Microsoft Defender, however this detection + should work for any security alerts that are ingested into the alerts data model. + **Note** - We are dynamically creating the risk_score field based on the severity + of the alert in the SPL and that supersedes the risk score set in the detection. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime values(Alerts.description) as description values(Alerts.mitre_technique_id) + as annotations.mitre_attack.mitre_technique_id values(Alerts.severity) as severity + values(Alerts.type) as type values(Alerts.severity_id) as severity_id values(Alerts.signature) + as signature values(Alerts.signature_id) as signature_id values(Alerts.dest) as + dest from datamodel=Alerts where Alerts.severity IN ("high","critical") by Alerts.src + Alerts.user Alerts.id Alerts.vendor sourcetype | `drop_dm_object_name("Alerts")` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | eval + risk_score=case(severity="informational", 2, severity="low", 5, severity="medium", + 10, severity="high", 50, severity="critical" , 100) | `detect_critical_alerts_from_security_tools_filter`' +how_to_implement: In order to properly run this search, you to ingest alerts data + from other security products such as Crowdstrike, Microsoft Defender, or Carbon + Black using appropriate TAs for that technology. Once ingested, the fields should + be mapped to the Alerts data model. Make sure to apply transformation on the data + if necessary. The risk_score field is used to calculate the risk score for the alerts + and the mitre_technique_id field is used to map the alerts to the MITRE ATT&CK framework + is dynamically created by the detection when this is triggered. These fields need + not be set in the adaptive response actions. +known_false_positives: False positives may vary by endpoint protection tool; monitor + and filter out the alerts that are not relevant to your environment. references: - https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/accessing-microsoft-defender-for-cloud-alerts-in-splunk-using/ba-p/938228 - https://docs.splunk.com/Documentation/CIM/5.3.2/User/Alerts diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml index 2d4975f3ec..b76c9405f5 100644 --- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml +++ b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml @@ -4,6 +4,12 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: This search looks for DNS requests for phishing domains that are leveraging EvilGinx tools to mimic websites. @@ -31,9 +37,9 @@ how_to_implement: "You need to ingest data from your DNS logs in the Network_Res add the correct hostname to the \"Phantom Instance\" field in the Adaptive Response Actions when configuring this detection search, and set the corresponding Playbook to active.\n(Playbook link:`https://my.phantom.us/4.2/playbook/lets-encrypt-domain-investigate/`)" -known_false_positives: If a known good domain is not listed in the `legit_domains` lookup, - then the search could give you false postives. Please update that lookup file - to filter out DNS requests to legitimate domains. +known_false_positives: If a known good domain is not listed in the `legit_domains` + lookup, then the search could give you false postives. Please update that lookup + file to filter out DNS requests to legitimate domains. references: [] rba: message: DNS Request for EvilGinx2 Phishing Site diff --git a/detections/deprecated/detect_long_dns_txt_record_response.yml b/detections/deprecated/detect_long_dns_txt_record_response.yml index 57a2fb80be..98b0f46fdc 100644 --- a/detections/deprecated/detect_long_dns_txt_record_response.yml +++ b/detections/deprecated/detect_long_dns_txt_record_response.yml @@ -4,6 +4,12 @@ version: 5 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: This search is used to detect attempts to use DNS tunneling, by calculating the length of responses to DNS TXT queries. Endpoints using DNS as a method of transmission diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/detections/deprecated/detect_mimikatz_using_loaded_images.yml index b002ff2bcc..2b96f938f5 100644 --- a/detections/deprecated/detect_mimikatz_using_loaded_images.yml +++ b/detections/deprecated/detect_mimikatz_using_loaded_images.yml @@ -4,6 +4,12 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: This search looks for reading loaded Images unique to credential dumping with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon diff --git a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml index aa9cabe8d3..4f622e2ba5 100644 --- a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml +++ b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml @@ -4,6 +4,13 @@ version: 5 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Updated to a new detection name + replacement_content: + - Detect Mimikatz With PowerShell Script Block Logging type: TTP description: This search looks for PowerShell requesting privileges consistent with credential dumping. Deprecated, looks like things changed from a logging perspective. diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/detections/deprecated/detect_new_api_calls_from_user_roles.yml index 5ed0943c52..a0a40a7079 100644 --- a/detections/deprecated/detect_new_api_calls_from_user_roles.yml +++ b/detections/deprecated/detect_new_api_calls_from_user_roles.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud API Calls From Previously Unseen User Roles type: Anomaly description: This search detects new API calls that have either never been seen before or that have not been seen in the previous hour, where the identity type is `AssumedRole`. @@ -12,9 +20,9 @@ search: '`cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=A [search `cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole | stats earliest(_time) as earliest latest(_time) as latest by userName eventName | inputlookup append=t previously_seen_api_calls_from_user_roles | stats min(earliest) - as earliest, max(latest) as latest by userName eventName | outputlookup previously_seen_api_calls_from_user_roles | - eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0) | - where newApiCallfromUserRole=1 | `security_content_ctime(earliest)` | `security_content_ctime(latest)` + as earliest, max(latest) as latest by userName eventName | outputlookup previously_seen_api_calls_from_user_roles + | eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0) + | where newApiCallfromUserRole=1 | `security_content_ctime(earliest)` | `security_content_ctime(latest)` | table eventName userName] |rename userName as user| stats values(eventName) earliest(_time) as earliest latest(_time) as latest by user | `security_content_ctime(earliest)` | `security_content_ctime(latest)` | `detect_new_api_calls_from_user_roles_filter`' diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/detections/deprecated/detect_new_user_aws_console_login.yml index 1713d3b52d..3b7dee01f6 100644 --- a/detections/deprecated/detect_new_user_aws_console_login.yml +++ b/detections/deprecated/detect_new_user_aws_console_login.yml @@ -4,6 +4,14 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Detect AWS Console Login by New User type: Hunting description: This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup @@ -13,9 +21,9 @@ description: This search looks for AWS CloudTrail events wherein a console login data_source: [] search: '`cloudtrail` eventName=ConsoleLogin | rename userIdentity.arn as user | stats earliest(_time) as firstTime latest(_time) as lastTime by user | inputlookup append=t - previously_seen_users_console_logins | stats min(firstTime) as firstTime - max(lastTime) as lastTime by user | eval userStatus=if(firstTime >= relative_time(now(), - "-70m@m"), "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`| + previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime) + as lastTime by user | eval userStatus=if(firstTime >= relative_time(now(), "-70m@m"), + "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`| where userStatus ="First Time Logging into AWS Console" | `detect_new_user_aws_console_login_filter`' how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail diff --git a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml index 077d4c8017..3abe50aa9b 100644 --- a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml +++ b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml @@ -4,17 +4,23 @@ version: 7 date: '2025-01-24' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Potential System Network Configuration Discovery Activity type: TTP -description: The following analytic has been deprecated. - The following analytic identifies the rapid execution of processes used - for system network configuration discovery on an endpoint. It leverages data from - Endpoint Detection and Response (EDR) agents, focusing on process GUIDs, names, - parent processes, and command-line executions. This activity is significant as it - may indicate an attacker attempting to map the network, which is a common precursor - to lateral movement or further exploitation. If confirmed malicious, this behavior - could allow an attacker to gain insights into the network topology, identify critical - systems, and plan subsequent attacks, potentially leading to data exfiltration or - system compromise. +description: The following analytic has been deprecated. The following analytic identifies + the rapid execution of processes used for system network configuration discovery + on an endpoint. It leverages data from Endpoint Detection and Response (EDR) agents, + focusing on process GUIDs, names, parent processes, and command-line executions. + This activity is significant as it may indicate an attacker attempting to map the + network, which is a common precursor to lateral movement or further exploitation. + If confirmed malicious, this behavior could allow an attacker to gain insights into + the network topology, identify critical systems, and plan subsequent attacks, potentially + leading to data exfiltration or system compromise. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/detect_spike_in_aws_api_activity.yml b/detections/deprecated/detect_spike_in_aws_api_activity.yml index 5a7efe7007..7757834caf 100644 --- a/detections/deprecated/detect_spike_in_aws_api_activity.yml +++ b/detections/deprecated/detect_spike_in_aws_api_activity.yml @@ -4,6 +4,13 @@ version: 5 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '' type: Anomaly description: This search will detect users creating spikes of API activity in your AWS environment. It will also update the cache file that factors in the latest diff --git a/detections/deprecated/detect_spike_in_network_acl_activity.yml b/detections/deprecated/detect_spike_in_network_acl_activity.yml index a7e693bf9e..b35582dc49 100644 --- a/detections/deprecated/detect_spike_in_network_acl_activity.yml +++ b/detections/deprecated/detect_spike_in_network_acl_activity.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Infrastructure API Calls type: Anomaly description: This search will detect users creating spikes in API activity related to network access-control lists (ACLs)in your AWS environment. This search is deprecated diff --git a/detections/deprecated/detect_spike_in_security_group_activity.yml b/detections/deprecated/detect_spike_in_security_group_activity.yml index de1cad3b6d..a8e0579682 100644 --- a/detections/deprecated/detect_spike_in_security_group_activity.yml +++ b/detections/deprecated/detect_spike_in_security_group_activity.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Security Group API Calls type: Anomaly description: This search will detect users creating spikes in API activity related to security groups in your AWS environment. It will also update the cache file diff --git a/detections/deprecated/detect_usb_device_insertion.yml b/detections/deprecated/detect_usb_device_insertion.yml index 2d6dd088f5..c363556e53 100644 --- a/detections/deprecated/detect_usb_device_insertion.yml +++ b/detections/deprecated/detect_usb_device_insertion.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: The search is used to detect hosts that generate Windows Event ID 4663 for successful attempts to write to or read from a removable storage and Event ID diff --git a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml index 853d302d85..885920c786 100644 --- a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml +++ b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml @@ -4,6 +4,13 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Updated to use a different log source + replacement_content: + - Detect hosts connecting to dynamic domain providers type: TTP description: This search looks for web connections to dynamic DNS providers. data_source: [] diff --git a/detections/deprecated/detect_webshell_exploit_behavior.yml b/detections/deprecated/detect_webshell_exploit_behavior.yml index 3b28ad33f1..e921c3ffbf 100644 --- a/detections/deprecated/detect_webshell_exploit_behavior.yml +++ b/detections/deprecated/detect_webshell_exploit_behavior.yml @@ -4,17 +4,23 @@ version: 7 date: '2025-01-24' author: Steven Dick status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Suspicious Child Process Spawned From WebServer type: TTP -description: The following analytic has been deprecated. - The following analytic identifies the execution of suspicious processes - typically associated with webshell activity on web servers. It detects when processes - like `cmd.exe`, `powershell.exe`, or `bash.exe` are spawned by web server processes - such as `w3wp.exe` or `nginx.exe`. This behavior is significant as it may indicate - an adversary exploiting a web application vulnerability to install a webshell, providing - persistent access and command execution capabilities. If confirmed malicious, this - activity could allow attackers to maintain control over the compromised server, - execute arbitrary commands, and potentially escalate privileges or exfiltrate sensitive - data. +description: The following analytic has been deprecated. The following analytic identifies + the execution of suspicious processes typically associated with webshell activity + on web servers. It detects when processes like `cmd.exe`, `powershell.exe`, or `bash.exe` + are spawned by web server processes such as `w3wp.exe` or `nginx.exe`. This behavior + is significant as it may indicate an adversary exploiting a web application vulnerability + to install a webshell, providing persistent access and command execution capabilities. + If confirmed malicious, this activity could allow attackers to maintain control + over the compromised server, execute arbitrary commands, and potentially escalate + privileges or exfiltrate sensitive data. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/detection_of_dns_tunnels.yml b/detections/deprecated/detection_of_dns_tunnels.yml index e903bf4d9a..595ded0bd5 100644 --- a/detections/deprecated/detection_of_dns_tunnels.yml +++ b/detections/deprecated/detection_of_dns_tunnels.yml @@ -4,6 +4,12 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: "This search is used to detect DNS tunneling, by calculating the sum of the length of DNS queries and DNS answers. The search also filters out potential diff --git a/detections/deprecated/disabling_net_user_account.yml b/detections/deprecated/disabling_net_user_account.yml index 2a10320558..3fee864584 100644 --- a/detections/deprecated/disabling_net_user_account.yml +++ b/detections/deprecated/disabling_net_user_account.yml @@ -4,15 +4,22 @@ version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows User Disabled Via Net type: TTP -description: The following analytic has been deprecated. - The following analytic detects the use of the `net.exe` utility to disable - a user account via the command line. It leverages data from Endpoint Detection and - Response (EDR) agents, focusing on process execution logs and command-line arguments. - This activity is significant as it may indicate an adversary's attempt to disrupt - user availability, potentially as a precursor to further malicious actions. If confirmed - malicious, this could lead to denial of service for legitimate users, aiding the - attacker in maintaining control or covering their tracks. +description: The following analytic has been deprecated. The following analytic detects + the use of the `net.exe` utility to disable a user account via the command line. + It leverages data from Endpoint Detection and Response (EDR) agents, focusing on + process execution logs and command-line arguments. This activity is significant + as it may indicate an adversary's attempt to disrupt user availability, potentially + as a precursor to further malicious actions. If confirmed malicious, this could + lead to denial of service for legitimate users, aiding the attacker in maintaining + control or covering their tracks. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml index b52f87457a..20f966e9b1 100644 --- a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml +++ b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml @@ -4,6 +4,12 @@ version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: This search will detect DNS requests resolved by unauthorized DNS servers. Legitimate DNS servers should be identified in the Enterprise Security Assets and diff --git a/detections/deprecated/dns_record_changed.yml b/detections/deprecated/dns_record_changed.yml index 1da12999ba..c917402af4 100644 --- a/detections/deprecated/dns_record_changed.yml +++ b/detections/deprecated/dns_record_changed.yml @@ -4,6 +4,12 @@ version: 6 date: '2024-11-14' author: Jose Hernandez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: The search takes the DNS records and their answers results of the discovered_dns_records lookup and finds if any records have changed by searching DNS response from the diff --git a/detections/deprecated/domain_account_discovery_with_net_app.yml b/detections/deprecated/domain_account_discovery_with_net_app.yml index 7299b21596..b4f21b70a2 100644 --- a/detections/deprecated/domain_account_discovery_with_net_app.yml +++ b/detections/deprecated/domain_account_discovery_with_net_app.yml @@ -4,8 +4,26 @@ version: 5 date: '2025-01-13' author: Teoderick Contreras, Mauricio Velazco, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: "This analytic was a TTP that looked only for commands that tries to query + info about the users via net user /do. This had a couple of issues, such as triggering + on creation of users via the /add flag etc..\nIt was deprecated in favor of a + more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122" + replacement_content: + - Windows User Discovery Via Net type: TTP -description: This following analytic has been deprecated in favour of the generic version "5d0d4830-0133-11ec-bae3-acde48001122". The following analytic detects the execution of `net.exe` or `net1.exe` with command-line arguments used to query domain users. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as it may indicate an attempt by adversaries to enumerate domain users for situational awareness and Active Directory discovery. If confirmed malicious, this behavior could allow attackers to map out user accounts, potentially leading to further exploitation or lateral movement within the network. +description: This following analytic has been deprecated in favour of the generic + version "5d0d4830-0133-11ec-bae3-acde48001122". The following analytic detects the + execution of `net.exe` or `net1.exe` with command-line arguments used to query domain + users. It leverages data from Endpoint Detection and Response (EDR) agents, focusing + on process names and command-line executions. This activity is significant as it + may indicate an attempt by adversaries to enumerate domain users for situational + awareness and Active Directory discovery. If confirmed malicious, this behavior + could allow attackers to map out user accounts, potentially leading to further exploitation + or lateral movement within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/domain_group_discovery_with_net.yml b/detections/deprecated/domain_group_discovery_with_net.yml index af3f1f4e79..8d355cbccc 100644 --- a/detections/deprecated/domain_group_discovery_with_net.yml +++ b/detections/deprecated/domain_group_discovery_with_net.yml @@ -4,8 +4,23 @@ version: 6 date: '2025-01-13' author: Mauricio Velazco, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Group Discovery Via Net type: Hunting -description: This search has been deprecated in favour of the more generic analytic "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic identifies the execution of `net.exe` with command-line arguments used to query domain groups, specifically `group /domain`. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries to enumerate domain groups, which is a common step in Active Directory Discovery. If confirmed malicious, this behavior could allow attackers to gain insights into the domain structure, aiding in further attacks such as privilege escalation or lateral movement. +description: This search has been deprecated in favour of the more generic analytic + "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic identifies the execution + of `net.exe` with command-line arguments used to query domain groups, specifically + `group /domain`. It leverages data from Endpoint Detection and Response (EDR) agents, + focusing on process names and command-line arguments. This activity is significant + as it indicates potential reconnaissance efforts by adversaries to enumerate domain + groups, which is a common step in Active Directory Discovery. If confirmed malicious, + this behavior could allow attackers to gain insights into the domain structure, + aiding in further attacks such as privilege escalation or lateral movement. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/dump_lsass_via_procdump_rename.yml b/detections/deprecated/dump_lsass_via_procdump_rename.yml index db67928fa4..db97b216a0 100644 --- a/detections/deprecated/dump_lsass_via_procdump_rename.yml +++ b/detections/deprecated/dump_lsass_via_procdump_rename.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Updated to a new detection name + replacement_content: + - Dump LSASS via procdump type: Hunting description: "Detect a renamed instance of procdump.exe dumping the lsass process. This query looks for both -mm and -ma usage. -mm will produce a mini dump file and diff --git a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml index c0dddee3ca..306a57bde9 100644 --- a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml @@ -4,6 +4,14 @@ version: 6 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud API Calls From Previously Unseen User Roles type: Anomaly description: This search looks for EC2 instances being modified by users who have not previously modified them. This search is deprecated and have been translated diff --git a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml index 0d7e62b234..21078ec309 100644 --- a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml +++ b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created In Previously Unused Region type: Hunting description: This search looks for AWS CloudTrail events where an instance is started in a particular region in the last one hour and then compares it to a lookup file diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml index 80a929eefb..7a08a8ab13 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml @@ -4,6 +4,14 @@ version: 5 date: '2025-01-16' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created With Previously Unseen Image type: Anomaly description: This search looks for EC2 instances being created with previously unseen AMIs. This search is deprecated and have been translated to use the latest Change diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml index e1a95404a0..1b2fbffdbb 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml @@ -4,6 +4,14 @@ version: 6 date: '2025-01-16' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created With Previously Unseen Instance Type type: Anomaly description: This search looks for EC2 instances being created with previously unseen instance types. This search is deprecated and have been translated to use the latest diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml index d43786da55..adaf0a181b 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml @@ -4,6 +4,14 @@ version: 6 date: '2025-01-16' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created By Previously Unseen User type: Anomaly description: This search looks for EC2 instances being created by users who have not created them before. This search is deprecated and have been translated to use the diff --git a/detections/deprecated/elevated_group_discovery_with_net.yml b/detections/deprecated/elevated_group_discovery_with_net.yml index 14e1b5ab5a..9712be51f2 100644 --- a/detections/deprecated/elevated_group_discovery_with_net.yml +++ b/detections/deprecated/elevated_group_discovery_with_net.yml @@ -4,16 +4,22 @@ version: 6 date: '2025-01-24' author: Mauricio Velazco, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Sensitive Group Discovery With Net type: TTP -description: The following analytic has been deprecated. - The following analytic detects the execution of `net.exe` or `net1.exe` - with command-line arguments used to query elevated domain groups. It leverages data - from Endpoint Detection and Response (EDR) agents, focusing on process names and - command-line executions. This activity is significant as it indicates potential - reconnaissance efforts by adversaries to identify high-privileged users within Active - Directory. If confirmed malicious, this behavior could lead to further attacks aimed - at compromising privileged accounts, escalating privileges, or gaining unauthorized - access to sensitive systems and data. +description: The following analytic has been deprecated. The following analytic detects + the execution of `net.exe` or `net1.exe` with command-line arguments used to query + elevated domain groups. It leverages data from Endpoint Detection and Response (EDR) + agents, focusing on process names and command-line executions. This activity is + significant as it indicates potential reconnaissance efforts by adversaries to identify + high-privileged users within Active Directory. If confirmed malicious, this behavior + could lead to further attacks aimed at compromising privileged accounts, escalating + privileges, or gaining unauthorized access to sensitive systems and data. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/excel_spawning_powershell.yml b/detections/deprecated/excel_spawning_powershell.yml index a4808cc05e..eeb145c769 100644 --- a/detections/deprecated/excel_spawning_powershell.yml +++ b/detections/deprecated/excel_spawning_powershell.yml @@ -4,16 +4,24 @@ version: 7 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". - The following analytic detects Microsoft Excel spawning PowerShell, an - uncommon and suspicious behavior. This detection leverages data from Endpoint Detection - and Response (EDR) agents, focusing on process creation events where the parent - process is "excel.exe" and the child process is PowerShell. This activity is significant - because it is often associated with spearphishing attacks, where malicious attachments - execute encoded PowerShell commands. If confirmed malicious, this behavior could - allow an attacker to execute arbitrary code, potentially leading to data exfiltration, - privilege escalation, or persistent access within the environment. +description: The following analytic has been deprecated in favour of a more generic + approach in "Windows Office Product Spawned Uncommon Process". The following analytic + detects Microsoft Excel spawning PowerShell, an uncommon and suspicious behavior. + This detection leverages data from Endpoint Detection and Response (EDR) agents, + focusing on process creation events where the parent process is "excel.exe" and + the child process is PowerShell. This activity is significant because it is often + associated with spearphishing attacks, where malicious attachments execute encoded + PowerShell commands. If confirmed malicious, this behavior could allow an attacker + to execute arbitrary code, potentially leading to data exfiltration, privilege escalation, + or persistent access within the environment. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/excessive_service_stop_attempt.yml b/detections/deprecated/excessive_service_stop_attempt.yml index 3e27dc456b..428f6c64e7 100644 --- a/detections/deprecated/excessive_service_stop_attempt.yml +++ b/detections/deprecated/excessive_service_stop_attempt.yml @@ -4,16 +4,22 @@ version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Excessive Service Stop Attempt type: Anomaly -description: The following analytic has been deprecated. - The following analytic detects multiple attempts to stop or delete services - on a system using `net.exe`, `sc.exe`, or `net1.exe`. It leverages Endpoint Detection - and Response (EDR) telemetry, focusing on process names and command-line executions - within a one-minute window. This activity is significant as it may indicate an adversary - attempting to disable security or critical services to evade detection and further - their objectives. If confirmed malicious, this could lead to the attacker gaining - persistence, escalating privileges, or disrupting essential services, thereby compromising - the system's security posture. +description: The following analytic has been deprecated. The following analytic detects + multiple attempts to stop or delete services on a system using `net.exe`, `sc.exe`, + or `net1.exe`. It leverages Endpoint Detection and Response (EDR) telemetry, focusing + on process names and command-line executions within a one-minute window. This activity + is significant as it may indicate an adversary attempting to disable security or + critical services to evade detection and further their objectives. If confirmed + malicious, this could lead to the attacker gaining persistence, escalating privileges, + or disrupting essential services, thereby compromising the system's security posture. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/excessive_usage_of_net_app.yml b/detections/deprecated/excessive_usage_of_net_app.yml index e48ea823d4..ea3c6f60ed 100644 --- a/detections/deprecated/excessive_usage_of_net_app.yml +++ b/detections/deprecated/excessive_usage_of_net_app.yml @@ -4,16 +4,22 @@ version: 6 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Excessive Usage Of Net App type: Anomaly -description: The following analytic has been deprecated. - The following analytic detects excessive usage of `net.exe` or `net1.exe` - within a one-minute interval. It leverages data from Endpoint Detection and Response - (EDR) agents, focusing on process names, parent processes, and command-line executions. - This behavior is significant as it may indicate an adversary attempting to create, - delete, or disable multiple user accounts rapidly, a tactic observed in Monero mining - incidents. If confirmed malicious, this activity could lead to unauthorized user - account manipulation, potentially compromising system integrity and enabling further - malicious actions. +description: The following analytic has been deprecated. The following analytic detects + excessive usage of `net.exe` or `net1.exe` within a one-minute interval. It leverages + data from Endpoint Detection and Response (EDR) agents, focusing on process names, + parent processes, and command-line executions. This behavior is significant as it + may indicate an adversary attempting to create, delete, or disable multiple user + accounts rapidly, a tactic observed in Monero mining incidents. If confirmed malicious, + this activity could lead to unauthorized user account manipulation, potentially + compromising system integrity and enabling further malicious actions. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml index 6e453a7f03..81f9becb23 100644 --- a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml +++ b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml @@ -4,6 +4,13 @@ version: 6 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Updated to a new detection name + replacement_content: + - Execution of File with Multiple Extensions type: TTP description: This search looks for processes launched from files with at least five spaces in the name before the extension. This is typically done to obfuscate the diff --git a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml index c72e3977a2..995f48dd58 100644 --- a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml +++ b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Hunting description: This search returns a list of hosts that have not successfully completed a backup in over a week. Deprecated because it's a infrastructure monitoring. diff --git a/detections/deprecated/extraction_of_registry_hives.yml b/detections/deprecated/extraction_of_registry_hives.yml index 565dccabfa..c4e3bdaee0 100644 --- a/detections/deprecated/extraction_of_registry_hives.yml +++ b/detections/deprecated/extraction_of_registry_hives.yml @@ -4,16 +4,23 @@ version: 6 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Sensitive Registry Hive Dump Via CommandLine type: TTP -description: The following analytic has been deprecated. - The following analytic detects the use of `reg.exe` to export Windows - Registry hives, which may contain sensitive credentials. This detection leverages - data from Endpoint Detection and Response (EDR) agents, focusing on command-line - executions involving `save` or `export` actions targeting the `sam`, `system`, or - `security` hives. This activity is significant as it indicates potential offline - credential access attacks, often executed from untrusted processes or scripts. If - confirmed malicious, attackers could gain access to credential data, enabling further - compromise and lateral movement within the network. +description: The following analytic has been deprecated. The following analytic detects + the use of `reg.exe` to export Windows Registry hives, which may contain sensitive + credentials. This detection leverages data from Endpoint Detection and Response + (EDR) agents, focusing on command-line executions involving `save` or `export` actions + targeting the `sam`, `system`, or `security` hives. This activity is significant + as it indicates potential offline credential access attacks, often executed from + untrusted processes or scripts. If confirmed malicious, attackers could gain access + to credential data, enabling further compromise and lateral movement within the + network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/first_time_seen_command_line_argument.yml b/detections/deprecated/first_time_seen_command_line_argument.yml index 5df827cada..f2d43dec54 100644 --- a/detections/deprecated/first_time_seen_command_line_argument.yml +++ b/detections/deprecated/first_time_seen_command_line_argument.yml @@ -4,6 +4,13 @@ version: 8 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. diff --git a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml index 10a412fbc9..da59975438 100644 --- a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml +++ b/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Hunting description: This search provides detection of accounts with high risk roles by projects. Compromised accounts with high risk roles can move laterally or even scalate privileges diff --git a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml index 1291444493..38e56596e6 100644 --- a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml +++ b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Hunting description: This search provides detection of high risk permissions by resource and accounts. These are permissions that can allow attackers with compromised accounts diff --git a/detections/deprecated/gcp_detect_oauth_token_abuse.yml b/detections/deprecated/gcp_detect_oauth_token_abuse.yml index 25144dd436..bef84aaa87 100644 --- a/detections/deprecated/gcp_detect_oauth_token_abuse.yml +++ b/detections/deprecated/gcp_detect_oauth_token_abuse.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Hunting description: This search provides detection of possible GCP Oauth token abuse. GCP Oauth token without time limit can be exfiltrated and reused for keeping access diff --git a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml index f8fabad5ff..88aad6f364 100644 --- a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml +++ b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Kubernetes Scanning by Unauthenticated IP Address type: TTP description: This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster diff --git a/detections/deprecated/identify_new_user_accounts.yml b/detections/deprecated/identify_new_user_accounts.yml index 55b528d72a..5e43985eae 100644 --- a/detections/deprecated/identify_new_user_accounts.yml +++ b/detections/deprecated/identify_new_user_accounts.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This detection search will help profile user accounts in your environment by identifying newly created accounts that have been added to your network in the diff --git a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml index 8aed9288a5..49a3f2cddb 100644 --- a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml +++ b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision diff --git a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml index 6d04bf8d94..2a269a69ce 100644 --- a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml +++ b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC diff --git a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml index bb7b707a96..7c08f4bb52 100644 --- a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml @@ -4,6 +4,13 @@ version: 5 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml index 17722e0587..3e8620e1f1 100644 --- a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or diff --git a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml index ef9d02ecbe..ec37c0848f 100644 --- a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml +++ b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes service accounts,accessing pods and namespaces by IP address and verb diff --git a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml index 0adc47769d..d96925d545 100644 --- a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml +++ b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding rare or top to see both extremes diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml index 8ae1ee647e..80591ab342 100644 --- a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml index 9993a0a115..b7243aff43 100644 --- a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml @@ -4,6 +4,13 @@ version: 5 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml index ccbf5daf0c..0740c5bc9e 100644 --- a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes service accounts with failure or forbidden access status diff --git a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml index ef3fed2b2d..94ba765c3e 100644 --- a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml +++ b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on rare Kubectl calls with IP, verb namespace and object access context diff --git a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml index 1b1378b2f7..d41ae9e248 100644 --- a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml +++ b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster pod diff --git a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml index 8a6b44473d..5ad0876707 100644 --- a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml +++ b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster in diff --git a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml index 0d3a4cdf11..32ad65ac4c 100644 --- a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml +++ b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision diff --git a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml index 09a26684ce..fc2bf51208 100644 --- a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml +++ b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml index 557ab8a5c3..67d2e2979e 100644 --- a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml index da1b2cf148..e37d0a15ab 100644 --- a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml @@ -4,6 +4,13 @@ version: 5 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml index fff4730076..7f03e97647 100644 --- a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or diff --git a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml index a78e967c70..80d95194a1 100644 --- a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml +++ b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: Hunting description: This search provides information on anonymous Kubectl calls with IP, verb namespace and object access context diff --git a/detections/deprecated/linux_auditd_find_private_keys.yml b/detections/deprecated/linux_auditd_find_private_keys.yml index e9b889bc9e..8ccb92c6c7 100644 --- a/detections/deprecated/linux_auditd_find_private_keys.yml +++ b/detections/deprecated/linux_auditd_find_private_keys.yml @@ -4,16 +4,22 @@ version: 5 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Linux Auditd Private Keys and Certificate Enumeration type: TTP -description: The following analytic has been deprecated. - The following analytic detects suspicious attempts to find private keys, - which may indicate an attacker's effort to access sensitive cryptographic information. - Private keys are crucial for securing encrypted communications and data, and unauthorized - access to them can lead to severe security breaches, including data decryption and - identity theft. By monitoring for unusual or unauthorized searches for private keys, - this analytic helps identify potential threats to cryptographic security, enabling - security teams to take swift action to protect the integrity and confidentiality - of encrypted information. +description: The following analytic has been deprecated. The following analytic detects + suspicious attempts to find private keys, which may indicate an attacker's effort + to access sensitive cryptographic information. Private keys are crucial for securing + encrypted communications and data, and unauthorized access to them can lead to severe + security breaches, including data decryption and identity theft. By monitoring for + unusual or unauthorized searches for private keys, this analytic helps identify + potential threats to cryptographic security, enabling security teams to take swift + action to protect the integrity and confidentiality of encrypted information. data_source: - Linux Auditd Execve search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as diff --git a/detections/deprecated/local_account_discovery_with_net.yml b/detections/deprecated/local_account_discovery_with_net.yml index 7ac754da20..6aa48ba58f 100644 --- a/detections/deprecated/local_account_discovery_with_net.yml +++ b/detections/deprecated/local_account_discovery_with_net.yml @@ -4,16 +4,22 @@ version: 6 date: '2025-01-24' author: Mauricio Velazco, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows User Discovery Via Net type: Hunting -description: The following analytic has been deprecated. - The following analytic detects the execution of `net.exe` or `net1.exe` - with command-line arguments `user` or `users` to query local user accounts. It leverages - data from Endpoint Detection and Response (EDR) agents, focusing on process names - and command-line executions. This activity is significant as it indicates potential - reconnaissance efforts by adversaries to enumerate local users, which is a common - step in situational awareness and Active Directory discovery. If confirmed malicious, - this behavior could lead to further attacks, including privilege escalation and - lateral movement within the network. +description: The following analytic has been deprecated. The following analytic detects + the execution of `net.exe` or `net1.exe` with command-line arguments `user` or `users` + to query local user accounts. It leverages data from Endpoint Detection and Response + (EDR) agents, focusing on process names and command-line executions. This activity + is significant as it indicates potential reconnaissance efforts by adversaries to + enumerate local users, which is a common step in situational awareness and Active + Directory discovery. If confirmed malicious, this behavior could lead to further + attacks, including privilege escalation and lateral movement within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/monitor_dns_for_brand_abuse.yml b/detections/deprecated/monitor_dns_for_brand_abuse.yml index 9ad520f284..dfe23ab2a6 100644 --- a/detections/deprecated/monitor_dns_for_brand_abuse.yml +++ b/detections/deprecated/monitor_dns_for_brand_abuse.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: TTP description: This search looks for DNS requests for faux domains similar to the domains that you want to have monitored for abuse. diff --git a/detections/deprecated/mshtml_module_load_in_office_product.yml b/detections/deprecated/mshtml_module_load_in_office_product.yml index f617d2f40e..f9b620ec36 100644 --- a/detections/deprecated/mshtml_module_load_in_office_product.yml +++ b/detections/deprecated/mshtml_module_load_in_office_product.yml @@ -4,15 +4,22 @@ version: 7 date: '2025-01-24' author: Michael Haag, Mauricio Velazco, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Loaded MSHTML Module type: TTP -description: The following analytic has been deprecated. - The following analytic detects the loading of the mshtml.dll module into - an Office product, which is indicative of CVE-2021-40444 exploitation. It leverages - Sysmon EventID 7 to monitor image loads by specific Office processes. This activity - is significant because it can indicate an attempt to exploit a vulnerability in - the MSHTML component via a malicious document. If confirmed malicious, this could - allow an attacker to execute arbitrary code, potentially leading to system compromise, - data exfiltration, or further network penetration. +description: The following analytic has been deprecated. The following analytic detects + the loading of the mshtml.dll module into an Office product, which is indicative + of CVE-2021-40444 exploitation. It leverages Sysmon EventID 7 to monitor image loads + by specific Office processes. This activity is significant because it can indicate + an attempt to exploit a vulnerability in the MSHTML component via a malicious document. + If confirmed malicious, this could allow an attacker to execute arbitrary code, + potentially leading to system compromise, data exfiltration, or further network + penetration. data_source: - Sysmon EventID 7 search: '`sysmon` EventID=7 process_name IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","wordpad.exe","wordview.exe","onenote.exe","onenotem.exe","onenoteviewer.exe","onenoteim.exe", diff --git a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml index 68269b2e43..23ac3906f5 100644 --- a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml +++ b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml @@ -4,6 +4,14 @@ version: 5 date: '2024-11-14' author: Michael Haag, Mauricio Velazco, Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Users Failing To Authenticate From Ip type: TTP description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Users Failing To Authenticate From Ip`. This analytic identifies diff --git a/detections/deprecated/net_localgroup_discovery.yml b/detections/deprecated/net_localgroup_discovery.yml index e54388cb4c..13b349af7b 100644 --- a/detections/deprecated/net_localgroup_discovery.yml +++ b/detections/deprecated/net_localgroup_discovery.yml @@ -4,8 +4,24 @@ version: 5 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 + / Windows Group Discovery Via Net + replacement_content: + - Windows Group Discovery Via Net type: Hunting -description: This search has been deprecated in favour of the more generic analytic "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic detects the execution of the `net localgroup` command, which is used to enumerate local group memberships on a system. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs that include command-line details. This activity is significant because it can indicate an attacker is gathering information about local group memberships, potentially to identify privileged accounts. If confirmed malicious, this behavior could lead to further privilege escalation or lateral movement within the network. +description: This search has been deprecated in favour of the more generic analytic + "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic detects the execution + of the `net localgroup` command, which is used to enumerate local group memberships + on a system. It leverages data from Endpoint Detection and Response (EDR) agents, + focusing on process execution logs that include command-line details. This activity + is significant because it can indicate an attacker is gathering information about + local group memberships, potentially to identify privileged accounts. If confirmed + malicious, this behavior could lead to further privilege escalation or lateral movement + within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/network_connection_discovery_with_net.yml b/detections/deprecated/network_connection_discovery_with_net.yml index 0002699f31..1785ae5ff7 100644 --- a/detections/deprecated/network_connection_discovery_with_net.yml +++ b/detections/deprecated/network_connection_discovery_with_net.yml @@ -4,16 +4,23 @@ version: 6 date: '2025-01-24' author: Mauricio Velazco, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Network Connection Discovery Via Net type: Hunting -description: The following analytic has been deprecated. - The following analytic identifies the execution of `net.exe` or `net1.exe` - with command-line arguments used to list network connections on a compromised system. - It leverages data from Endpoint Detection and Response (EDR) agents, focusing on - process names and command-line executions. This activity is significant as it indicates - potential network reconnaissance by adversaries or Red Teams, aiming to gather situational - awareness and Active Directory information. If confirmed malicious, this behavior - could allow attackers to map the network, identify critical assets, and plan further - attacks, potentially leading to data exfiltration or lateral movement. +description: The following analytic has been deprecated. The following analytic identifies + the execution of `net.exe` or `net1.exe` with command-line arguments used to list + network connections on a compromised system. It leverages data from Endpoint Detection + and Response (EDR) agents, focusing on process names and command-line executions. + This activity is significant as it indicates potential network reconnaissance by + adversaries or Red Teams, aiming to gather situational awareness and Active Directory + information. If confirmed malicious, this behavior could allow attackers to map + the network, identify critical assets, and plan further attacks, potentially leading + to data exfiltration or lateral movement. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml index 13dddb8c18..23ed76cc7c 100644 --- a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml +++ b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml @@ -4,6 +4,14 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - O365 Mailbox Email Forwarding Enabled type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Mailbox Email Forwarding Enabled`. This search detects when an admin diff --git a/detections/deprecated/o365_suspicious_rights_delegation.yml b/detections/deprecated/o365_suspicious_rights_delegation.yml index e9e6543750..a0fcb196a4 100644 --- a/detections/deprecated/o365_suspicious_rights_delegation.yml +++ b/detections/deprecated/o365_suspicious_rights_delegation.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Patrick Bareiss, Mauricio Velazco, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - O365 Elevated Mailbox Permission Assigned type: TTP description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Elevated Mailbox Permission Assigned`. This analytic identifies instances diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/detections/deprecated/o365_suspicious_user_email_forwarding.yml index 1a9c9c5c4c..682a9fff0c 100644 --- a/detections/deprecated/o365_suspicious_user_email_forwarding.yml +++ b/detections/deprecated/o365_suspicious_user_email_forwarding.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - O365 Mailbox Email Forwarding Enabled type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Mailbox Email Forwarding Enabled`. The following analytic detects when diff --git a/detections/deprecated/office_application_drop_executable.yml b/detections/deprecated/office_application_drop_executable.yml index 94ddc48e52..da7930df64 100644 --- a/detections/deprecated/office_application_drop_executable.yml +++ b/detections/deprecated/office_application_drop_executable.yml @@ -4,16 +4,22 @@ version: 9 date: '2025-01-24' author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Dropped Uncommon File type: TTP -description: The following analytic has been deprecated. - The following analytic detects Microsoft Office applications dropping - or creating executables or scripts on a Windows OS. It leverages process creation - and file system events from the Endpoint data model to identify Office applications - like Word or Excel generating files with extensions such as .exe, .dll, or .ps1. - This behavior is significant as it is often associated with spear-phishing attacks - where malicious files are dropped to compromise the host. If confirmed malicious, - this activity could lead to code execution, privilege escalation, or persistent - access, posing a severe threat to the environment. +description: The following analytic has been deprecated. The following analytic detects + Microsoft Office applications dropping or creating executables or scripts on a Windows + OS. It leverages process creation and file system events from the Endpoint data + model to identify Office applications like Word or Excel generating files with extensions + such as .exe, .dll, or .ps1. This behavior is significant as it is often associated + with spear-phishing attacks where malicious files are dropped to compromise the + host. If confirmed malicious, this activity could lead to code execution, privilege + escalation, or persistent access, posing a severe threat to the environment. data_source: - Sysmon EventID 1 AND Sysmon EventID 11 search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes diff --git a/detections/deprecated/office_application_spawn_regsvr32_process.yml b/detections/deprecated/office_application_spawn_regsvr32_process.yml index 20aef6978a..0b35f87583 100644 --- a/detections/deprecated/office_application_spawn_regsvr32_process.yml +++ b/detections/deprecated/office_application_spawn_regsvr32_process.yml @@ -4,16 +4,24 @@ version: 8 date: '2025-01-13' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". - The following analytic identifies instances where an Office application - spawns a Regsvr32 process, which is often indicative of macro execution or malicious - code. This detection leverages data from Endpoint Detection and Response (EDR) agents, - focusing on process creation events where the parent process is a known Office application. - This activity is significant because it is a common technique used by malware, such - as IcedID, to initiate infections. If confirmed malicious, this behavior could lead - to code execution, allowing attackers to gain control over the affected system and - potentially escalate privileges. +description: The following analytic has been deprecated in favour of a more generic + approach in "Windows Office Product Spawned Uncommon Process". The following analytic + identifies instances where an Office application spawns a Regsvr32 process, which + is often indicative of macro execution or malicious code. This detection leverages + data from Endpoint Detection and Response (EDR) agents, focusing on process creation + events where the parent process is a known Office application. This activity is + significant because it is a common technique used by malware, such as IcedID, to + initiate infections. If confirmed malicious, this behavior could lead to code execution, + allowing attackers to gain control over the affected system and potentially escalate + privileges. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/office_application_spawn_rundll32_process.yml b/detections/deprecated/office_application_spawn_rundll32_process.yml index fd944b75cf..d9a37aaba7 100644 --- a/detections/deprecated/office_application_spawn_rundll32_process.yml +++ b/detections/deprecated/office_application_spawn_rundll32_process.yml @@ -4,15 +4,23 @@ version: 8 date: '2025-01-13' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". - The following analytic identifies instances where an Office application - spawns a rundll32 process, which is often indicative of macro execution or malicious - code. This detection leverages data from Endpoint Detection and Response (EDR) agents, - focusing on process creation events where the parent process is a known Office application. - This activity is significant because it is a common technique used by malware, such - as Trickbot, to initiate infections. If confirmed malicious, this behavior could - lead to code execution, further system compromise, and potential data exfiltration. +description: The following analytic has been deprecated in favour of a more generic + approach in "Windows Office Product Spawned Uncommon Process". The following analytic + identifies instances where an Office application spawns a rundll32 process, which + is often indicative of macro execution or malicious code. This detection leverages + data from Endpoint Detection and Response (EDR) agents, focusing on process creation + events where the parent process is a known Office application. This activity is + significant because it is a common technique used by malware, such as Trickbot, + to initiate infections. If confirmed malicious, this behavior could lead to code + execution, further system compromise, and potential data exfiltration. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/office_document_creating_schedule_task.yml b/detections/deprecated/office_document_creating_schedule_task.yml index 0198d43de6..d317b98c6a 100644 --- a/detections/deprecated/office_document_creating_schedule_task.yml +++ b/detections/deprecated/office_document_creating_schedule_task.yml @@ -4,15 +4,22 @@ version: 10 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Loading Taskschd DLL type: TTP -description: The following analytic has been deprecated. - The following analytic detects an Office document creating a scheduled - task, either through a macro VBA API or by loading `taskschd.dll`. This detection - leverages Sysmon EventCode 7 to identify when Office applications load the `taskschd.dll` - file. This activity is significant as it is a common technique used by malicious - macro malware to establish persistence or initiate beaconing. If confirmed malicious, - this could allow an attacker to maintain persistence, execute arbitrary commands, - or schedule future malicious activities, posing a significant threat to the environment. +description: The following analytic has been deprecated. The following analytic detects + an Office document creating a scheduled task, either through a macro VBA API or + by loading `taskschd.dll`. This detection leverages Sysmon EventCode 7 to identify + when Office applications load the `taskschd.dll` file. This activity is significant + as it is a common technique used by malicious macro malware to establish persistence + or initiate beaconing. If confirmed malicious, this could allow an attacker to maintain + persistence, execute arbitrary commands, or schedule future malicious activities, + posing a significant threat to the environment. data_source: - Sysmon EventID 7 search: '`sysmon` EventCode=7 process_name IN ("WINWORD.EXE", "EXCEL.EXE", "POWERPNT.EXE","onenote.exe","onenotem.exe","onenoteviewer.exe","onenoteim.exe", diff --git a/detections/deprecated/office_document_executing_macro_code.yml b/detections/deprecated/office_document_executing_macro_code.yml index 920e9483f5..35c088e292 100644 --- a/detections/deprecated/office_document_executing_macro_code.yml +++ b/detections/deprecated/office_document_executing_macro_code.yml @@ -4,15 +4,21 @@ version: 9 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Loading VBE7 DLL type: TTP -description: The following analytic has been deprecated. - The following analytic identifies office documents executing macro code. - It leverages Sysmon EventCode 7 to detect when processes like WINWORD.EXE or EXCEL.EXE - load specific DLLs associated with macros (e.g., VBE7.DLL). This activity is significant - because macros are a common attack vector for delivering malicious payloads, such - as malware. If confirmed malicious, this could lead to unauthorized code execution, - data exfiltration, or further compromise of the system. Disabling macros by default - is recommended to mitigate this risk. +description: The following analytic has been deprecated. The following analytic identifies + office documents executing macro code. It leverages Sysmon EventCode 7 to detect + when processes like WINWORD.EXE or EXCEL.EXE load specific DLLs associated with + macros (e.g., VBE7.DLL). This activity is significant because macros are a common + attack vector for delivering malicious payloads, such as malware. If confirmed malicious, + this could lead to unauthorized code execution, data exfiltration, or further compromise + of the system. Disabling macros by default is recommended to mitigate this risk. data_source: - Sysmon EventID 7 search: '`sysmon` EventCode=7 process_name IN ("WINWORD.EXE", "EXCEL.EXE", "POWERPNT.EXE","onenote.exe","onenotem.exe","onenoteviewer.exe","onenoteim.exe","msaccess.exe") diff --git a/detections/deprecated/office_document_spawned_child_process_to_download.yml b/detections/deprecated/office_document_spawned_child_process_to_download.yml index def3130752..0763eb9df3 100644 --- a/detections/deprecated/office_document_spawned_child_process_to_download.yml +++ b/detections/deprecated/office_document_spawned_child_process_to_download.yml @@ -4,16 +4,23 @@ version: 10 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned Child Process For Download type: TTP -description: The following analytic has been deprecated. - The following analytic identifies Office applications spawning child - processes to download content via HTTP/HTTPS. It leverages data from Endpoint Detection - and Response (EDR) agents, focusing on process creation events where Office applications - like Word or Excel initiate network connections, excluding common browsers. This - activity is significant as it often indicates the use of malicious documents to - execute living-off-the-land binaries (LOLBins) for payload delivery. If confirmed - malicious, this behavior could lead to unauthorized code execution, data exfiltration, - or further malware deployment, posing a severe threat to the organization's security. +description: The following analytic has been deprecated. The following analytic identifies + Office applications spawning child processes to download content via HTTP/HTTPS. + It leverages data from Endpoint Detection and Response (EDR) agents, focusing on + process creation events where Office applications like Word or Excel initiate network + connections, excluding common browsers. This activity is significant as it often + indicates the use of malicious documents to execute living-off-the-land binaries + (LOLBins) for payload delivery. If confirmed malicious, this behavior could lead + to unauthorized code execution, data exfiltration, or further malware deployment, + posing a severe threat to the organization's security. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/office_product_spawn_cmd_process.yml b/detections/deprecated/office_product_spawn_cmd_process.yml index acbe347fb7..d9d6ff558c 100644 --- a/detections/deprecated/office_product_spawn_cmd_process.yml +++ b/detections/deprecated/office_product_spawn_cmd_process.yml @@ -4,9 +4,23 @@ version: 8 date: '2025-01-13' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". - The following analytic detects an Office product spawning a CMD process, which is indicative of a macro executing shell commands to download or run malicious code. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and parent process names. This activity is significant as it often signals the execution of malicious payloads, such as those seen in Trickbot spear-phishing campaigns. If confirmed malicious, this behavior could lead to unauthorized code execution, potentially compromising the system and allowing further malicious activities. +description: The following analytic has been deprecated in favour of a more generic + approach in "Windows Office Product Spawned Uncommon Process". The following analytic + detects an Office product spawning a CMD process, which is indicative of a macro + executing shell commands to download or run malicious code. This detection leverages + data from Endpoint Detection and Response (EDR) agents, focusing on process and + parent process names. This activity is significant as it often signals the execution + of malicious payloads, such as those seen in Trickbot spear-phishing campaigns. + If confirmed malicious, this behavior could lead to unauthorized code execution, + potentially compromising the system and allowing further malicious activities. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/office_product_spawning_bitsadmin.yml b/detections/deprecated/office_product_spawning_bitsadmin.yml index 8c3de51640..2b8a51389c 100644 --- a/detections/deprecated/office_product_spawning_bitsadmin.yml +++ b/detections/deprecated/office_product_spawning_bitsadmin.yml @@ -4,16 +4,24 @@ version: 9 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". - The following analytic detects any Windows Office Product spawning `bitsadmin.exe`, - a behavior often associated with malware families like TA551 and IcedID. This detection - leverages data from Endpoint Detection and Response (EDR) agents, focusing on process - and parent process relationships. This activity is significant because `bitsadmin.exe` - is commonly used for malicious file transfers, potentially indicating a malware - infection. If confirmed malicious, this activity could allow attackers to download - additional payloads, escalate privileges, or establish persistence, leading to further - compromise of the affected system. +description: The following analytic has been deprecated in favour of a more generic + approach in "Windows Office Product Spawned Uncommon Process". The following analytic + detects any Windows Office Product spawning `bitsadmin.exe`, a behavior often associated + with malware families like TA551 and IcedID. This detection leverages data from + Endpoint Detection and Response (EDR) agents, focusing on process and parent process + relationships. This activity is significant because `bitsadmin.exe` is commonly + used for malicious file transfers, potentially indicating a malware infection. If + confirmed malicious, this activity could allow attackers to download additional + payloads, escalate privileges, or establish persistence, leading to further compromise + of the affected system. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/office_product_spawning_certutil.yml b/detections/deprecated/office_product_spawning_certutil.yml index d1e14b4181..d89056cb83 100644 --- a/detections/deprecated/office_product_spawning_certutil.yml +++ b/detections/deprecated/office_product_spawning_certutil.yml @@ -4,16 +4,23 @@ version: 9 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". - The following analytic detects any Windows Office Product spawning `certutil.exe`, - a behavior often associated with malware families like TA551 and IcedID. This detection - leverages Endpoint Detection and Response (EDR) data, focusing on process relationships - and command-line executions. The significance lies in the fact that `certutil.exe` - is frequently used for downloading malicious payloads from remote URLs. If confirmed - malicious, this activity could lead to unauthorized code execution, data exfiltration, - or further system compromise. Immediate investigation and containment are crucial - to prevent potential damage. +description: The following analytic has been deprecated in favour of a more generic + approach in "Windows Office Product Spawned Uncommon Process". The following analytic + detects any Windows Office Product spawning `certutil.exe`, a behavior often associated + with malware families like TA551 and IcedID. This detection leverages Endpoint Detection + and Response (EDR) data, focusing on process relationships and command-line executions. + The significance lies in the fact that `certutil.exe` is frequently used for downloading + malicious payloads from remote URLs. If confirmed malicious, this activity could + lead to unauthorized code execution, data exfiltration, or further system compromise. + Immediate investigation and containment are crucial to prevent potential damage. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/office_product_spawning_mshta.yml b/detections/deprecated/office_product_spawning_mshta.yml index 966d3f3b98..4ba85dc480 100644 --- a/detections/deprecated/office_product_spawning_mshta.yml +++ b/detections/deprecated/office_product_spawning_mshta.yml @@ -4,16 +4,23 @@ version: 8 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". - The following analytic identifies instances where a Microsoft Office - product spawns `mshta.exe`. This detection leverages data from Endpoint Detection - and Response (EDR) agents, focusing on process creation events where the parent - process is an Office application. This activity is significant because it is a common - technique used by malware families like TA551 and IcedID to execute malicious scripts - or payloads. If confirmed malicious, this behavior could allow attackers to execute - arbitrary code, potentially leading to data exfiltration, system compromise, or - further malware deployment. +description: The following analytic has been deprecated in favour of a more generic + approach in "Windows Office Product Spawned Uncommon Process". The following analytic + identifies instances where a Microsoft Office product spawns `mshta.exe`. This detection + leverages data from Endpoint Detection and Response (EDR) agents, focusing on process + creation events where the parent process is an Office application. This activity + is significant because it is a common technique used by malware families like TA551 + and IcedID to execute malicious scripts or payloads. If confirmed malicious, this + behavior could allow attackers to execute arbitrary code, potentially leading to + data exfiltration, system compromise, or further malware deployment. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 @@ -81,6 +88,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml index 34040e8cb5..43530ad126 100644 --- a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml +++ b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml @@ -4,16 +4,22 @@ version: 10 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned Rundll32 With No DLL type: TTP -description: The following analytic has been deprecated. - The following analytic detects any Windows Office Product spawning `rundll32.exe` - without a `.dll` file extension. This behavior is identified using Endpoint Detection - and Response (EDR) telemetry, focusing on process and parent process relationships. - This activity is significant as it is a known tactic of the IcedID malware family, - which can lead to unauthorized code execution. If confirmed malicious, this could - allow attackers to execute arbitrary code, potentially leading to data exfiltration, - system compromise, or further malware deployment. Immediate investigation and containment - are recommended. +description: The following analytic has been deprecated. The following analytic detects + any Windows Office Product spawning `rundll32.exe` without a `.dll` file extension. + This behavior is identified using Endpoint Detection and Response (EDR) telemetry, + focusing on process and parent process relationships. This activity is significant + as it is a known tactic of the IcedID malware family, which can lead to unauthorized + code execution. If confirmed malicious, this could allow attackers to execute arbitrary + code, potentially leading to data exfiltration, system compromise, or further malware + deployment. Immediate investigation and containment are recommended. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/office_product_spawning_windows_script_host.yml b/detections/deprecated/office_product_spawning_windows_script_host.yml index 20ee47bc5c..d6bfcc6025 100644 --- a/detections/deprecated/office_product_spawning_windows_script_host.yml +++ b/detections/deprecated/office_product_spawning_windows_script_host.yml @@ -4,15 +4,23 @@ version: 10 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". - The following analytic detects an Office product spawning WScript.exe - or CScript.exe. It leverages data from Endpoint Detection and Response (EDR) agents, - focusing on process creation events where Office applications are the parent processes. - This activity is significant because it may indicate the execution of potentially - malicious scripts through Office products, a common tactic in phishing attacks and - malware delivery. If confirmed malicious, this behavior could lead to unauthorized - code execution, data exfiltration, or further system compromise. +description: The following analytic has been deprecated in favour of a more generic + approach in "Windows Office Product Spawned Uncommon Process". The following analytic + detects an Office product spawning WScript.exe or CScript.exe. It leverages data + from Endpoint Detection and Response (EDR) agents, focusing on process creation + events where Office applications are the parent processes. This activity is significant + because it may indicate the execution of potentially malicious scripts through Office + products, a common tactic in phishing attacks and malware delivery. If confirmed + malicious, this behavior could lead to unauthorized code execution, data exfiltration, + or further system compromise. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 @@ -84,6 +92,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/deprecated/office_product_spawning_wmic.yml b/detections/deprecated/office_product_spawning_wmic.yml index 6360ea5c4e..c60f305eb0 100644 --- a/detections/deprecated/office_product_spawning_wmic.yml +++ b/detections/deprecated/office_product_spawning_wmic.yml @@ -4,16 +4,23 @@ version: 10 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". - The following analytic detects any Windows Office Product spawning `wmic.exe`, - specifically when the command-line of `wmic.exe` contains `wmic process call create`. - This behavior is identified using data from Endpoint Detection and Response (EDR) - agents, focusing on process and parent process relationships. This activity is significant - as it is commonly associated with the Ursnif malware family, indicating potential - malicious activity. If confirmed malicious, this could allow an attacker to execute - arbitrary commands, leading to further system compromise, data exfiltration, or - lateral movement within the network. +description: The following analytic has been deprecated in favour of a more generic + approach in "Windows Office Product Spawned Uncommon Process". The following analytic + detects any Windows Office Product spawning `wmic.exe`, specifically when the command-line + of `wmic.exe` contains `wmic process call create`. This behavior is identified using + data from Endpoint Detection and Response (EDR) agents, focusing on process and + parent process relationships. This activity is significant as it is commonly associated + with the Ursnif malware family, indicating potential malicious activity. If confirmed + malicious, this could allow an attacker to execute arbitrary commands, leading to + further system compromise, data exfiltration, or lateral movement within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 @@ -82,6 +89,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/deprecated/office_product_writing_cab_or_inf.yml b/detections/deprecated/office_product_writing_cab_or_inf.yml index dbea8b4ac3..cb9aafc883 100644 --- a/detections/deprecated/office_product_writing_cab_or_inf.yml +++ b/detections/deprecated/office_product_writing_cab_or_inf.yml @@ -4,15 +4,22 @@ version: 10 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Dropped Cab or Inf File type: TTP -description: The following analytic has been deprecated. - The following analytic detects Office products writing .cab or .inf files, - indicative of CVE-2021-40444 exploitation. It leverages the Endpoint.Processes and - Endpoint.Filesystem data models to identify Office applications creating these file - types. This activity is significant as it may signal an attempt to load malicious - ActiveX controls and download remote payloads, a known attack vector. If confirmed - malicious, this could lead to remote code execution, allowing attackers to gain - control over the affected system and potentially compromise sensitive data. +description: The following analytic has been deprecated. The following analytic detects + Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation. + It leverages the Endpoint.Processes and Endpoint.Filesystem data models to identify + Office applications creating these file types. This activity is significant as it + may signal an attempt to load malicious ActiveX controls and download remote payloads, + a known attack vector. If confirmed malicious, this could lead to remote code execution, + allowing attackers to gain control over the affected system and potentially compromise + sensitive data. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/office_spawning_control.yml b/detections/deprecated/office_spawning_control.yml index ac4c987bc2..389aa5d867 100644 --- a/detections/deprecated/office_spawning_control.yml +++ b/detections/deprecated/office_spawning_control.yml @@ -4,16 +4,22 @@ version: 10 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned Control type: TTP -description: The following analytic has been deprecated. - The following analytic identifies instances where `control.exe` is spawned - by a Microsoft Office product. It leverages data from Endpoint Detection and Response - (EDR) agents, focusing on process and parent process relationships. This activity - is significant because it can indicate exploitation attempts related to CVE-2021-40444, - where `control.exe` is used to execute malicious .cpl or .inf files. If confirmed - malicious, this behavior could allow an attacker to execute arbitrary code, potentially - leading to system compromise, data exfiltration, or further lateral movement within - the network. +description: The following analytic has been deprecated. The following analytic identifies + instances where `control.exe` is spawned by a Microsoft Office product. It leverages + data from Endpoint Detection and Response (EDR) agents, focusing on process and + parent process relationships. This activity is significant because it can indicate + exploitation attempts related to CVE-2021-40444, where `control.exe` is used to + execute malicious .cpl or .inf files. If confirmed malicious, this behavior could + allow an attacker to execute arbitrary code, potentially leading to system compromise, + data exfiltration, or further lateral movement within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/okta_account_locked_out.yml b/detections/deprecated/okta_account_locked_out.yml index 0ad8243973..0b1df607ad 100644 --- a/detections/deprecated/okta_account_locked_out.yml +++ b/detections/deprecated/okta_account_locked_out.yml @@ -4,6 +4,14 @@ version: 3 date: '2024-11-14' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Accounts Locked Out type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Accounts Locked Out`. The following analytic utilizes the user.acount.lock diff --git a/detections/deprecated/okta_account_lockout_events.yml b/detections/deprecated/okta_account_lockout_events.yml index 07f8d09a9d..4049ec139c 100644 --- a/detections/deprecated/okta_account_lockout_events.yml +++ b/detections/deprecated/okta_account_lockout_events.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Michael Haag, Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Accounts Locked Out type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Accounts Locked Out`. The following anomaly will generate based diff --git a/detections/deprecated/okta_failed_sso_attempts.yml b/detections/deprecated/okta_failed_sso_attempts.yml index 6516d32c67..cd83cc1cb9 100644 --- a/detections/deprecated/okta_failed_sso_attempts.yml +++ b/detections/deprecated/okta_failed_sso_attempts.yml @@ -4,6 +4,14 @@ version: 5 date: '2024-11-14' author: Michael Haag, Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Unauthorized Access to Application type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with this detection `Okta Unauthorized Access to Application - DM`. The following diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml index 1f87cc42bf..018e6ec446 100644 --- a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml +++ b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml @@ -5,6 +5,12 @@ date: '2024-11-14' author: Okta, Inc, Michael Haag, Splunk type: TTP status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] data_source: [] description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml index 478b4895a1..e686982f42 100644 --- a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml +++ b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml @@ -5,6 +5,14 @@ date: '2024-11-14' author: Okta, Inc, Michael Haag, Splunk type: TTP status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta ThreatInsight Threat Detected data_source: [] description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas diff --git a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml b/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml index 9817b5f845..971408a38b 100644 --- a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml +++ b/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml @@ -4,6 +4,14 @@ version: 4 date: '2024-11-14' author: Michael Haag, Marissa Bower, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Failed MFA Requests For User type: TTP description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Failed MFA Requests For User`. The following analytic identifies diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/detections/deprecated/osquery_pack___coldroot_detection.yml index 3ba9866bed..8c0a454e3c 100644 --- a/detections/deprecated/osquery_pack___coldroot_detection.yml +++ b/detections/deprecated/osquery_pack___coldroot_detection.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: This search looks for ColdRoot events from the osx-attacks osquery pack. data_source: [] diff --git a/detections/deprecated/password_policy_discovery_with_net.yml b/detections/deprecated/password_policy_discovery_with_net.yml index 0656e661c8..89def529b1 100644 --- a/detections/deprecated/password_policy_discovery_with_net.yml +++ b/detections/deprecated/password_policy_discovery_with_net.yml @@ -4,17 +4,23 @@ version: 7 date: '2025-01-24' author: Teoderick Contreras, Mauricio Velazco, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Password Policy Discovery with Net type: Hunting -description: The following analytic has been deprecated. - The following analytic identifies the execution of `net.exe` or `net1.exe` - with command line arguments aimed at obtaining the domain password policy. It leverages - data from Endpoint Detection and Response (EDR) agents, focusing on process names - and command-line executions. This activity is significant as it indicates potential - reconnaissance efforts by adversaries to gather information about Active Directory - password policies. If confirmed malicious, this behavior could allow attackers to - understand password complexity requirements, aiding in brute-force or password-guessing - attacks, ultimately compromising user accounts and gaining unauthorized access to - the network. +description: The following analytic has been deprecated. The following analytic identifies + the execution of `net.exe` or `net1.exe` with command line arguments aimed at obtaining + the domain password policy. It leverages data from Endpoint Detection and Response + (EDR) agents, focusing on process names and command-line executions. This activity + is significant as it indicates potential reconnaissance efforts by adversaries to + gather information about Active Directory password policies. If confirmed malicious, + this behavior could allow attackers to understand password complexity requirements, + aiding in brute-force or password-guessing attacks, ultimately compromising user + accounts and gaining unauthorized access to the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/processes_created_by_netsh.yml b/detections/deprecated/processes_created_by_netsh.yml index cb947299d8..c82728a2d9 100644 --- a/detections/deprecated/processes_created_by_netsh.yml +++ b/detections/deprecated/processes_created_by_netsh.yml @@ -4,6 +4,13 @@ version: 8 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Updated to a new detection name + replacement_content: + - Processes launching netsh type: TTP description: This search looks for processes launching netsh.exe to execute various commands via the netsh command-line utility. Netsh.exe is a command-line scripting diff --git a/detections/deprecated/prohibited_software_on_endpoint.yml b/detections/deprecated/prohibited_software_on_endpoint.yml index 243c1c8374..86593fcbf9 100644 --- a/detections/deprecated/prohibited_software_on_endpoint.yml +++ b/detections/deprecated/prohibited_software_on_endpoint.yml @@ -4,6 +4,13 @@ version: 5 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Attacker Tools On Endpoint type: Hunting description: This search looks for applications on the endpoint that you have marked as prohibited. diff --git a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml index b003f3bd58..6947837938 100644 --- a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml +++ b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml @@ -4,6 +4,13 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '- ' type: TTP description: The search looks for command-line arguments used to hide a file or directory using the reg add command. diff --git a/detections/deprecated/remote_registry_key_modifications.yml b/detections/deprecated/remote_registry_key_modifications.yml index 71f902a8ad..4a417c4fa6 100644 --- a/detections/deprecated/remote_registry_key_modifications.yml +++ b/detections/deprecated/remote_registry_key_modifications.yml @@ -4,6 +4,12 @@ version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: This search monitors for remote modifications to registry keys. data_source: diff --git a/detections/deprecated/remote_system_discovery_with_net.yml b/detections/deprecated/remote_system_discovery_with_net.yml index 2377264b52..8b19a36706 100644 --- a/detections/deprecated/remote_system_discovery_with_net.yml +++ b/detections/deprecated/remote_system_discovery_with_net.yml @@ -4,14 +4,43 @@ version: 5 date: '2025-01-13' author: Mauricio Velazco, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Sensitive Group Discovery With Net type: Hunting -description: The following analytic has been deprecated in favour of two dedicated analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" .The following analytic identifies the execution of `net.exe` or `net1.exe` with command-line arguments used to discover remote systems, such as `domain computers /domain`. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries or Red Teams to map out networked systems and Active Directory structures. If confirmed malicious, this behavior could lead to further network exploitation, privilege escalation, or lateral movement within the environment. +description: The following analytic has been deprecated in favour of two dedicated + analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" + .The following analytic identifies the execution of `net.exe` or `net1.exe` with + command-line arguments used to discover remote systems, such as `domain computers + /domain`. This detection leverages data from Endpoint Detection and Response (EDR) + agents, focusing on process names and command-line arguments. This activity is significant + as it indicates potential reconnaissance efforts by adversaries or Red Teams to + map out networked systems and Active Directory structures. If confirmed malicious, + this behavior could lead to further network exploitation, privilege escalation, + or lateral movement within the environment. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*domain computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `remote_system_discovery_with_net_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*domain + computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*) + by Processes.dest Processes.user Processes.parent_process Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `remote_system_discovery_with_net_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: Administrators or power users may use this command for troubleshooting. references: - https://attack.mitre.org/techniques/T1018/ @@ -31,6 +60,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml index 0197ba45a3..d3d1e1b499 100644 --- a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml +++ b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml @@ -4,6 +4,13 @@ version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Updated to a new detection name + replacement_content: + - Scheduled Task Deleted Or Created via CMD type: TTP description: This search looks for flags passed to schtasks.exe on the command-line that indicate that task names related to the execution of Bad Rabbit ransomware diff --git a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml index 1f4a043402..c894e4fa3a 100644 --- a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml +++ b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: The search is used to detect systems that are still vulnerable to the Spectre and Meltdown vulnerabilities. diff --git a/detections/deprecated/suspicious_changes_to_file_associations.yml b/detections/deprecated/suspicious_changes_to_file_associations.yml index e9438be5a1..f1c5eb5d31 100644 --- a/detections/deprecated/suspicious_changes_to_file_associations.yml +++ b/detections/deprecated/suspicious_changes_to_file_associations.yml @@ -4,6 +4,12 @@ version: 7 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: This search looks for changes to registry values that control Windows file associations, executed by a process that is not typical for legitimate, routine diff --git a/detections/deprecated/suspicious_email___uba_anomaly.yml b/detections/deprecated/suspicious_email___uba_anomaly.yml index 0e3a3f31d6..0b77fd20a8 100644 --- a/detections/deprecated/suspicious_email___uba_anomaly.yml +++ b/detections/deprecated/suspicious_email___uba_anomaly.yml @@ -4,6 +4,12 @@ version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Anomaly description: This detection looks for emails that are suspicious because of their sender, domain rareness, or behavior differences. This is an anomaly generated by diff --git a/detections/deprecated/suspicious_file_write.yml b/detections/deprecated/suspicious_file_write.yml index 8630632e57..ce7ce09da0 100644 --- a/detections/deprecated/suspicious_file_write.yml +++ b/detections/deprecated/suspicious_file_write.yml @@ -4,6 +4,13 @@ version: 6 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '' type: Hunting description: The search looks for files created with names that have been linked to malicious activity. diff --git a/detections/deprecated/suspicious_powershell_command_line_arguments.yml b/detections/deprecated/suspicious_powershell_command_line_arguments.yml index b2efc4ee51..a6c19ed8d7 100644 --- a/detections/deprecated/suspicious_powershell_command_line_arguments.yml +++ b/detections/deprecated/suspicious_powershell_command_line_arguments.yml @@ -4,6 +4,13 @@ version: 9 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Malicious PowerShell Process - Encoded Command type: TTP description: This search looks for PowerShell processes started with a base64 encoded command-line passed to it, with parameters to modify the execution policy for the diff --git a/detections/deprecated/suspicious_rundll32_rename.yml b/detections/deprecated/suspicious_rundll32_rename.yml index 48fdc6b2d5..eff58f4873 100644 --- a/detections/deprecated/suspicious_rundll32_rename.yml +++ b/detections/deprecated/suspicious_rundll32_rename.yml @@ -4,6 +4,12 @@ version: 7 date: '2024-11-14' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Hunting description: The following hunting analytic identifies renamed instances of rundll32.exe executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. diff --git a/detections/deprecated/suspicious_writes_to_system_volume_information.yml b/detections/deprecated/suspicious_writes_to_system_volume_information.yml index 866160575b..cc6e0fa6ae 100644 --- a/detections/deprecated/suspicious_writes_to_system_volume_information.yml +++ b/detections/deprecated/suspicious_writes_to_system_volume_information.yml @@ -4,6 +4,12 @@ version: 5 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Hunting description: This search detects writes to the 'System Volume Information' folder by something other than the System process. diff --git a/detections/deprecated/uncommon_processes_on_endpoint.yml b/detections/deprecated/uncommon_processes_on_endpoint.yml index e0378b0e1f..4c90b29fdc 100644 --- a/detections/deprecated/uncommon_processes_on_endpoint.yml +++ b/detections/deprecated/uncommon_processes_on_endpoint.yml @@ -4,6 +4,13 @@ version: 7 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Attacker Tools On Endpoint type: Hunting description: This search looks for applications on the endpoint that you have marked as uncommon. diff --git a/detections/deprecated/unsigned_image_loaded_by_lsass.yml b/detections/deprecated/unsigned_image_loaded_by_lsass.yml index db021a2bf3..38f74b6f6d 100644 --- a/detections/deprecated/unsigned_image_loaded_by_lsass.yml +++ b/detections/deprecated/unsigned_image_loaded_by_lsass.yml @@ -4,6 +4,13 @@ version: 4 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - '' type: TTP description: This search detects loading of unsigned images by LSASS. Deprecated because too noisy. diff --git a/detections/deprecated/unsuccessful_netbackup_backups.yml b/detections/deprecated/unsuccessful_netbackup_backups.yml index 3e8fc0b5af..feafa5361e 100644 --- a/detections/deprecated/unsuccessful_netbackup_backups.yml +++ b/detections/deprecated/unsuccessful_netbackup_backups.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Hunting description: This search gives you the hosts where a backup was attempted and then failed. diff --git a/detections/deprecated/web_fraud___account_harvesting.yml b/detections/deprecated/web_fraud___account_harvesting.yml index 4fb3b3b784..17f3be4b4f 100644 --- a/detections/deprecated/web_fraud___account_harvesting.yml +++ b/detections/deprecated/web_fraud___account_harvesting.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: Jim Apger, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: This search is used to identify the creation of multiple user accounts using the same email domain name. diff --git a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml index 518a5be28e..69a013dabf 100644 --- a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml +++ b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: Jim Apger, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Anomaly description: This search is used to examine web sessions to identify those where the clicks are occurring too quickly for a human or are occurring with a near-perfect diff --git a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml index 48c9b3908c..0fe79ab5ff 100644 --- a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml +++ b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: Jim Apger, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: Anomaly description: This search is used to identify user accounts that share a common password. data_source: [] diff --git a/detections/deprecated/windows_command_shell_fetch_env_variables.yml b/detections/deprecated/windows_command_shell_fetch_env_variables.yml index 90618ba3e5..80ddcb7db1 100644 --- a/detections/deprecated/windows_command_shell_fetch_env_variables.yml +++ b/detections/deprecated/windows_command_shell_fetch_env_variables.yml @@ -4,16 +4,22 @@ version: 5 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows List ENV Variables Via SET Command From Uncommon Parent type: TTP -description: The following analytic has been deprecated. - The following analytic identifies a suspicious process command line fetching - environment variables with a non-shell parent process. It leverages data from Endpoint - Detection and Response (EDR) agents, focusing on command-line executions and parent - process names. This activity is significant as it is commonly associated with malware - like Qakbot, which uses this technique to gather system information. If confirmed - malicious, this behavior could indicate that the parent process has been compromised, - potentially allowing attackers to execute arbitrary commands, escalate privileges, - or persist within the environment. +description: The following analytic has been deprecated. The following analytic identifies + a suspicious process command line fetching environment variables with a non-shell + parent process. It leverages data from Endpoint Detection and Response (EDR) agents, + focusing on command-line executions and parent process names. This activity is significant + as it is commonly associated with malware like Qakbot, which uses this technique + to gather system information. If confirmed malicious, this behavior could indicate + that the parent process has been compromised, potentially allowing attackers to + execute arbitrary commands, escalate privileges, or persist within the environment. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/windows_connhost_exe_started_forcefully.yml b/detections/deprecated/windows_connhost_exe_started_forcefully.yml index 2718083864..8bb950c864 100644 --- a/detections/deprecated/windows_connhost_exe_started_forcefully.yml +++ b/detections/deprecated/windows_connhost_exe_started_forcefully.yml @@ -4,6 +4,12 @@ version: 5 date: '2024-11-14' author: Rod Soto, Jose Hernandez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: The search looks for the Console Window Host process (connhost.exe) executed using the force flag -ForceV1. This is not regular behavior in the Windows OS and diff --git a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml index 38d777ae9a..f452743951 100644 --- a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml +++ b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml @@ -4,6 +4,14 @@ version: 5 date: '2024-11-14' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Windows DLL Search Order Hijacking Hunt with Sysmon type: Hunting description: The following hunting analytic is an experimental query built against a accidental feature using the latest Sysmon TA 3.0 (https://splunkbase.splunk.com/app/5709/) diff --git a/detections/deprecated/windows_hosts_file_modification.yml b/detections/deprecated/windows_hosts_file_modification.yml index 0c7453eab3..fd6fa8ec88 100644 --- a/detections/deprecated/windows_hosts_file_modification.yml +++ b/detections/deprecated/windows_hosts_file_modification.yml @@ -4,6 +4,12 @@ version: 4 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: [] type: TTP description: The search looks for modifications to the hosts file on all Windows endpoints across your environment. diff --git a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml index 0611c1c8f6..dd1d040b65 100644 --- a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml +++ b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml @@ -5,6 +5,13 @@ date: '2024-12-10' author: Michael Haag, Splunk type: TTP status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Updated to a new detection name + replacement_content: + - Windows Service Execution RemCom data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/windows_modify_registry_reg_restore.yml b/detections/deprecated/windows_modify_registry_reg_restore.yml index f63d1b0214..324a5baed9 100644 --- a/detections/deprecated/windows_modify_registry_reg_restore.yml +++ b/detections/deprecated/windows_modify_registry_reg_restore.yml @@ -4,16 +4,23 @@ version: 5 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Registry Entries Restored Via Reg type: Hunting -description: The following analytic has been deprecated. - The following analytic detects the execution of reg.exe with the "restore" - parameter, indicating an attempt to restore registry backup data on a host. This - detection leverages data from Endpoint Detection and Response (EDR) agents, focusing - on process execution logs and command-line arguments. This activity is significant - as it may indicate post-exploitation actions, such as those performed by tools like - winpeas, which use "reg save" and "reg restore" to manipulate registry settings. - If confirmed malicious, this could allow an attacker to revert registry changes, - potentially bypassing security controls and maintaining persistence. +description: The following analytic has been deprecated. The following analytic detects + the execution of reg.exe with the "restore" parameter, indicating an attempt to + restore registry backup data on a host. This detection leverages data from Endpoint + Detection and Response (EDR) agents, focusing on process execution logs and command-line + arguments. This activity is significant as it may indicate post-exploitation actions, + such as those performed by tools like winpeas, which use "reg save" and "reg restore" + to manipulate registry settings. If confirmed malicious, this could allow an attacker + to revert registry changes, potentially bypassing security controls and maintaining + persistence. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/windows_msiexec_with_network_connections.yml b/detections/deprecated/windows_msiexec_with_network_connections.yml index 26347f6535..2331bd6952 100644 --- a/detections/deprecated/windows_msiexec_with_network_connections.yml +++ b/detections/deprecated/windows_msiexec_with_network_connections.yml @@ -4,16 +4,22 @@ version: 6 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows HTTP Network Communication From MSIExec type: TTP -description: The following analytic has been deprecated. - The following analytic detects MSIExec making network connections over - ports 443 or 80. This behavior is identified by correlating process creation events - from Endpoint Detection and Response (EDR) agents with network traffic logs. Typically, - MSIExec does not perform network communication to the internet, making this activity - unusual and potentially indicative of malicious behavior. If confirmed malicious, - an attacker could be using MSIExec to download or communicate with external servers, - potentially leading to data exfiltration, command and control (C2) communication, - or further malware deployment. +description: The following analytic has been deprecated. The following analytic detects + MSIExec making network connections over ports 443 or 80. This behavior is identified + by correlating process creation events from Endpoint Detection and Response (EDR) + agents with network traffic logs. Typically, MSIExec does not perform network communication + to the internet, making this activity unusual and potentially indicative of malicious + behavior. If confirmed malicious, an attacker could be using MSIExec to download + or communicate with external servers, potentially leading to data exfiltration, + command and control (C2) communication, or further malware deployment. data_source: - Sysmon EventID 1 AND Sysmon EventID 3 search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes diff --git a/detections/deprecated/windows_network_share_interaction_with_net.yml b/detections/deprecated/windows_network_share_interaction_with_net.yml index fea71519c1..ab7de51ef6 100644 --- a/detections/deprecated/windows_network_share_interaction_with_net.yml +++ b/detections/deprecated/windows_network_share_interaction_with_net.yml @@ -4,16 +4,23 @@ version: 6 date: '2025-01-24' author: Dean Luxton status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Network Share Interaction Via Net type: TTP data_source: - Sysmon EventID 1 -description: The following analytic has been deprecated. - This analytic detects network share discovery and collection activities - performed on Windows systems using the Net command. Attackers often use network - share discovery to identify accessible shared resources within a network, which - can be a precursor to privilege escalation or data exfiltration. By monitoring Windows - Event Logs for the usage of the Net command to list and interact with network shares, - this detection helps identify potential reconnaissance and collection activities. +description: The following analytic has been deprecated. This analytic detects network + share discovery and collection activities performed on Windows systems using the + Net command. Attackers often use network share discovery to identify accessible + shared resources within a network, which can be a precursor to privilege escalation + or data exfiltration. By monitoring Windows Event Logs for the usage of the Net + command to list and interact with network shares, this detection helps identify + potential reconnaissance and collection activities. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.user_category) as user_category values(Processes.user_bunit) as user_bunit FROM datamodel=Endpoint.Processes WHERE `process_net` BY Processes.user diff --git a/detections/deprecated/windows_office_product_spawning_msdt.yml b/detections/deprecated/windows_office_product_spawning_msdt.yml index ad36ac3325..73517da1ff 100644 --- a/detections/deprecated/windows_office_product_spawning_msdt.yml +++ b/detections/deprecated/windows_office_product_spawning_msdt.yml @@ -4,16 +4,22 @@ version: 9 date: '2025-01-24' author: Michael Haag, Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned MSDT type: TTP -description: The following analytic has been deprecated. - The following analytic detects a Microsoft Office product spawning the - Windows msdt.exe process. This detection leverages data from Endpoint Detection - and Response (EDR) agents, focusing on process creation events where Office applications - are the parent process. This activity is significant as it may indicate an attempt - to exploit protocol handlers to bypass security controls, even if macros are disabled. - If confirmed malicious, this behavior could allow an attacker to execute arbitrary - code, potentially leading to system compromise, data exfiltration, or further lateral - movement within the network. +description: The following analytic has been deprecated. The following analytic detects + a Microsoft Office product spawning the Windows msdt.exe process. This detection + leverages data from Endpoint Detection and Response (EDR) agents, focusing on process + creation events where Office applications are the parent process. This activity + is significant as it may indicate an attempt to exploit protocol handlers to bypass + security controls, even if macros are disabled. If confirmed malicious, this behavior + could allow an attacker to execute arbitrary code, potentially leading to system + compromise, data exfiltration, or further lateral movement within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 @@ -91,6 +97,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/deprecated/windows_query_registry_reg_save.yml b/detections/deprecated/windows_query_registry_reg_save.yml index 291c0cf7a0..2ef3993258 100644 --- a/detections/deprecated/windows_query_registry_reg_save.yml +++ b/detections/deprecated/windows_query_registry_reg_save.yml @@ -4,15 +4,22 @@ version: 6 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Registry Entries Exported Via Reg type: Hunting -description: The following analytic has been deprecated. - The following analytic detects the execution of the reg.exe process with - the "save" parameter. This detection leverages data from Endpoint Detection and - Response (EDR) agents, focusing on process execution logs and command-line arguments. - This activity is significant because threat actors often use the "reg save" command - to dump credentials or test registry modification capabilities on compromised hosts. - If confirmed malicious, this behavior could allow attackers to escalate privileges, - persist in the environment, or access sensitive information stored in the registry. +description: The following analytic has been deprecated. The following analytic detects + the execution of the reg.exe process with the "save" parameter. This detection leverages + data from Endpoint Detection and Response (EDR) agents, focusing on process execution + logs and command-line arguments. This activity is significant because threat actors + often use the "reg save" command to dump credentials or test registry modification + capabilities on compromised hosts. If confirmed malicious, this behavior could allow + attackers to escalate privileges, persist in the environment, or access sensitive + information stored in the registry. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/windows_valid_account_with_never_expires_password.yml b/detections/deprecated/windows_valid_account_with_never_expires_password.yml index 01b416d1d5..65421b5a51 100644 --- a/detections/deprecated/windows_valid_account_with_never_expires_password.yml +++ b/detections/deprecated/windows_valid_account_with_never_expires_password.yml @@ -4,16 +4,22 @@ version: 6 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: Renamed and updated logic + replacement_content: + - Windows Set Account Password Policy To Unlimited Via Net type: TTP -description: The following analytic has been deprecated. - The following analytic detects the use of net.exe to update user account - policies to set passwords as non-expiring. It leverages data from Endpoint Detection - and Response (EDR) agents, focusing on command-line executions involving "/maxpwage:unlimited". - This activity is significant as it can indicate an attempt to maintain persistence, - escalate privileges, evade defenses, or facilitate lateral movement. If confirmed - malicious, this behavior could allow an attacker to maintain long-term access to - compromised accounts, potentially leading to further exploitation and unauthorized - access to sensitive information. +description: The following analytic has been deprecated. The following analytic detects + the use of net.exe to update user account policies to set passwords as non-expiring. + It leverages data from Endpoint Detection and Response (EDR) agents, focusing on + command-line executions involving "/maxpwage:unlimited". This activity is significant + as it can indicate an attempt to maintain persistence, escalate privileges, evade + defenses, or facilitate lateral movement. If confirmed malicious, this behavior + could allow an attacker to maintain long-term access to compromised accounts, potentially + leading to further exploitation and unauthorized access to sensitive information. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/winword_spawning_cmd.yml b/detections/deprecated/winword_spawning_cmd.yml index 5760517a84..de643bfb78 100644 --- a/detections/deprecated/winword_spawning_cmd.yml +++ b/detections/deprecated/winword_spawning_cmd.yml @@ -4,16 +4,24 @@ version: 7 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". - The following analytic identifies instances where Microsoft Word (winword.exe) - spawns the command prompt (cmd.exe). This behavior is detected using Endpoint Detection - and Response (EDR) telemetry, focusing on process creation events where the parent - process is winword.exe. This activity is significant because it is uncommon and - often associated with spearphishing attacks, where malicious attachments execute - commands via cmd.exe. If confirmed malicious, this could allow an attacker to execute - arbitrary commands, potentially leading to further system compromise, data exfiltration, - or lateral movement within the network. +description: The following analytic has been deprecated in favour of a more generic + approach in "Windows Office Product Spawned Uncommon Process". The following analytic + identifies instances where Microsoft Word (winword.exe) spawns the command prompt + (cmd.exe). This behavior is detected using Endpoint Detection and Response (EDR) + telemetry, focusing on process creation events where the parent process is winword.exe. + This activity is significant because it is uncommon and often associated with spearphishing + attacks, where malicious attachments execute commands via cmd.exe. If confirmed + malicious, this could allow an attacker to execute arbitrary commands, potentially + leading to further system compromise, data exfiltration, or lateral movement within + the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 @@ -82,6 +90,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/deprecated/winword_spawning_powershell.yml b/detections/deprecated/winword_spawning_powershell.yml index b2e102dc75..74a7ae6560 100644 --- a/detections/deprecated/winword_spawning_powershell.yml +++ b/detections/deprecated/winword_spawning_powershell.yml @@ -4,16 +4,24 @@ version: 7 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". - The following analytic identifies instances where Microsoft Word (winword.exe) - spawns a PowerShell process. This behavior is detected using Endpoint Detection - and Response (EDR) telemetry, focusing on process creation events where the parent - process is winword.exe. This activity is significant because it is uncommon and - often associated with spearphishing attacks, where malicious documents execute encoded - PowerShell commands. If confirmed malicious, this could allow an attacker to execute - arbitrary code, potentially leading to data exfiltration, system compromise, or - further lateral movement within the network. +description: The following analytic has been deprecated in favour of a more generic + approach in "Windows Office Product Spawned Uncommon Process". The following analytic + identifies instances where Microsoft Word (winword.exe) spawns a PowerShell process. + This behavior is detected using Endpoint Detection and Response (EDR) telemetry, + focusing on process creation events where the parent process is winword.exe. This + activity is significant because it is uncommon and often associated with spearphishing + attacks, where malicious documents execute encoded PowerShell commands. If confirmed + malicious, this could allow an attacker to execute arbitrary code, potentially leading + to data exfiltration, system compromise, or further lateral movement within the + network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 @@ -85,6 +93,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/deprecated/winword_spawning_windows_script_host.yml b/detections/deprecated/winword_spawning_windows_script_host.yml index 16ee7d84c1..606abeabb3 100644 --- a/detections/deprecated/winword_spawning_windows_script_host.yml +++ b/detections/deprecated/winword_spawning_windows_script_host.yml @@ -4,9 +4,19 @@ version: 6 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated +deprecation_info: + deprecation_date: '2025-02-26' + deprecation_version: 5.2.0 + content_type: detection + reason: "The following analytics was deprecated in favour of a more generic approach. + Where instead of creating specific analytic for every potentially suspicious child + of an office product. We group them by threat level.\nThis would ease management + and false positives tuning." + replacement_content: + - Windows Office Product Spawned Uncommon Process type: TTP -description: The following analytic has been deprecated in favour of a more generic approach. - The following analytic identifies instances where Microsoft Winword.exe +description: The following analytic has been deprecated in favour of a more generic + approach. The following analytic identifies instances where Microsoft Winword.exe spawns Windows Script Host processes (cscript.exe or wscript.exe). This behavior is detected using Endpoint Detection and Response (EDR) telemetry, focusing on process creation events where the parent process is Winword.exe. This activity is significant @@ -80,6 +90,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_wsh.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_wsh.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog From ebc1d84058f5366480fd7719f70d37b8b099eca8 Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Fri, 14 Feb 2025 10:10:20 -0800 Subject: [PATCH 07/67] remove the deprecation_info section that was previously added to detections --- .../abnormally_high_aws_instances_launched_by_user.yml | 8 -------- ...ally_high_aws_instances_launched_by_user___mltk.yml | 6 ------ ...bnormally_high_aws_instances_terminated_by_user.yml | 8 -------- ...ly_high_aws_instances_terminated_by_user___mltk.yml | 6 ------ .../deprecated/account_discovery_with_net_app.yml | 10 ---------- detections/deprecated/asl_aws_createaccesskey.yml | 8 -------- .../deprecated/asl_aws_excessive_security_scanning.yml | 6 ------ .../deprecated/asl_aws_password_policy_changes.yml | 6 ------ .../deprecated/attempt_to_stop_security_service.yml | 7 ------- ...mpted_credential_dump_from_registry_via_reg_exe.yml | 9 --------- ..._cloud_provisioning_from_previously_unseen_city.yml | 8 -------- ...oud_provisioning_from_previously_unseen_country.yml | 8 -------- ..._provisioning_from_previously_unseen_ip_address.yml | 8 -------- ...loud_provisioning_from_previously_unseen_region.yml | 8 -------- ..._eks_kubernetes_cluster_sensitive_object_access.yml | 8 -------- .../deprecated/change_default_file_association.yml | 7 ------- .../clients_connecting_to_multiple_dns_servers.yml | 6 ------ .../cloud_network_access_control_list_deleted.yml | 8 -------- .../cmdline_tool_not_executed_in_cmd_shell.yml | 7 ------- .../deprecated/correlation_by_repository_and_risk.yml | 7 ------- detections/deprecated/correlation_by_user_and_risk.yml | 7 ------- .../create_local_admin_accounts_using_net_exe.yml | 7 ------- detections/deprecated/deleting_of_net_users.yml | 7 ------- ...etect_activity_related_to_pass_the_hash_attacks.yml | 6 ------ .../detect_api_activity_from_users_without_mfa.yml | 8 -------- ...ect_aws_api_activities_from_unapproved_accounts.yml | 6 ------ .../detect_critical_alerts_from_security_tools.yml | 7 ------- ...requests_to_phishing_sites_leveraging_evilginx2.yml | 6 ------ .../deprecated/detect_long_dns_txt_record_response.yml | 6 ------ .../deprecated/detect_mimikatz_using_loaded_images.yml | 6 ------ ...tect_mimikatz_via_powershell_and_eventcode_4703.yml | 7 ------- .../detect_new_api_calls_from_user_roles.yml | 8 -------- .../deprecated/detect_new_user_aws_console_login.yml | 8 -------- ...used_for_system_network_configuration_discovery.yml | 7 ------- .../deprecated/detect_spike_in_aws_api_activity.yml | 7 ------- .../detect_spike_in_network_acl_activity.yml | 8 -------- .../detect_spike_in_security_group_activity.yml | 8 -------- detections/deprecated/detect_usb_device_insertion.yml | 6 ------ .../detect_web_traffic_to_dynamic_domain_providers.yml | 7 ------- .../deprecated/detect_webshell_exploit_behavior.yml | 7 ------- detections/deprecated/detection_of_dns_tunnels.yml | 6 ------ detections/deprecated/disabling_net_user_account.yml | 7 ------- ...y_requests_resolved_by_unauthorized_dns_servers.yml | 6 ------ detections/deprecated/dns_record_changed.yml | 6 ------ .../domain_account_discovery_with_net_app.yml | 10 ---------- .../deprecated/domain_group_discovery_with_net.yml | 7 ------- .../deprecated/dump_lsass_via_procdump_rename.yml | 7 ------- ...2_instance_modified_with_previously_unseen_user.yml | 8 -------- ...c2_instance_started_in_previously_unseen_region.yml | 8 -------- ...ec2_instance_started_with_previously_unseen_ami.yml | 8 -------- ...ce_started_with_previously_unseen_instance_type.yml | 8 -------- ...c2_instance_started_with_previously_unseen_user.yml | 8 -------- .../deprecated/elevated_group_discovery_with_net.yml | 7 ------- detections/deprecated/excel_spawning_powershell.yml | 7 ------- .../deprecated/excessive_service_stop_attempt.yml | 7 ------- detections/deprecated/excessive_usage_of_net_app.yml | 7 ------- .../execution_of_file_with_spaces_before_extension.yml | 7 ------- ...ded_period_without_successful_netbackup_backups.yml | 6 ------ detections/deprecated/extraction_of_registry_hives.yml | 7 ------- .../first_time_seen_command_line_argument.yml | 7 ------- ...detect_accounts_with_high_risk_roles_by_project.yml | 6 ------ ...t_high_risk_permissions_by_resource_and_account.yml | 6 ------ detections/deprecated/gcp_detect_oauth_token_abuse.yml | 6 ------ .../gcp_kubernetes_cluster_scan_detection.yml | 8 -------- detections/deprecated/identify_new_user_accounts.yml | 7 ------- ..._aws_detect_most_active_service_accounts_by_pod.yml | 7 ------- ...rnetes_aws_detect_rbac_authorization_by_account.yml | 7 ------- .../kubernetes_aws_detect_sensitive_role_access.yml | 7 ------- ...etect_service_accounts_forbidden_failure_access.yml | 7 ------- ..._azure_active_service_accounts_by_pod_namespace.yml | 7 ------- ...etes_azure_detect_rbac_authorization_by_account.yml | 7 ------- ...kubernetes_azure_detect_sensitive_object_access.yml | 7 ------- .../kubernetes_azure_detect_sensitive_role_access.yml | 7 ------- ...etect_service_accounts_forbidden_failure_access.yml | 7 ------- ...ubernetes_azure_detect_suspicious_kubectl_calls.yml | 7 ------- .../kubernetes_azure_pod_scan_fingerprint.yml | 7 ------- .../deprecated/kubernetes_azure_scan_fingerprint.yml | 7 ------- ..._gcp_detect_most_active_service_accounts_by_pod.yml | 7 ------- ...netes_gcp_detect_rbac_authorizations_by_account.yml | 7 ------- .../kubernetes_gcp_detect_sensitive_object_access.yml | 7 ------- .../kubernetes_gcp_detect_sensitive_role_access.yml | 7 ------- ...etect_service_accounts_forbidden_failure_access.yml | 7 ------- .../kubernetes_gcp_detect_suspicious_kubectl_calls.yml | 7 ------- .../deprecated/linux_auditd_find_private_keys.yml | 7 ------- .../deprecated/local_account_discovery_with_net.yml | 7 ------- detections/deprecated/monitor_dns_for_brand_abuse.yml | 7 ------- .../mshtml_module_load_in_office_product.yml | 7 ------- ...users_with_invalid_credentials_from_the_same_ip.yml | 8 -------- detections/deprecated/net_localgroup_discovery.yml | 8 -------- .../network_connection_discovery_with_net.yml | 7 ------- .../o365_suspicious_admin_email_forwarding.yml | 8 -------- .../deprecated/o365_suspicious_rights_delegation.yml | 8 -------- .../o365_suspicious_user_email_forwarding.yml | 8 -------- .../deprecated/office_application_drop_executable.yml | 7 ------- .../office_application_spawn_regsvr32_process.yml | 7 ------- .../office_application_spawn_rundll32_process.yml | 7 ------- .../office_document_creating_schedule_task.yml | 7 ------- .../office_document_executing_macro_code.yml | 7 ------- ...fice_document_spawned_child_process_to_download.yml | 7 ------- .../deprecated/office_product_spawn_cmd_process.yml | 7 ------- .../deprecated/office_product_spawning_bitsadmin.yml | 7 ------- .../deprecated/office_product_spawning_certutil.yml | 7 ------- .../deprecated/office_product_spawning_mshta.yml | 7 ------- .../office_product_spawning_rundll32_with_no_dll.yml | 7 ------- .../office_product_spawning_windows_script_host.yml | 7 ------- detections/deprecated/office_product_spawning_wmic.yml | 7 ------- .../deprecated/office_product_writing_cab_or_inf.yml | 7 ------- detections/deprecated/office_spawning_control.yml | 7 ------- detections/deprecated/okta_account_locked_out.yml | 8 -------- detections/deprecated/okta_account_lockout_events.yml | 8 -------- detections/deprecated/okta_failed_sso_attempts.yml | 8 -------- ...atinsight_login_failure_with_high_unknown_users.yml | 6 ------ ...ta_threatinsight_suspected_passwordspray_attack.yml | 8 -------- .../okta_two_or_more_rejected_okta_pushes.yml | 8 -------- .../deprecated/osquery_pack___coldroot_detection.yml | 6 ------ .../deprecated/password_policy_discovery_with_net.yml | 7 ------- detections/deprecated/processes_created_by_netsh.yml | 7 ------- .../deprecated/prohibited_software_on_endpoint.yml | 7 ------- ...sed_to_hide_files_directories_via_registry_keys.yml | 7 ------- .../deprecated/remote_registry_key_modifications.yml | 6 ------ .../deprecated/remote_system_discovery_with_net.yml | 7 ------- .../scheduled_tasks_used_in_badrabbit_ransomware.yml | 7 ------- .../spectre_and_meltdown_vulnerable_systems.yml | 6 ------ .../suspicious_changes_to_file_associations.yml | 6 ------ .../deprecated/suspicious_email___uba_anomaly.yml | 6 ------ detections/deprecated/suspicious_file_write.yml | 7 ------- .../suspicious_powershell_command_line_arguments.yml | 7 ------- detections/deprecated/suspicious_rundll32_rename.yml | 6 ------ .../suspicious_writes_to_system_volume_information.yml | 6 ------ .../deprecated/uncommon_processes_on_endpoint.yml | 7 ------- .../deprecated/unsigned_image_loaded_by_lsass.yml | 7 ------- .../deprecated/unsuccessful_netbackup_backups.yml | 6 ------ .../deprecated/web_fraud___account_harvesting.yml | 6 ------ .../web_fraud___anomalous_user_clickspeed.yml | 6 ------ .../web_fraud___password_sharing_across_accounts.yml | 6 ------ .../windows_command_shell_fetch_env_variables.yml | 7 ------- .../windows_connhost_exe_started_forcefully.yml | 6 ------ .../windows_dll_search_order_hijacking_hunt.yml | 8 -------- .../deprecated/windows_hosts_file_modification.yml | 6 ------ .../windows_lateral_tool_transfer_remcom.yml | 7 ------- .../deprecated/windows_modify_registry_reg_restore.yml | 7 ------- .../windows_msiexec_with_network_connections.yml | 7 ------- .../windows_network_share_interaction_with_net.yml | 7 ------- .../windows_office_product_spawning_msdt.yml | 7 ------- .../deprecated/windows_query_registry_reg_save.yml | 7 ------- ...ndows_valid_account_with_never_expires_password.yml | 7 ------- detections/deprecated/winword_spawning_cmd.yml | 7 ------- detections/deprecated/winword_spawning_powershell.yml | 7 ------- .../winword_spawning_windows_script_host.yml | 10 ---------- 149 files changed, 1053 deletions(-) diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml index a84ac20e7c..e46dec6369 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml @@ -4,14 +4,6 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Abnormally High Number Of Cloud Instances Launched type: Anomaly description: This search looks for AWS CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml index 8279df5c30..9acc4411b2 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml @@ -4,12 +4,6 @@ version: 5 date: '2024-11-14' author: Jason Brewer, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Anomaly description: This search looks for AWS CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml index f028df1a26..ae3c15024b 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml @@ -4,14 +4,6 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Abnormally High Number Of Cloud Instances Destroyed type: Anomaly description: This search looks for AWS CloudTrail events where an abnormally high number of instances were successfully terminated by a user in a 10-minute window. diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml index adcfe17ca3..04f88a704a 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml @@ -4,12 +4,6 @@ version: 5 date: '2024-11-14' author: Jason Brewer, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Anomaly description: This search looks for AWS CloudTrail events where a user successfully terminates an abnormally high number of instances. This search is deprecated and diff --git a/detections/deprecated/account_discovery_with_net_app.yml b/detections/deprecated/account_discovery_with_net_app.yml index 323489ac89..bf2568a3f0 100644 --- a/detections/deprecated/account_discovery_with_net_app.yml +++ b/detections/deprecated/account_discovery_with_net_app.yml @@ -4,16 +4,6 @@ version: 8 date: '2025-01-13' author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: This analytic was a TTP that focused on unrelated things and called account - discovery. Since there were other detection that overlapped with it. I choose - to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 - / Windows Excessive Usage Of Net App. - replacement_content: - - Windows Excessive Usage Of Net App type: TTP description: The following analytic has been deprecated in favour of the more generic "45e52536-ae42-11eb-b5c6-acde48001122". The following analytic detects potential diff --git a/detections/deprecated/asl_aws_createaccesskey.yml b/detections/deprecated/asl_aws_createaccesskey.yml index 33967e66c7..e7588388f6 100644 --- a/detections/deprecated/asl_aws_createaccesskey.yml +++ b/detections/deprecated/asl_aws_createaccesskey.yml @@ -4,14 +4,6 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - ASL AWS Create Access Key type: Hunting description: This detection rule monitors for the creation of AWS Identity and Access Management (IAM) access keys. An IAM access key consists of an access key ID and diff --git a/detections/deprecated/asl_aws_excessive_security_scanning.yml b/detections/deprecated/asl_aws_excessive_security_scanning.yml index 483db858df..0ee3a463e3 100644 --- a/detections/deprecated/asl_aws_excessive_security_scanning.yml +++ b/detections/deprecated/asl_aws_excessive_security_scanning.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Anomaly description: This search looks for AWS CloudTrail events and analyse the amount of eventNames which starts with Describe by a single user. This indicates that this diff --git a/detections/deprecated/asl_aws_password_policy_changes.yml b/detections/deprecated/asl_aws_password_policy_changes.yml index 6ee31b185c..d791f17208 100644 --- a/detections/deprecated/asl_aws_password_policy_changes.yml +++ b/detections/deprecated/asl_aws_password_policy_changes.yml @@ -4,12 +4,6 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Hunting description: This search looks for AWS CloudTrail events from Amazon Security Lake where a user is making successful API calls to view/update/delete the existing password diff --git a/detections/deprecated/attempt_to_stop_security_service.yml b/detections/deprecated/attempt_to_stop_security_service.yml index 864f401149..09f69ad572 100644 --- a/detections/deprecated/attempt_to_stop_security_service.yml +++ b/detections/deprecated/attempt_to_stop_security_service.yml @@ -4,13 +4,6 @@ version: 9 date: '2025-01-24' author: Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Attempt To Stop Security Service type: TTP description: The following analytic has been deprecated. The following analytic detects attempts to stop security-related services on an endpoint, which may indicate malicious diff --git a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml index 60166bd1f3..38fdbf95b5 100644 --- a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -4,15 +4,6 @@ version: 12 date: '2025-01-15' author: Patrick Bareiss, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: This analytic had some overlap with another one, hence the deprecation. - It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry - Hive Dump Via CommandLine - replacement_content: - - Windows Sensitive Registry Hive Dump Via CommandLine type: TTP description: The following analytic has been deprecated in favour of "8bbb7d58-b360-11eb-ba21-acde48001122". The following analytic detects the execution of reg.exe with parameters that export diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml index 6b328e1c99..d59e586b5a 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml @@ -4,14 +4,6 @@ version: 5 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Provisioning Activity From Previously Unseen City type: Anomaly description: This search looks for AWS provisioning activities from previously unseen cities. Provisioning activities are defined broadly as any event that begins with diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml index 9fa34711fb..05ecc67be0 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml @@ -4,14 +4,6 @@ version: 5 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Provisioning Activity From Previously Unseen Country type: Anomaly description: This search looks for AWS provisioning activities from previously unseen countries. Provisioning activities are defined broadly as any event that begins diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml index d90ad488c4..5568175da0 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml @@ -4,14 +4,6 @@ version: 5 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Provisioning Activity From Previously Unseen IP Address type: Anomaly description: This search looks for AWS provisioning activities from previously unseen IP addresses. Provisioning activities are defined broadly as any event that begins diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml index b3748cf690..7adba589db 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Provisioning Activity From Previously Unseen Region type: Anomaly description: This search looks for AWS provisioning activities from previously unseen regions. Region in this context is similar to a state in the United States. Provisioning diff --git a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml index 016a68160e..866bca7809 100644 --- a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml +++ b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Kubernetes Abuse of Secret by Unusual Location type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets diff --git a/detections/deprecated/change_default_file_association.yml b/detections/deprecated/change_default_file_association.yml index e3de336511..b524230015 100644 --- a/detections/deprecated/change_default_file_association.yml +++ b/detections/deprecated/change_default_file_association.yml @@ -4,13 +4,6 @@ version: 5 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows New Default File Association Value Set type: TTP description: The following analytic has been deprecated. The following analytic detects suspicious registry modifications that change the default file association to execute diff --git a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml index 7ea5a6c524..eb01c32ea2 100644 --- a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml +++ b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml @@ -4,12 +4,6 @@ version: 6 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: This search allows you to identify the endpoints that have connected to more than five DNS servers and made DNS Queries over the time frame of the search. diff --git a/detections/deprecated/cloud_network_access_control_list_deleted.yml b/detections/deprecated/cloud_network_access_control_list_deleted.yml index c5a273eb95..8a9036b76a 100644 --- a/detections/deprecated/cloud_network_access_control_list_deleted.yml +++ b/detections/deprecated/cloud_network_access_control_list_deleted.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Peter Gael, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - AWS Network Access Control List Deleted type: Anomaly description: Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker diff --git a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml index 98e8084d64..1df440f488 100644 --- a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml @@ -4,13 +4,6 @@ version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Cmdline Tool Execution From Non-Shell Process type: TTP description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`, or similar tools are executed by a non-standard parent process, excluding CMD, PowerShell, diff --git a/detections/deprecated/correlation_by_repository_and_risk.yml b/detections/deprecated/correlation_by_repository_and_risk.yml index afc868dcee..2629b408ff 100644 --- a/detections/deprecated/correlation_by_repository_and_risk.yml +++ b/detections/deprecated/correlation_by_repository_and_risk.yml @@ -4,13 +4,6 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the datamodel - replacement_content: - - Risk Rule for Dev Sec Ops by Repository type: Correlation description: |- This search has been deprecated and updated with Risk Rule for Dev Sec Ops by Repository detection. The following analytic detects by correlating repository and risk score to identify patterns and trends in the data based on the level of risk associated. The analytic adds any null values and calculates the sum of the risk scores for each detection. Then, the analytic captures the source and user information for each detection and sorts the results in ascending order based on the risk score. Finally, the analytic filters the detections with a risk score below 80 and focuses only on high-risk detections.This detection is important because it provides valuable insights into the distribution of high-risk activities across different repositories. It also identifies the most vulnerable repositories that are frequently targeted by potential threats. Additionally, it proactively detects and responds to potential threats, thereby minimizing the impact of attacks and safeguarding critical assets. Finally, it provides a comprehensive view of the risk landscape and helps to make informed decisions to protect the organization's data and infrastructure. False positives might occur so it is important to identify the impact of the attack and prioritize response and mitigation efforts. diff --git a/detections/deprecated/correlation_by_user_and_risk.yml b/detections/deprecated/correlation_by_user_and_risk.yml index 0d95f474ec..63d9c738ae 100644 --- a/detections/deprecated/correlation_by_user_and_risk.yml +++ b/detections/deprecated/correlation_by_user_and_risk.yml @@ -4,13 +4,6 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the datamodel - replacement_content: - - Risk Rule for Dev Sec Ops by Repository type: Correlation description: |- The following analytic detects the correlation between the user and risk score and identifies users with a high risk score that pose a significant security risk such as unauthorized access attempts, suspicious behavior, or potential insider threats. Next, the analytic calculates the sum of the risk scores and groups the results by user, the corresponding signals, and the repository. The results are sorted in descending order based on the risk score and filtered to include records with a risk score greater than 80. Finally, the results are passed through a correlation filter specific to the user and risk. This detection is important because it identifies users who have a high risk score and helps to prioritize investigations and allocate resources. False positives might occur but the impact of such an attack can vary depending on the specific scenario such as data exfiltration, system compromise, or the disruption of critical services. Please investigate this notable event. diff --git a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml index b4553ed94f..cf89f5b1ac 100644 --- a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml +++ b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml @@ -4,13 +4,6 @@ version: 15 date: '2025-01-24' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Create Local Administrator Account Via Net type: TTP description: The following analytic has been deprecated. The following analytic detects the creation of local administrator accounts using the net.exe command. It leverages diff --git a/detections/deprecated/deleting_of_net_users.yml b/detections/deprecated/deleting_of_net_users.yml index 7d5ea4007a..cb8dc58817 100644 --- a/detections/deprecated/deleting_of_net_users.yml +++ b/detections/deprecated/deleting_of_net_users.yml @@ -4,13 +4,6 @@ version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows User Deletion Via Net type: TTP description: The following analytic has been deprecated. The following analytic detects the use of net.exe or net1.exe command-line to delete a user account on a system. diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml index 92df160e8f..0c13a55b87 100644 --- a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml @@ -4,12 +4,6 @@ version: 9 date: '2024-11-14' author: Bhavin Patel, Patrick Bareiss, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Hunting description: This search looks for specific authentication events from the Windows Security Event logs to detect potential attempts at using the Pass-the-Hash technique. diff --git a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml index 82e5931e6a..e0ad2efcfc 100644 --- a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml +++ b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - AWS Successful Single-Factor Authentication type: Hunting description: This search looks for AWS CloudTrail events where a user logged into the AWS account, is making API calls and has not enabled Multi Factor authentication. diff --git a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml index b97773f126..23e833aac1 100644 --- a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml +++ b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml @@ -4,12 +4,6 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Hunting description: This search looks for successful AWS CloudTrail activity by user accounts that are not listed in the identity table or `aws_service_accounts.csv`. It returns diff --git a/detections/deprecated/detect_critical_alerts_from_security_tools.yml b/detections/deprecated/detect_critical_alerts_from_security_tools.yml index a956ec746a..75848f931f 100644 --- a/detections/deprecated/detect_critical_alerts_from_security_tools.yml +++ b/detections/deprecated/detect_critical_alerts_from_security_tools.yml @@ -4,13 +4,6 @@ version: 2 date: '2025-01-13' author: Gowthamaraj Rajendran, Patrick Bareiss, Bhavin Patel, Bryan Pluta, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Microsoft Defender Incident Alerts type: TTP data_source: - Windows Defender Alerts diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml index b76c9405f5..67c72e7e14 100644 --- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml +++ b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml @@ -4,12 +4,6 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: This search looks for DNS requests for phishing domains that are leveraging EvilGinx tools to mimic websites. diff --git a/detections/deprecated/detect_long_dns_txt_record_response.yml b/detections/deprecated/detect_long_dns_txt_record_response.yml index 98b0f46fdc..57a2fb80be 100644 --- a/detections/deprecated/detect_long_dns_txt_record_response.yml +++ b/detections/deprecated/detect_long_dns_txt_record_response.yml @@ -4,12 +4,6 @@ version: 5 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: This search is used to detect attempts to use DNS tunneling, by calculating the length of responses to DNS TXT queries. Endpoints using DNS as a method of transmission diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/detections/deprecated/detect_mimikatz_using_loaded_images.yml index 2b96f938f5..b002ff2bcc 100644 --- a/detections/deprecated/detect_mimikatz_using_loaded_images.yml +++ b/detections/deprecated/detect_mimikatz_using_loaded_images.yml @@ -4,12 +4,6 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: This search looks for reading loaded Images unique to credential dumping with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon diff --git a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml index 4f622e2ba5..aa9cabe8d3 100644 --- a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml +++ b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml @@ -4,13 +4,6 @@ version: 5 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Updated to a new detection name - replacement_content: - - Detect Mimikatz With PowerShell Script Block Logging type: TTP description: This search looks for PowerShell requesting privileges consistent with credential dumping. Deprecated, looks like things changed from a logging perspective. diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/detections/deprecated/detect_new_api_calls_from_user_roles.yml index a0a40a7079..cc41aecff1 100644 --- a/detections/deprecated/detect_new_api_calls_from_user_roles.yml +++ b/detections/deprecated/detect_new_api_calls_from_user_roles.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud API Calls From Previously Unseen User Roles type: Anomaly description: This search detects new API calls that have either never been seen before or that have not been seen in the previous hour, where the identity type is `AssumedRole`. diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/detections/deprecated/detect_new_user_aws_console_login.yml index 3b7dee01f6..68c62a8d9c 100644 --- a/detections/deprecated/detect_new_user_aws_console_login.yml +++ b/detections/deprecated/detect_new_user_aws_console_login.yml @@ -4,14 +4,6 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Detect AWS Console Login by New User type: Hunting description: This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup diff --git a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml index 3abe50aa9b..05f6ff2bd6 100644 --- a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml +++ b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml @@ -4,13 +4,6 @@ version: 7 date: '2025-01-24' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Potential System Network Configuration Discovery Activity type: TTP description: The following analytic has been deprecated. The following analytic identifies the rapid execution of processes used for system network configuration discovery diff --git a/detections/deprecated/detect_spike_in_aws_api_activity.yml b/detections/deprecated/detect_spike_in_aws_api_activity.yml index 7757834caf..5a7efe7007 100644 --- a/detections/deprecated/detect_spike_in_aws_api_activity.yml +++ b/detections/deprecated/detect_spike_in_aws_api_activity.yml @@ -4,13 +4,6 @@ version: 5 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '' type: Anomaly description: This search will detect users creating spikes of API activity in your AWS environment. It will also update the cache file that factors in the latest diff --git a/detections/deprecated/detect_spike_in_network_acl_activity.yml b/detections/deprecated/detect_spike_in_network_acl_activity.yml index b35582dc49..a7e693bf9e 100644 --- a/detections/deprecated/detect_spike_in_network_acl_activity.yml +++ b/detections/deprecated/detect_spike_in_network_acl_activity.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Abnormally High Number Of Cloud Infrastructure API Calls type: Anomaly description: This search will detect users creating spikes in API activity related to network access-control lists (ACLs)in your AWS environment. This search is deprecated diff --git a/detections/deprecated/detect_spike_in_security_group_activity.yml b/detections/deprecated/detect_spike_in_security_group_activity.yml index a8e0579682..de1cad3b6d 100644 --- a/detections/deprecated/detect_spike_in_security_group_activity.yml +++ b/detections/deprecated/detect_spike_in_security_group_activity.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Abnormally High Number Of Cloud Security Group API Calls type: Anomaly description: This search will detect users creating spikes in API activity related to security groups in your AWS environment. It will also update the cache file diff --git a/detections/deprecated/detect_usb_device_insertion.yml b/detections/deprecated/detect_usb_device_insertion.yml index c363556e53..2d6dd088f5 100644 --- a/detections/deprecated/detect_usb_device_insertion.yml +++ b/detections/deprecated/detect_usb_device_insertion.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: The search is used to detect hosts that generate Windows Event ID 4663 for successful attempts to write to or read from a removable storage and Event ID diff --git a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml index 885920c786..853d302d85 100644 --- a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml +++ b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml @@ -4,13 +4,6 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Updated to use a different log source - replacement_content: - - Detect hosts connecting to dynamic domain providers type: TTP description: This search looks for web connections to dynamic DNS providers. data_source: [] diff --git a/detections/deprecated/detect_webshell_exploit_behavior.yml b/detections/deprecated/detect_webshell_exploit_behavior.yml index e921c3ffbf..5f61b3c0c8 100644 --- a/detections/deprecated/detect_webshell_exploit_behavior.yml +++ b/detections/deprecated/detect_webshell_exploit_behavior.yml @@ -4,13 +4,6 @@ version: 7 date: '2025-01-24' author: Steven Dick status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Suspicious Child Process Spawned From WebServer type: TTP description: The following analytic has been deprecated. The following analytic identifies the execution of suspicious processes typically associated with webshell activity diff --git a/detections/deprecated/detection_of_dns_tunnels.yml b/detections/deprecated/detection_of_dns_tunnels.yml index 595ded0bd5..e903bf4d9a 100644 --- a/detections/deprecated/detection_of_dns_tunnels.yml +++ b/detections/deprecated/detection_of_dns_tunnels.yml @@ -4,12 +4,6 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: "This search is used to detect DNS tunneling, by calculating the sum of the length of DNS queries and DNS answers. The search also filters out potential diff --git a/detections/deprecated/disabling_net_user_account.yml b/detections/deprecated/disabling_net_user_account.yml index 3fee864584..615c9dea0b 100644 --- a/detections/deprecated/disabling_net_user_account.yml +++ b/detections/deprecated/disabling_net_user_account.yml @@ -4,13 +4,6 @@ version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows User Disabled Via Net type: TTP description: The following analytic has been deprecated. The following analytic detects the use of the `net.exe` utility to disable a user account via the command line. diff --git a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml index 20f966e9b1..b52f87457a 100644 --- a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml +++ b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml @@ -4,12 +4,6 @@ version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: This search will detect DNS requests resolved by unauthorized DNS servers. Legitimate DNS servers should be identified in the Enterprise Security Assets and diff --git a/detections/deprecated/dns_record_changed.yml b/detections/deprecated/dns_record_changed.yml index c917402af4..1da12999ba 100644 --- a/detections/deprecated/dns_record_changed.yml +++ b/detections/deprecated/dns_record_changed.yml @@ -4,12 +4,6 @@ version: 6 date: '2024-11-14' author: Jose Hernandez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: The search takes the DNS records and their answers results of the discovered_dns_records lookup and finds if any records have changed by searching DNS response from the diff --git a/detections/deprecated/domain_account_discovery_with_net_app.yml b/detections/deprecated/domain_account_discovery_with_net_app.yml index b4f21b70a2..92ad5bcfa8 100644 --- a/detections/deprecated/domain_account_discovery_with_net_app.yml +++ b/detections/deprecated/domain_account_discovery_with_net_app.yml @@ -4,16 +4,6 @@ version: 5 date: '2025-01-13' author: Teoderick Contreras, Mauricio Velazco, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: "This analytic was a TTP that looked only for commands that tries to query - info about the users via net user /do. This had a couple of issues, such as triggering - on creation of users via the /add flag etc..\nIt was deprecated in favor of a - more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122" - replacement_content: - - Windows User Discovery Via Net type: TTP description: This following analytic has been deprecated in favour of the generic version "5d0d4830-0133-11ec-bae3-acde48001122". The following analytic detects the diff --git a/detections/deprecated/domain_group_discovery_with_net.yml b/detections/deprecated/domain_group_discovery_with_net.yml index 8d355cbccc..b01c32e127 100644 --- a/detections/deprecated/domain_group_discovery_with_net.yml +++ b/detections/deprecated/domain_group_discovery_with_net.yml @@ -4,13 +4,6 @@ version: 6 date: '2025-01-13' author: Mauricio Velazco, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Group Discovery Via Net type: Hunting description: This search has been deprecated in favour of the more generic analytic "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic identifies the execution diff --git a/detections/deprecated/dump_lsass_via_procdump_rename.yml b/detections/deprecated/dump_lsass_via_procdump_rename.yml index db97b216a0..db67928fa4 100644 --- a/detections/deprecated/dump_lsass_via_procdump_rename.yml +++ b/detections/deprecated/dump_lsass_via_procdump_rename.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Updated to a new detection name - replacement_content: - - Dump LSASS via procdump type: Hunting description: "Detect a renamed instance of procdump.exe dumping the lsass process. This query looks for both -mm and -ma usage. -mm will produce a mini dump file and diff --git a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml index 306a57bde9..c0dddee3ca 100644 --- a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml @@ -4,14 +4,6 @@ version: 6 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud API Calls From Previously Unseen User Roles type: Anomaly description: This search looks for EC2 instances being modified by users who have not previously modified them. This search is deprecated and have been translated diff --git a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml index 21078ec309..0d7e62b234 100644 --- a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml +++ b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Compute Instance Created In Previously Unused Region type: Hunting description: This search looks for AWS CloudTrail events where an instance is started in a particular region in the last one hour and then compares it to a lookup file diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml index 7a08a8ab13..80a929eefb 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml @@ -4,14 +4,6 @@ version: 5 date: '2025-01-16' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Compute Instance Created With Previously Unseen Image type: Anomaly description: This search looks for EC2 instances being created with previously unseen AMIs. This search is deprecated and have been translated to use the latest Change diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml index 1b2fbffdbb..e1a95404a0 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml @@ -4,14 +4,6 @@ version: 6 date: '2025-01-16' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Compute Instance Created With Previously Unseen Instance Type type: Anomaly description: This search looks for EC2 instances being created with previously unseen instance types. This search is deprecated and have been translated to use the latest diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml index adaf0a181b..d43786da55 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml @@ -4,14 +4,6 @@ version: 6 date: '2025-01-16' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Compute Instance Created By Previously Unseen User type: Anomaly description: This search looks for EC2 instances being created by users who have not created them before. This search is deprecated and have been translated to use the diff --git a/detections/deprecated/elevated_group_discovery_with_net.yml b/detections/deprecated/elevated_group_discovery_with_net.yml index 9712be51f2..45c777516b 100644 --- a/detections/deprecated/elevated_group_discovery_with_net.yml +++ b/detections/deprecated/elevated_group_discovery_with_net.yml @@ -4,13 +4,6 @@ version: 6 date: '2025-01-24' author: Mauricio Velazco, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Sensitive Group Discovery With Net type: TTP description: The following analytic has been deprecated. The following analytic detects the execution of `net.exe` or `net1.exe` with command-line arguments used to query diff --git a/detections/deprecated/excel_spawning_powershell.yml b/detections/deprecated/excel_spawning_powershell.yml index eeb145c769..28ca3fa40a 100644 --- a/detections/deprecated/excel_spawning_powershell.yml +++ b/detections/deprecated/excel_spawning_powershell.yml @@ -4,13 +4,6 @@ version: 7 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/detections/deprecated/excessive_service_stop_attempt.yml b/detections/deprecated/excessive_service_stop_attempt.yml index 428f6c64e7..9c51626bde 100644 --- a/detections/deprecated/excessive_service_stop_attempt.yml +++ b/detections/deprecated/excessive_service_stop_attempt.yml @@ -4,13 +4,6 @@ version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Excessive Service Stop Attempt type: Anomaly description: The following analytic has been deprecated. The following analytic detects multiple attempts to stop or delete services on a system using `net.exe`, `sc.exe`, diff --git a/detections/deprecated/excessive_usage_of_net_app.yml b/detections/deprecated/excessive_usage_of_net_app.yml index ea3c6f60ed..050c4047c9 100644 --- a/detections/deprecated/excessive_usage_of_net_app.yml +++ b/detections/deprecated/excessive_usage_of_net_app.yml @@ -4,13 +4,6 @@ version: 6 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Excessive Usage Of Net App type: Anomaly description: The following analytic has been deprecated. The following analytic detects excessive usage of `net.exe` or `net1.exe` within a one-minute interval. It leverages diff --git a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml index 81f9becb23..6e453a7f03 100644 --- a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml +++ b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml @@ -4,13 +4,6 @@ version: 6 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Updated to a new detection name - replacement_content: - - Execution of File with Multiple Extensions type: TTP description: This search looks for processes launched from files with at least five spaces in the name before the extension. This is typically done to obfuscate the diff --git a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml index 995f48dd58..c72e3977a2 100644 --- a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml +++ b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Hunting description: This search returns a list of hosts that have not successfully completed a backup in over a week. Deprecated because it's a infrastructure monitoring. diff --git a/detections/deprecated/extraction_of_registry_hives.yml b/detections/deprecated/extraction_of_registry_hives.yml index c4e3bdaee0..7e1ddbc2bc 100644 --- a/detections/deprecated/extraction_of_registry_hives.yml +++ b/detections/deprecated/extraction_of_registry_hives.yml @@ -4,13 +4,6 @@ version: 6 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Sensitive Registry Hive Dump Via CommandLine type: TTP description: The following analytic has been deprecated. The following analytic detects the use of `reg.exe` to export Windows Registry hives, which may contain sensitive diff --git a/detections/deprecated/first_time_seen_command_line_argument.yml b/detections/deprecated/first_time_seen_command_line_argument.yml index f2d43dec54..5df827cada 100644 --- a/detections/deprecated/first_time_seen_command_line_argument.yml +++ b/detections/deprecated/first_time_seen_command_line_argument.yml @@ -4,13 +4,6 @@ version: 8 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. diff --git a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml index da59975438..10a412fbc9 100644 --- a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml +++ b/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Hunting description: This search provides detection of accounts with high risk roles by projects. Compromised accounts with high risk roles can move laterally or even scalate privileges diff --git a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml index 38e56596e6..1291444493 100644 --- a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml +++ b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Hunting description: This search provides detection of high risk permissions by resource and accounts. These are permissions that can allow attackers with compromised accounts diff --git a/detections/deprecated/gcp_detect_oauth_token_abuse.yml b/detections/deprecated/gcp_detect_oauth_token_abuse.yml index bef84aaa87..25144dd436 100644 --- a/detections/deprecated/gcp_detect_oauth_token_abuse.yml +++ b/detections/deprecated/gcp_detect_oauth_token_abuse.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Hunting description: This search provides detection of possible GCP Oauth token abuse. GCP Oauth token without time limit can be exfiltrated and reused for keeping access diff --git a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml index 88aad6f364..f8fabad5ff 100644 --- a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml +++ b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Kubernetes Scanning by Unauthenticated IP Address type: TTP description: This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster diff --git a/detections/deprecated/identify_new_user_accounts.yml b/detections/deprecated/identify_new_user_accounts.yml index 5e43985eae..55b528d72a 100644 --- a/detections/deprecated/identify_new_user_accounts.yml +++ b/detections/deprecated/identify_new_user_accounts.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This detection search will help profile user accounts in your environment by identifying newly created accounts that have been added to your network in the diff --git a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml index 49a3f2cddb..8aed9288a5 100644 --- a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml +++ b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision diff --git a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml index 2a269a69ce..6d04bf8d94 100644 --- a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml +++ b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC diff --git a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml index 7c08f4bb52..bb7b707a96 100644 --- a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml @@ -4,13 +4,6 @@ version: 5 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml index 3e8620e1f1..17722e0587 100644 --- a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or diff --git a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml index ec37c0848f..ef9d02ecbe 100644 --- a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml +++ b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes service accounts,accessing pods and namespaces by IP address and verb diff --git a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml index d96925d545..0adc47769d 100644 --- a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml +++ b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding rare or top to see both extremes diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml index 80591ab342..8ae1ee647e 100644 --- a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml index b7243aff43..9993a0a115 100644 --- a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml @@ -4,13 +4,6 @@ version: 5 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml index 0740c5bc9e..ccbf5daf0c 100644 --- a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes service accounts with failure or forbidden access status diff --git a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml index 94ba765c3e..ef3fed2b2d 100644 --- a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml +++ b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on rare Kubectl calls with IP, verb namespace and object access context diff --git a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml index d41ae9e248..1b1378b2f7 100644 --- a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml +++ b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster pod diff --git a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml index 5ad0876707..8a6b44473d 100644 --- a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml +++ b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster in diff --git a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml index 32ad65ac4c..0d3a4cdf11 100644 --- a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml +++ b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision diff --git a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml index fc2bf51208..09a26684ce 100644 --- a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml +++ b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml index 67d2e2979e..557ab8a5c3 100644 --- a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml index e37d0a15ab..da1b2cf148 100644 --- a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml @@ -4,13 +4,6 @@ version: 5 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml index 7f03e97647..fff4730076 100644 --- a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or diff --git a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml index 80d95194a1..a78e967c70 100644 --- a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml +++ b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: Hunting description: This search provides information on anonymous Kubectl calls with IP, verb namespace and object access context diff --git a/detections/deprecated/linux_auditd_find_private_keys.yml b/detections/deprecated/linux_auditd_find_private_keys.yml index 8ccb92c6c7..756073da56 100644 --- a/detections/deprecated/linux_auditd_find_private_keys.yml +++ b/detections/deprecated/linux_auditd_find_private_keys.yml @@ -4,13 +4,6 @@ version: 5 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Linux Auditd Private Keys and Certificate Enumeration type: TTP description: The following analytic has been deprecated. The following analytic detects suspicious attempts to find private keys, which may indicate an attacker's effort diff --git a/detections/deprecated/local_account_discovery_with_net.yml b/detections/deprecated/local_account_discovery_with_net.yml index 6aa48ba58f..8af80acf03 100644 --- a/detections/deprecated/local_account_discovery_with_net.yml +++ b/detections/deprecated/local_account_discovery_with_net.yml @@ -4,13 +4,6 @@ version: 6 date: '2025-01-24' author: Mauricio Velazco, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows User Discovery Via Net type: Hunting description: The following analytic has been deprecated. The following analytic detects the execution of `net.exe` or `net1.exe` with command-line arguments `user` or `users` diff --git a/detections/deprecated/monitor_dns_for_brand_abuse.yml b/detections/deprecated/monitor_dns_for_brand_abuse.yml index dfe23ab2a6..9ad520f284 100644 --- a/detections/deprecated/monitor_dns_for_brand_abuse.yml +++ b/detections/deprecated/monitor_dns_for_brand_abuse.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: TTP description: This search looks for DNS requests for faux domains similar to the domains that you want to have monitored for abuse. diff --git a/detections/deprecated/mshtml_module_load_in_office_product.yml b/detections/deprecated/mshtml_module_load_in_office_product.yml index f9b620ec36..870c4aea9d 100644 --- a/detections/deprecated/mshtml_module_load_in_office_product.yml +++ b/detections/deprecated/mshtml_module_load_in_office_product.yml @@ -4,13 +4,6 @@ version: 7 date: '2025-01-24' author: Michael Haag, Mauricio Velazco, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Loaded MSHTML Module type: TTP description: The following analytic has been deprecated. The following analytic detects the loading of the mshtml.dll module into an Office product, which is indicative diff --git a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml index 23ac3906f5..68269b2e43 100644 --- a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml +++ b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml @@ -4,14 +4,6 @@ version: 5 date: '2024-11-14' author: Michael Haag, Mauricio Velazco, Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta Multiple Users Failing To Authenticate From Ip type: TTP description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Users Failing To Authenticate From Ip`. This analytic identifies diff --git a/detections/deprecated/net_localgroup_discovery.yml b/detections/deprecated/net_localgroup_discovery.yml index 13b349af7b..b3d15becdf 100644 --- a/detections/deprecated/net_localgroup_discovery.yml +++ b/detections/deprecated/net_localgroup_discovery.yml @@ -4,14 +4,6 @@ version: 5 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 - / Windows Group Discovery Via Net - replacement_content: - - Windows Group Discovery Via Net type: Hunting description: This search has been deprecated in favour of the more generic analytic "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic detects the execution diff --git a/detections/deprecated/network_connection_discovery_with_net.yml b/detections/deprecated/network_connection_discovery_with_net.yml index 1785ae5ff7..e2caea92c7 100644 --- a/detections/deprecated/network_connection_discovery_with_net.yml +++ b/detections/deprecated/network_connection_discovery_with_net.yml @@ -4,13 +4,6 @@ version: 6 date: '2025-01-24' author: Mauricio Velazco, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Network Connection Discovery Via Net type: Hunting description: The following analytic has been deprecated. The following analytic identifies the execution of `net.exe` or `net1.exe` with command-line arguments used to list diff --git a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml index 23ed76cc7c..13dddb8c18 100644 --- a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml +++ b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml @@ -4,14 +4,6 @@ version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - O365 Mailbox Email Forwarding Enabled type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Mailbox Email Forwarding Enabled`. This search detects when an admin diff --git a/detections/deprecated/o365_suspicious_rights_delegation.yml b/detections/deprecated/o365_suspicious_rights_delegation.yml index a0fcb196a4..e9e6543750 100644 --- a/detections/deprecated/o365_suspicious_rights_delegation.yml +++ b/detections/deprecated/o365_suspicious_rights_delegation.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Patrick Bareiss, Mauricio Velazco, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - O365 Elevated Mailbox Permission Assigned type: TTP description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Elevated Mailbox Permission Assigned`. This analytic identifies instances diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/detections/deprecated/o365_suspicious_user_email_forwarding.yml index 682a9fff0c..1a9c9c5c4c 100644 --- a/detections/deprecated/o365_suspicious_user_email_forwarding.yml +++ b/detections/deprecated/o365_suspicious_user_email_forwarding.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - O365 Mailbox Email Forwarding Enabled type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Mailbox Email Forwarding Enabled`. The following analytic detects when diff --git a/detections/deprecated/office_application_drop_executable.yml b/detections/deprecated/office_application_drop_executable.yml index da7930df64..792556a6d3 100644 --- a/detections/deprecated/office_application_drop_executable.yml +++ b/detections/deprecated/office_application_drop_executable.yml @@ -4,13 +4,6 @@ version: 9 date: '2025-01-24' author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Dropped Uncommon File type: TTP description: The following analytic has been deprecated. The following analytic detects Microsoft Office applications dropping or creating executables or scripts on a Windows diff --git a/detections/deprecated/office_application_spawn_regsvr32_process.yml b/detections/deprecated/office_application_spawn_regsvr32_process.yml index 0b35f87583..ceec84dba1 100644 --- a/detections/deprecated/office_application_spawn_regsvr32_process.yml +++ b/detections/deprecated/office_application_spawn_regsvr32_process.yml @@ -4,13 +4,6 @@ version: 8 date: '2025-01-13' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/detections/deprecated/office_application_spawn_rundll32_process.yml b/detections/deprecated/office_application_spawn_rundll32_process.yml index d9a37aaba7..6d10c2b8c8 100644 --- a/detections/deprecated/office_application_spawn_rundll32_process.yml +++ b/detections/deprecated/office_application_spawn_rundll32_process.yml @@ -4,13 +4,6 @@ version: 8 date: '2025-01-13' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/detections/deprecated/office_document_creating_schedule_task.yml b/detections/deprecated/office_document_creating_schedule_task.yml index d317b98c6a..1275c00579 100644 --- a/detections/deprecated/office_document_creating_schedule_task.yml +++ b/detections/deprecated/office_document_creating_schedule_task.yml @@ -4,13 +4,6 @@ version: 10 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Loading Taskschd DLL type: TTP description: The following analytic has been deprecated. The following analytic detects an Office document creating a scheduled task, either through a macro VBA API or diff --git a/detections/deprecated/office_document_executing_macro_code.yml b/detections/deprecated/office_document_executing_macro_code.yml index 35c088e292..9bf6ad3357 100644 --- a/detections/deprecated/office_document_executing_macro_code.yml +++ b/detections/deprecated/office_document_executing_macro_code.yml @@ -4,13 +4,6 @@ version: 9 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Loading VBE7 DLL type: TTP description: The following analytic has been deprecated. The following analytic identifies office documents executing macro code. It leverages Sysmon EventCode 7 to detect diff --git a/detections/deprecated/office_document_spawned_child_process_to_download.yml b/detections/deprecated/office_document_spawned_child_process_to_download.yml index 0763eb9df3..73220f4027 100644 --- a/detections/deprecated/office_document_spawned_child_process_to_download.yml +++ b/detections/deprecated/office_document_spawned_child_process_to_download.yml @@ -4,13 +4,6 @@ version: 10 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Spawned Child Process For Download type: TTP description: The following analytic has been deprecated. The following analytic identifies Office applications spawning child processes to download content via HTTP/HTTPS. diff --git a/detections/deprecated/office_product_spawn_cmd_process.yml b/detections/deprecated/office_product_spawn_cmd_process.yml index d9d6ff558c..4193c23ca8 100644 --- a/detections/deprecated/office_product_spawn_cmd_process.yml +++ b/detections/deprecated/office_product_spawn_cmd_process.yml @@ -4,13 +4,6 @@ version: 8 date: '2025-01-13' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/detections/deprecated/office_product_spawning_bitsadmin.yml b/detections/deprecated/office_product_spawning_bitsadmin.yml index 2b8a51389c..3bda779c35 100644 --- a/detections/deprecated/office_product_spawning_bitsadmin.yml +++ b/detections/deprecated/office_product_spawning_bitsadmin.yml @@ -4,13 +4,6 @@ version: 9 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/detections/deprecated/office_product_spawning_certutil.yml b/detections/deprecated/office_product_spawning_certutil.yml index d89056cb83..00bc0797c9 100644 --- a/detections/deprecated/office_product_spawning_certutil.yml +++ b/detections/deprecated/office_product_spawning_certutil.yml @@ -4,13 +4,6 @@ version: 9 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/detections/deprecated/office_product_spawning_mshta.yml b/detections/deprecated/office_product_spawning_mshta.yml index 4ba85dc480..ef07f76ce2 100644 --- a/detections/deprecated/office_product_spawning_mshta.yml +++ b/detections/deprecated/office_product_spawning_mshta.yml @@ -4,13 +4,6 @@ version: 8 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml index 43530ad126..a74965e373 100644 --- a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml +++ b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml @@ -4,13 +4,6 @@ version: 10 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Spawned Rundll32 With No DLL type: TTP description: The following analytic has been deprecated. The following analytic detects any Windows Office Product spawning `rundll32.exe` without a `.dll` file extension. diff --git a/detections/deprecated/office_product_spawning_windows_script_host.yml b/detections/deprecated/office_product_spawning_windows_script_host.yml index d6bfcc6025..659a4b48ed 100644 --- a/detections/deprecated/office_product_spawning_windows_script_host.yml +++ b/detections/deprecated/office_product_spawning_windows_script_host.yml @@ -4,13 +4,6 @@ version: 10 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/detections/deprecated/office_product_spawning_wmic.yml b/detections/deprecated/office_product_spawning_wmic.yml index c60f305eb0..a06d97a5d7 100644 --- a/detections/deprecated/office_product_spawning_wmic.yml +++ b/detections/deprecated/office_product_spawning_wmic.yml @@ -4,13 +4,6 @@ version: 10 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/detections/deprecated/office_product_writing_cab_or_inf.yml b/detections/deprecated/office_product_writing_cab_or_inf.yml index cb9aafc883..30adac14d5 100644 --- a/detections/deprecated/office_product_writing_cab_or_inf.yml +++ b/detections/deprecated/office_product_writing_cab_or_inf.yml @@ -4,13 +4,6 @@ version: 10 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Dropped Cab or Inf File type: TTP description: The following analytic has been deprecated. The following analytic detects Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation. diff --git a/detections/deprecated/office_spawning_control.yml b/detections/deprecated/office_spawning_control.yml index 389aa5d867..984e8bf0a8 100644 --- a/detections/deprecated/office_spawning_control.yml +++ b/detections/deprecated/office_spawning_control.yml @@ -4,13 +4,6 @@ version: 10 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Spawned Control type: TTP description: The following analytic has been deprecated. The following analytic identifies instances where `control.exe` is spawned by a Microsoft Office product. It leverages diff --git a/detections/deprecated/okta_account_locked_out.yml b/detections/deprecated/okta_account_locked_out.yml index 0b1df607ad..0ad8243973 100644 --- a/detections/deprecated/okta_account_locked_out.yml +++ b/detections/deprecated/okta_account_locked_out.yml @@ -4,14 +4,6 @@ version: 3 date: '2024-11-14' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta Multiple Accounts Locked Out type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Accounts Locked Out`. The following analytic utilizes the user.acount.lock diff --git a/detections/deprecated/okta_account_lockout_events.yml b/detections/deprecated/okta_account_lockout_events.yml index 4049ec139c..07f8d09a9d 100644 --- a/detections/deprecated/okta_account_lockout_events.yml +++ b/detections/deprecated/okta_account_lockout_events.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Michael Haag, Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta Multiple Accounts Locked Out type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Accounts Locked Out`. The following anomaly will generate based diff --git a/detections/deprecated/okta_failed_sso_attempts.yml b/detections/deprecated/okta_failed_sso_attempts.yml index cd83cc1cb9..6516d32c67 100644 --- a/detections/deprecated/okta_failed_sso_attempts.yml +++ b/detections/deprecated/okta_failed_sso_attempts.yml @@ -4,14 +4,6 @@ version: 5 date: '2024-11-14' author: Michael Haag, Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta Unauthorized Access to Application type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with this detection `Okta Unauthorized Access to Application - DM`. The following diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml index 018e6ec446..1f87cc42bf 100644 --- a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml +++ b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml @@ -5,12 +5,6 @@ date: '2024-11-14' author: Okta, Inc, Michael Haag, Splunk type: TTP status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] data_source: [] description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml index e686982f42..478b4895a1 100644 --- a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml +++ b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml @@ -5,14 +5,6 @@ date: '2024-11-14' author: Okta, Inc, Michael Haag, Splunk type: TTP status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta ThreatInsight Threat Detected data_source: [] description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas diff --git a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml b/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml index 971408a38b..9817b5f845 100644 --- a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml +++ b/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml @@ -4,14 +4,6 @@ version: 4 date: '2024-11-14' author: Michael Haag, Marissa Bower, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta Multiple Failed MFA Requests For User type: TTP description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Failed MFA Requests For User`. The following analytic identifies diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/detections/deprecated/osquery_pack___coldroot_detection.yml index 8c0a454e3c..3ba9866bed 100644 --- a/detections/deprecated/osquery_pack___coldroot_detection.yml +++ b/detections/deprecated/osquery_pack___coldroot_detection.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: This search looks for ColdRoot events from the osx-attacks osquery pack. data_source: [] diff --git a/detections/deprecated/password_policy_discovery_with_net.yml b/detections/deprecated/password_policy_discovery_with_net.yml index 89def529b1..66ef237307 100644 --- a/detections/deprecated/password_policy_discovery_with_net.yml +++ b/detections/deprecated/password_policy_discovery_with_net.yml @@ -4,13 +4,6 @@ version: 7 date: '2025-01-24' author: Teoderick Contreras, Mauricio Velazco, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Password Policy Discovery with Net type: Hunting description: The following analytic has been deprecated. The following analytic identifies the execution of `net.exe` or `net1.exe` with command line arguments aimed at obtaining diff --git a/detections/deprecated/processes_created_by_netsh.yml b/detections/deprecated/processes_created_by_netsh.yml index c82728a2d9..cb947299d8 100644 --- a/detections/deprecated/processes_created_by_netsh.yml +++ b/detections/deprecated/processes_created_by_netsh.yml @@ -4,13 +4,6 @@ version: 8 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Updated to a new detection name - replacement_content: - - Processes launching netsh type: TTP description: This search looks for processes launching netsh.exe to execute various commands via the netsh command-line utility. Netsh.exe is a command-line scripting diff --git a/detections/deprecated/prohibited_software_on_endpoint.yml b/detections/deprecated/prohibited_software_on_endpoint.yml index 86593fcbf9..243c1c8374 100644 --- a/detections/deprecated/prohibited_software_on_endpoint.yml +++ b/detections/deprecated/prohibited_software_on_endpoint.yml @@ -4,13 +4,6 @@ version: 5 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Attacker Tools On Endpoint type: Hunting description: This search looks for applications on the endpoint that you have marked as prohibited. diff --git a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml index 6947837938..b003f3bd58 100644 --- a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml +++ b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml @@ -4,13 +4,6 @@ version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '- ' type: TTP description: The search looks for command-line arguments used to hide a file or directory using the reg add command. diff --git a/detections/deprecated/remote_registry_key_modifications.yml b/detections/deprecated/remote_registry_key_modifications.yml index 4a417c4fa6..71f902a8ad 100644 --- a/detections/deprecated/remote_registry_key_modifications.yml +++ b/detections/deprecated/remote_registry_key_modifications.yml @@ -4,12 +4,6 @@ version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: This search monitors for remote modifications to registry keys. data_source: diff --git a/detections/deprecated/remote_system_discovery_with_net.yml b/detections/deprecated/remote_system_discovery_with_net.yml index 8b19a36706..6e730569fc 100644 --- a/detections/deprecated/remote_system_discovery_with_net.yml +++ b/detections/deprecated/remote_system_discovery_with_net.yml @@ -4,13 +4,6 @@ version: 5 date: '2025-01-13' author: Mauricio Velazco, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Sensitive Group Discovery With Net type: Hunting description: The following analytic has been deprecated in favour of two dedicated analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" diff --git a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml index d3d1e1b499..0197ba45a3 100644 --- a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml +++ b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml @@ -4,13 +4,6 @@ version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Updated to a new detection name - replacement_content: - - Scheduled Task Deleted Or Created via CMD type: TTP description: This search looks for flags passed to schtasks.exe on the command-line that indicate that task names related to the execution of Bad Rabbit ransomware diff --git a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml index c894e4fa3a..1f4a043402 100644 --- a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml +++ b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: The search is used to detect systems that are still vulnerable to the Spectre and Meltdown vulnerabilities. diff --git a/detections/deprecated/suspicious_changes_to_file_associations.yml b/detections/deprecated/suspicious_changes_to_file_associations.yml index f1c5eb5d31..e9438be5a1 100644 --- a/detections/deprecated/suspicious_changes_to_file_associations.yml +++ b/detections/deprecated/suspicious_changes_to_file_associations.yml @@ -4,12 +4,6 @@ version: 7 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: This search looks for changes to registry values that control Windows file associations, executed by a process that is not typical for legitimate, routine diff --git a/detections/deprecated/suspicious_email___uba_anomaly.yml b/detections/deprecated/suspicious_email___uba_anomaly.yml index 0b77fd20a8..0e3a3f31d6 100644 --- a/detections/deprecated/suspicious_email___uba_anomaly.yml +++ b/detections/deprecated/suspicious_email___uba_anomaly.yml @@ -4,12 +4,6 @@ version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Anomaly description: This detection looks for emails that are suspicious because of their sender, domain rareness, or behavior differences. This is an anomaly generated by diff --git a/detections/deprecated/suspicious_file_write.yml b/detections/deprecated/suspicious_file_write.yml index ce7ce09da0..8630632e57 100644 --- a/detections/deprecated/suspicious_file_write.yml +++ b/detections/deprecated/suspicious_file_write.yml @@ -4,13 +4,6 @@ version: 6 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '' type: Hunting description: The search looks for files created with names that have been linked to malicious activity. diff --git a/detections/deprecated/suspicious_powershell_command_line_arguments.yml b/detections/deprecated/suspicious_powershell_command_line_arguments.yml index a6c19ed8d7..b2efc4ee51 100644 --- a/detections/deprecated/suspicious_powershell_command_line_arguments.yml +++ b/detections/deprecated/suspicious_powershell_command_line_arguments.yml @@ -4,13 +4,6 @@ version: 9 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Malicious PowerShell Process - Encoded Command type: TTP description: This search looks for PowerShell processes started with a base64 encoded command-line passed to it, with parameters to modify the execution policy for the diff --git a/detections/deprecated/suspicious_rundll32_rename.yml b/detections/deprecated/suspicious_rundll32_rename.yml index eff58f4873..48fdc6b2d5 100644 --- a/detections/deprecated/suspicious_rundll32_rename.yml +++ b/detections/deprecated/suspicious_rundll32_rename.yml @@ -4,12 +4,6 @@ version: 7 date: '2024-11-14' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Hunting description: The following hunting analytic identifies renamed instances of rundll32.exe executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. diff --git a/detections/deprecated/suspicious_writes_to_system_volume_information.yml b/detections/deprecated/suspicious_writes_to_system_volume_information.yml index cc6e0fa6ae..866160575b 100644 --- a/detections/deprecated/suspicious_writes_to_system_volume_information.yml +++ b/detections/deprecated/suspicious_writes_to_system_volume_information.yml @@ -4,12 +4,6 @@ version: 5 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Hunting description: This search detects writes to the 'System Volume Information' folder by something other than the System process. diff --git a/detections/deprecated/uncommon_processes_on_endpoint.yml b/detections/deprecated/uncommon_processes_on_endpoint.yml index 4c90b29fdc..e0378b0e1f 100644 --- a/detections/deprecated/uncommon_processes_on_endpoint.yml +++ b/detections/deprecated/uncommon_processes_on_endpoint.yml @@ -4,13 +4,6 @@ version: 7 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Attacker Tools On Endpoint type: Hunting description: This search looks for applications on the endpoint that you have marked as uncommon. diff --git a/detections/deprecated/unsigned_image_loaded_by_lsass.yml b/detections/deprecated/unsigned_image_loaded_by_lsass.yml index 38f74b6f6d..db021a2bf3 100644 --- a/detections/deprecated/unsigned_image_loaded_by_lsass.yml +++ b/detections/deprecated/unsigned_image_loaded_by_lsass.yml @@ -4,13 +4,6 @@ version: 4 date: '2024-11-14' author: Patrick Bareiss, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - '' type: TTP description: This search detects loading of unsigned images by LSASS. Deprecated because too noisy. diff --git a/detections/deprecated/unsuccessful_netbackup_backups.yml b/detections/deprecated/unsuccessful_netbackup_backups.yml index feafa5361e..3e8fc0b5af 100644 --- a/detections/deprecated/unsuccessful_netbackup_backups.yml +++ b/detections/deprecated/unsuccessful_netbackup_backups.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: David Dorsey, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Hunting description: This search gives you the hosts where a backup was attempted and then failed. diff --git a/detections/deprecated/web_fraud___account_harvesting.yml b/detections/deprecated/web_fraud___account_harvesting.yml index 17f3be4b4f..4fb3b3b784 100644 --- a/detections/deprecated/web_fraud___account_harvesting.yml +++ b/detections/deprecated/web_fraud___account_harvesting.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: Jim Apger, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: This search is used to identify the creation of multiple user accounts using the same email domain name. diff --git a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml index 69a013dabf..518a5be28e 100644 --- a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml +++ b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: Jim Apger, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Anomaly description: This search is used to examine web sessions to identify those where the clicks are occurring too quickly for a human or are occurring with a near-perfect diff --git a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml index 0fe79ab5ff..48c9b3908c 100644 --- a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml +++ b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: Jim Apger, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: Anomaly description: This search is used to identify user accounts that share a common password. data_source: [] diff --git a/detections/deprecated/windows_command_shell_fetch_env_variables.yml b/detections/deprecated/windows_command_shell_fetch_env_variables.yml index 80ddcb7db1..8fcaf15950 100644 --- a/detections/deprecated/windows_command_shell_fetch_env_variables.yml +++ b/detections/deprecated/windows_command_shell_fetch_env_variables.yml @@ -4,13 +4,6 @@ version: 5 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows List ENV Variables Via SET Command From Uncommon Parent type: TTP description: The following analytic has been deprecated. The following analytic identifies a suspicious process command line fetching environment variables with a non-shell diff --git a/detections/deprecated/windows_connhost_exe_started_forcefully.yml b/detections/deprecated/windows_connhost_exe_started_forcefully.yml index 8bb950c864..2718083864 100644 --- a/detections/deprecated/windows_connhost_exe_started_forcefully.yml +++ b/detections/deprecated/windows_connhost_exe_started_forcefully.yml @@ -4,12 +4,6 @@ version: 5 date: '2024-11-14' author: Rod Soto, Jose Hernandez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: The search looks for the Console Window Host process (connhost.exe) executed using the force flag -ForceV1. This is not regular behavior in the Windows OS and diff --git a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml index f452743951..38d777ae9a 100644 --- a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml +++ b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml @@ -4,14 +4,6 @@ version: 5 date: '2024-11-14' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Windows DLL Search Order Hijacking Hunt with Sysmon type: Hunting description: The following hunting analytic is an experimental query built against a accidental feature using the latest Sysmon TA 3.0 (https://splunkbase.splunk.com/app/5709/) diff --git a/detections/deprecated/windows_hosts_file_modification.yml b/detections/deprecated/windows_hosts_file_modification.yml index fd6fa8ec88..0c7453eab3 100644 --- a/detections/deprecated/windows_hosts_file_modification.yml +++ b/detections/deprecated/windows_hosts_file_modification.yml @@ -4,12 +4,6 @@ version: 4 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: [] type: TTP description: The search looks for modifications to the hosts file on all Windows endpoints across your environment. diff --git a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml index dd1d040b65..0611c1c8f6 100644 --- a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml +++ b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml @@ -5,13 +5,6 @@ date: '2024-12-10' author: Michael Haag, Splunk type: TTP status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Updated to a new detection name - replacement_content: - - Windows Service Execution RemCom data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/windows_modify_registry_reg_restore.yml b/detections/deprecated/windows_modify_registry_reg_restore.yml index 324a5baed9..e1fcad055a 100644 --- a/detections/deprecated/windows_modify_registry_reg_restore.yml +++ b/detections/deprecated/windows_modify_registry_reg_restore.yml @@ -4,13 +4,6 @@ version: 5 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Registry Entries Restored Via Reg type: Hunting description: The following analytic has been deprecated. The following analytic detects the execution of reg.exe with the "restore" parameter, indicating an attempt to diff --git a/detections/deprecated/windows_msiexec_with_network_connections.yml b/detections/deprecated/windows_msiexec_with_network_connections.yml index 2331bd6952..39ac9d4465 100644 --- a/detections/deprecated/windows_msiexec_with_network_connections.yml +++ b/detections/deprecated/windows_msiexec_with_network_connections.yml @@ -4,13 +4,6 @@ version: 6 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows HTTP Network Communication From MSIExec type: TTP description: The following analytic has been deprecated. The following analytic detects MSIExec making network connections over ports 443 or 80. This behavior is identified diff --git a/detections/deprecated/windows_network_share_interaction_with_net.yml b/detections/deprecated/windows_network_share_interaction_with_net.yml index ab7de51ef6..29047d8992 100644 --- a/detections/deprecated/windows_network_share_interaction_with_net.yml +++ b/detections/deprecated/windows_network_share_interaction_with_net.yml @@ -4,13 +4,6 @@ version: 6 date: '2025-01-24' author: Dean Luxton status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Network Share Interaction Via Net type: TTP data_source: - Sysmon EventID 1 diff --git a/detections/deprecated/windows_office_product_spawning_msdt.yml b/detections/deprecated/windows_office_product_spawning_msdt.yml index 73517da1ff..88be1f1298 100644 --- a/detections/deprecated/windows_office_product_spawning_msdt.yml +++ b/detections/deprecated/windows_office_product_spawning_msdt.yml @@ -4,13 +4,6 @@ version: 9 date: '2025-01-24' author: Michael Haag, Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Spawned MSDT type: TTP description: The following analytic has been deprecated. The following analytic detects a Microsoft Office product spawning the Windows msdt.exe process. This detection diff --git a/detections/deprecated/windows_query_registry_reg_save.yml b/detections/deprecated/windows_query_registry_reg_save.yml index 2ef3993258..f44d4b8617 100644 --- a/detections/deprecated/windows_query_registry_reg_save.yml +++ b/detections/deprecated/windows_query_registry_reg_save.yml @@ -4,13 +4,6 @@ version: 6 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Registry Entries Exported Via Reg type: Hunting description: The following analytic has been deprecated. The following analytic detects the execution of the reg.exe process with the "save" parameter. This detection leverages diff --git a/detections/deprecated/windows_valid_account_with_never_expires_password.yml b/detections/deprecated/windows_valid_account_with_never_expires_password.yml index 65421b5a51..6bd2c46133 100644 --- a/detections/deprecated/windows_valid_account_with_never_expires_password.yml +++ b/detections/deprecated/windows_valid_account_with_never_expires_password.yml @@ -4,13 +4,6 @@ version: 6 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: Renamed and updated logic - replacement_content: - - Windows Set Account Password Policy To Unlimited Via Net type: TTP description: The following analytic has been deprecated. The following analytic detects the use of net.exe to update user account policies to set passwords as non-expiring. diff --git a/detections/deprecated/winword_spawning_cmd.yml b/detections/deprecated/winword_spawning_cmd.yml index de643bfb78..f16575033c 100644 --- a/detections/deprecated/winword_spawning_cmd.yml +++ b/detections/deprecated/winword_spawning_cmd.yml @@ -4,13 +4,6 @@ version: 7 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/detections/deprecated/winword_spawning_powershell.yml b/detections/deprecated/winword_spawning_powershell.yml index 74a7ae6560..50d598f95b 100644 --- a/detections/deprecated/winword_spawning_powershell.yml +++ b/detections/deprecated/winword_spawning_powershell.yml @@ -4,13 +4,6 @@ version: 7 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/detections/deprecated/winword_spawning_windows_script_host.yml b/detections/deprecated/winword_spawning_windows_script_host.yml index 606abeabb3..b1d17ca5a5 100644 --- a/detections/deprecated/winword_spawning_windows_script_host.yml +++ b/detections/deprecated/winword_spawning_windows_script_host.yml @@ -4,16 +4,6 @@ version: 6 date: '2025-01-13' author: Michael Haag, Splunk status: deprecated -deprecation_info: - deprecation_date: '2025-02-26' - deprecation_version: 5.2.0 - content_type: detection - reason: "The following analytics was deprecated in favour of a more generic approach. - Where instead of creating specific analytic for every potentially suspicious child - of an office product. We group them by threat level.\nThis would ease management - and false positives tuning." - replacement_content: - - Windows Office Product Spawned Uncommon Process type: TTP description: The following analytic has been deprecated in favour of a more generic approach. The following analytic identifies instances where Microsoft Winword.exe From f1dd70da1ea344a8285d2adbfa591eecb9c00868 Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Fri, 14 Feb 2025 10:22:46 -0800 Subject: [PATCH 08/67] update and pull in all the latest changes from develop branch --- ...ct_distributed_password_spray_attempts.yml | 5 +- .../detect_password_spray_attempts.yml | 5 +- ...itten_outside_of_the_outlook_directory.yml | 5 +- ...s_sending_high_volume_traffic_to_hosts.yml | 5 +- ...entication_failed_during_mfa_challenge.yml | 8 +- ...a_multi_factor_authentication_disabled.yml | 5 +- .../okta_new_api_token_created.yml | 5 +- .../okta_new_device_enrolled_on_account.yml | 5 +- ...g_detection_with_fastpass_origin_check.yml | 5 +- ...uccessful_single_factor_authentication.yml | 8 +- .../okta_suspicious_activity_reported.yml | 5 +- .../okta_threatinsight_threat_detected.yml | 5 +- ..._auth_source_and_verification_response.yml | 2 +- ...suspicious_email_attachment_extensions.yml | 5 +- ...ows_ad_dangerous_deny_acl_modification.yml | 7 +- ...ws_ad_dangerous_group_acl_modification.yml | 7 +- ...ows_ad_dangerous_user_acl_modification.yml | 7 +- .../windows_ad_domain_root_acl_deletion.yml | 7 +- ...indows_ad_domain_root_acl_modification.yml | 7 +- .../windows_ad_gpo_new_cse_addition.yml | 8 +- .../windows_ad_hidden_ou_creation.yml | 7 +- .../windows_ad_object_owner_updated.yml | 7 +- ...s_ad_suspicious_attribute_modification.yml | 7 +- ...windows_ad_suspicious_gpo_modification.yml | 8 +- ...mber_of_cloud_infrastructure_api_calls.yml | 5 +- ...gh_number_of_cloud_instances_destroyed.yml | 5 +- ...igh_number_of_cloud_instances_launched.yml | 5 +- ...mber_of_cloud_security_group_api_calls.yml | 5 +- .../cloud/asl_aws_create_access_key.yml | 35 +++-- ..._policy_version_to_allow_all_resources.yml | 48 ++++-- ..._aws_credential_access_getpassworddata.yml | 46 ++++-- ...s_credential_access_rds_password_reset.yml | 44 ++++-- ..._aws_defense_evasion_delete_cloudtrail.yml | 35 +++-- ...se_evasion_delete_cloudwatch_log_group.yml | 33 +++- ...fense_evasion_impair_security_services.yml | 37 +++-- ...aws_defense_evasion_putbucketlifecycle.yml | 39 +++-- ...efense_evasion_stop_logging_cloudtrail.yml | 39 +++-- ..._aws_defense_evasion_update_cloudtrail.yml | 37 +++-- ...ontainer_upload_outside_business_hours.yml | 40 +++-- ..._aws_ecr_container_upload_unknown_user.yml | 35 ++++- .../asl_aws_iam_successful_group_deletion.yml | 34 +++-- ...s_multi_factor_authentication_disabled.yml | 39 +++-- ...ntrol_list_created_with_all_open_ports.yml | 58 ++++--- ...ws_network_access_control_list_deleted.yml | 49 ++++-- ...aws_new_mfa_method_registered_for_user.yml | 36 +++-- .../cloud/asl_aws_updateloginprofile.yml | 52 +++++-- ...sole_login_failed_during_mfa_challenge.yml | 5 +- ..._policy_version_to_allow_all_resources.yml | 5 +- detections/cloud/aws_createaccesskey.yml | 5 +- detections/cloud/aws_createloginprofile.yml | 5 +- .../aws_credential_access_failed_login.yml | 8 +- .../aws_credential_access_getpassworddata.yml | 8 +- ...s_credential_access_rds_password_reset.yml | 7 +- .../aws_defense_evasion_delete_cloudtrail.yml | 5 +- ...se_evasion_delete_cloudwatch_log_group.yml | 5 +- ...fense_evasion_impair_security_services.yml | 5 +- ...aws_defense_evasion_putbucketlifecycle.yml | 8 +- ...efense_evasion_stop_logging_cloudtrail.yml | 5 +- .../aws_defense_evasion_update_cloudtrail.yml | 5 +- ...s_ecr_container_scanning_findings_high.yml | 5 +- ...ing_findings_low_informational_unknown.yml | 5 +- ...ecr_container_scanning_findings_medium.yml | 5 +- ...ontainer_upload_outside_business_hours.yml | 5 +- .../aws_ecr_container_upload_unknown_user.yml | 5 +- ...mber_of_failed_authentications_from_ip.yml | 5 +- .../aws_iam_successful_group_deletion.yml | 5 +- ...s_multi_factor_authentication_disabled.yml | 8 +- ..._multiple_failed_mfa_requests_for_user.yml | 5 +- ..._users_failing_to_authenticate_from_ip.yml | 5 +- ...ntrol_list_created_with_all_open_ports.yml | 5 +- ...ws_network_access_control_list_deleted.yml | 5 +- ...aws_new_mfa_method_registered_for_user.yml | 5 +- .../cloud/aws_setdefaultpolicyversion.yml | 5 +- ...uccessful_single_factor_authentication.yml | 8 +- ...mber_of_failed_authentications_from_ip.yml | 8 +- detections/cloud/aws_updateloginprofile.yml | 5 +- ...ure_active_directory_high_risk_sign_in.yml | 8 +- ...pplication_administrator_role_assigned.yml | 5 +- ...entication_failed_during_mfa_challenge.yml | 8 +- ...azure_ad_azurehound_useragent_detected.yml | 2 +- .../azure_ad_device_code_authentication.yml | 5 +- .../azure_ad_external_guest_user_invited.yml | 2 +- ...ber_of_failed_authentications_for_user.yml | 5 +- ...mber_of_failed_authentications_from_ip.yml | 5 +- ...d_multi_factor_authentication_disabled.yml | 8 +- ...ti_source_failed_authentications_spike.yml | 8 +- ..._multiple_failed_mfa_requests_for_user.yml | 8 +- ..._users_failing_to_authenticate_from_ip.yml | 8 +- .../azure_ad_new_custom_domain_added.yml | 5 +- .../azure_ad_new_federated_domain_added.yml | 5 +- .../azure_ad_new_mfa_method_registered.yml | 5 +- ..._ad_new_mfa_method_registered_for_user.yml | 5 +- .../cloud/azure_ad_pim_role_assigned.yml | 5 +- ...azure_ad_pim_role_assignment_activated.yml | 5 +- .../azure_ad_privileged_role_assigned.yml | 5 +- ...ged_role_assigned_to_service_principal.yml | 5 +- ...azure_ad_service_principal_enumeration.yml | 2 +- ...rvice_principal_new_client_credentials.yml | 5 +- ...azure_ad_service_principal_owner_added.yml | 2 +- ...service_principal_privilege_escalation.yml | 45 ++++-- ...sful_authentication_from_different_ips.yml | 5 +- ...d_successful_powershell_authentication.yml | 8 +- ...uccessful_single_factor_authentication.yml | 8 +- ...e_ad_tenant_wide_admin_consent_granted.yml | 5 +- ...mber_of_failed_authentications_from_ip.yml | 8 +- ...ure_ad_user_enabled_and_password_reset.yml | 2 +- ..._ad_user_immutableid_attribute_updated.yml | 2 +- .../azure_automation_account_created.yml | 5 +- .../azure_automation_runbook_created.yml | 5 +- .../cloud/azure_runbook_webhook_created.yml | 5 +- ...ance_created_by_previously_unseen_user.yml | 5 +- ...nce_modified_by_previously_unseen_user.yml | 5 +- .../detect_aws_console_login_by_new_user.yml | 7 +- ...ws_console_login_by_user_from_new_city.yml | 7 +- ...console_login_by_user_from_new_country.yml | 7 +- ..._console_login_by_user_from_new_region.yml | 7 +- ...entication_failed_during_mfa_challenge.yml | 8 +- ...p_multi_factor_authentication_disabled.yml | 8 +- ..._multiple_failed_mfa_requests_for_user.yml | 8 +- ..._users_failing_to_authenticate_from_ip.yml | 8 +- ...uccessful_single_factor_authentication.yml | 8 +- ...mber_of_failed_authentications_from_ip.yml | 8 +- ...thub_actions_disable_security_workflow.yml | 5 +- detections/cloud/github_dependabot_alert.yml | 5 +- .../github_pull_request_from_unknown_user.yml | 5 +- .../gsuite_drive_share_in_external_email.yml | 5 +- .../gsuite_email_suspicious_attachment.yml | 5 +- ...ail_suspicious_subject_with_attachment.yml | 5 +- ...mail_with_known_abuse_web_service_link.yml | 5 +- ...ail_with_attachment_to_external_domain.yml | 5 +- .../gsuite_suspicious_shared_file_name.yml | 5 +- ...of_login_failures_from_a_single_source.yml | 5 +- ...365_add_app_role_assignment_grant_user.yml | 5 +- .../cloud/o365_added_service_principal.yml | 5 +- .../cloud/o365_advanced_audit_disabled.yml | 5 +- ...application_available_to_other_tenants.yml | 5 +- ...applicationimpersonation_role_assigned.yml | 5 +- .../cloud/o365_bypass_mfa_via_trusted_ip.yml | 5 +- ...365_compliance_content_search_exported.yml | 5 +- ...o365_compliance_content_search_started.yml | 5 +- ...5_elevated_mailbox_permission_assigned.yml | 5 +- ...email_access_by_security_administrator.yml | 7 +- ...mail_reported_by_admin_found_malicious.yml | 5 +- ...email_reported_by_user_found_malicious.yml | 5 +- .../o365_email_security_feature_changed.yml | 7 +- .../o365_email_suspicious_behavior_alert.yml | 5 +- .../o365_email_transport_rule_changed.yml | 67 ++++++++ ...ber_of_failed_authentications_for_user.yml | 5 +- .../o365_high_privilege_role_granted.yml | 5 +- .../o365_mailbox_email_forwarding_enabled.yml | 5 +- ...ailbox_folder_read_permission_assigned.yml | 5 +- ...mailbox_folder_read_permission_granted.yml | 5 +- ...box_inbox_folder_shared_with_all_users.yml | 5 +- ...box_read_access_granted_to_application.yml | 8 +- ...ti_source_failed_authentications_spike.yml | 8 +- ...le_os_vendors_authenticating_from_user.yml | 66 ++++++++ ..._users_failing_to_authenticate_from_ip.yml | 8 +- ...o365_new_email_forwarding_rule_created.yml | 5 +- ...o365_new_email_forwarding_rule_enabled.yml | 5 +- .../cloud/o365_new_federated_domain_added.yml | 5 +- .../cloud/o365_new_mfa_method_registered.yml | 5 +- .../cloud/o365_privileged_role_assigned.yml | 5 +- ...ged_role_assigned_to_service_principal.yml | 5 +- .../cloud/o365_safe_links_detection.yml | 5 +- ...ecurity_and_compliance_alert_triggered.yml | 5 +- ...rvice_principal_new_client_credentials.yml | 5 +- ...service_principal_privilege_escalation.yml | 39 +++-- .../o365_sharepoint_malware_detection.yml | 5 +- ..._sharepoint_suspicious_search_behavior.yml | 67 ++++++++ ...o365_tenant_wide_admin_consent_granted.yml | 5 +- ...ntelligence_suspicious_email_delivered.yml | 5 +- ..._intelligence_suspicious_file_detected.yml | 5 +- .../cloud/o365_zap_activity_detection.yml | 5 +- ...isk_rule_for_dev_sec_ops_by_repository.yml | 5 +- .../account_discovery_with_net_app.yml | 5 +- .../attempt_to_stop_security_service.yml | 5 +- ...dential_dump_from_registry_via_reg_exe.yml | 5 +- ...ovisioning_from_previously_unseen_city.yml | 4 +- ...sioning_from_previously_unseen_country.yml | 14 +- ...isioning_from_previously_unseen_region.yml | 4 +- .../change_default_file_association.yml | 5 +- ...cmdline_tool_not_executed_in_cmd_shell.yml | 5 +- .../correlation_by_repository_and_risk.yml | 5 +- .../correlation_by_user_and_risk.yml | 5 +- ...ate_local_admin_accounts_using_net_exe.yml | 5 +- .../deprecated/deleting_of_net_users.yml | 18 +-- ...ivity_related_to_pass_the_hash_attacks.yml | 5 +- ...ct_critical_alerts_from_security_tools.yml | 38 +---- ...to_phishing_sites_leveraging_evilginx2.yml | 6 +- .../detect_mimikatz_using_loaded_images.yml | 5 +- .../detect_new_api_calls_from_user_roles.yml | 6 +- .../detect_new_user_aws_console_login.yml | 6 +- ...system_network_configuration_discovery.yml | 21 +-- .../detect_webshell_exploit_behavior.yml | 5 +- .../deprecated/disabling_net_user_account.yml | 18 +-- .../domain_account_discovery_with_net_app.yml | 5 +- .../domain_group_discovery_with_net.yml | 5 +- .../elevated_group_discovery_with_net.yml | 5 +- .../deprecated/excel_spawning_powershell.yml | 5 +- .../excel_spawning_windows_script_host.yml | 12 +- .../excessive_service_stop_attempt.yml | 17 ++- .../deprecated/excessive_usage_of_net_app.yml | 19 +-- .../extraction_of_registry_hives.yml | 5 +- .../known_services_killed_by_ransomware.yml | 10 +- .../linux_auditd_find_private_keys.yml | 5 +- .../local_account_discovery_with_net.yml | 5 +- .../mshtml_module_load_in_office_product.yml | 5 +- ...h_invalid_credentials_from_the_same_ip.yml | 7 +- .../deprecated/net_localgroup_discovery.yml | 5 +- .../network_connection_discovery_with_net.yml | 18 +-- ...o365_suspicious_admin_email_forwarding.yml | 5 +- .../o365_suspicious_rights_delegation.yml | 8 +- .../o365_suspicious_user_email_forwarding.yml | 5 +- .../office_application_drop_executable.yml | 5 +- ...ice_application_spawn_regsvr32_process.yml | 5 +- ...ice_application_spawn_rundll32_process.yml | 5 +- ...office_document_creating_schedule_task.yml | 5 +- .../office_document_executing_macro_code.yml | 5 +- ...ment_spawned_child_process_to_download.yml | 5 +- .../office_product_spawn_cmd_process.yml | 5 +- .../office_product_spawning_bitsadmin.yml | 5 +- .../office_product_spawning_certutil.yml | 5 +- .../office_product_spawning_mshta.yml | 5 +- ..._product_spawning_rundll32_with_no_dll.yml | 5 +- ...e_product_spawning_windows_script_host.yml | 5 +- .../office_product_spawning_wmic.yml | 5 +- .../office_product_writing_cab_or_inf.yml | 5 +- .../deprecated/office_spawning_control.yml | 5 +- .../okta_account_lockout_events.yml | 5 +- .../deprecated/okta_failed_sso_attempts.yml | 5 +- ..._login_failure_with_high_unknown_users.yml | 5 +- ...insight_suspected_passwordspray_attack.yml | 5 +- .../osquery_pack___coldroot_detection.yml | 2 +- .../password_policy_discovery_with_net.yml | 19 +-- .../remote_desktop_network_bruteforce.yml | 58 +++++++ .../remote_system_discovery_with_net.yml | 31 +--- .../suspicious_driver_loaded_path.yml | 9 +- .../suspicious_process_file_path.yml | 10 +- .../deprecated/suspicious_rundll32_rename.yml | 8 +- ...dows_command_shell_fetch_env_variables.yml | 17 ++- ...indows_dll_search_order_hijacking_hunt.yml | 5 +- .../windows_lateral_tool_transfer_remcom.yml | 2 +- .../windows_modify_registry_reg_restore.yml | 18 +-- ...ndows_msiexec_with_network_connections.yml | 19 +-- ...ows_network_share_interaction_with_net.yml | 14 +- .../windows_office_product_spawning_msdt.yml | 5 +- .../windows_query_registry_reg_save.yml | 16 +- ...id_account_with_never_expires_password.yml | 17 ++- .../deprecated/winword_spawning_cmd.yml | 5 +- .../winword_spawning_powershell.yml | 5 +- .../winword_spawning_windows_script_host.yml | 5 +- .../7zip_commandline_to_smb_share_path.yml | 5 +- .../access_lsass_memory_for_dump_creation.yml | 5 +- .../active_setup_registry_autostart.yml | 5 +- ...d_defaultuser_and_password_in_registry.yml | 5 +- .../add_or_set_windows_defender_exclusion.yml | 5 +- .../adsisearcher_account_discovery.yml | 5 +- ..._file_and_printing_sharing_in_firewall.yml | 5 +- ...ound_traffic_by_firewall_rule_registry.yml | 5 +- ...allow_inbound_traffic_in_firewall_rule.yml | 5 +- .../allow_network_discovery_in_firewall.yml | 5 +- .../endpoint/anomalous_usage_of_7zip.yml | 5 +- .../endpoint/any_powershell_downloadfile.yml | 8 +- .../any_powershell_downloadstring.yml | 5 +- .../endpoint/attacker_tools_on_endpoint.yml | 7 +- ..._to_add_certificate_to_untrusted_store.yml | 5 +- .../auto_admin_logon_registry_entry.yml | 5 +- .../endpoint/batch_file_write_to_system32.yml | 5 +- .../bcdedit_failure_recovery_modification.yml | 2 +- detections/endpoint/bits_job_persistence.yml | 2 +- .../endpoint/bitsadmin_download_file.yml | 2 +- ...load_with_urlcache_and_split_arguments.yml | 2 +- ...oad_with_verifyctl_and_split_arguments.yml | 2 +- .../certutil_exe_certificate_extraction.yml | 2 +- .../certutil_with_decode_argument.yml | 2 +- .../check_elevated_cmd_using_whoami.yml | 2 +- ...ar_unallocated_sector_using_cipher_app.yml | 5 +- .../endpoint/clop_common_exec_parameter.yml | 2 +- ...cmd_carry_out_string_command_parameter.yml | 5 +- .../endpoint/cmd_echo_pipe___escalation.yml | 6 +- .../endpoint/cmlua_or_cmstplua_uac_bypass.yml | 5 +- .../endpoint/common_ransomware_extensions.yml | 2 +- .../endpoint/conti_common_exec_parameter.yml | 2 +- ..._loading_from_world_writable_directory.yml | 5 +- ...or_delete_windows_shares_using_net_exe.yml | 5 +- .../create_remote_thread_into_lsass.yml | 5 +- .../creation_of_lsass_dump_with_taskmgr.yml | 5 +- .../endpoint/creation_of_shadow_copy.yml | 5 +- ...f_shadow_copy_with_wmic_and_powershell.yml | 5 +- ...ping_via_copy_command_from_shadow_copy.yml | 5 +- ...ial_dumping_via_symlink_to_shadow_copy.yml | 5 +- .../csc_net_on_the_fly_compilation.yml | 5 +- .../endpoint/deleting_shadow_copies.yml | 2 +- ...tect_azurehound_command_line_arguments.yml | 12 +- .../detect_azurehound_file_modifications.yml | 12 +- ...y_with_powershell_script_block_logging.yml | 7 +- .../detect_certipy_file_modifications.yml | 2 +- ...f_shadowcopy_with_script_block_logging.yml | 5 +- ...redential_dumping_through_lsass_access.yml | 5 +- ...e_with_powershell_script_block_logging.yml | 5 +- ...cessive_account_lockouts_from_endpoint.yml | 5 +- ...detect_excessive_user_account_lockouts.yml | 5 +- .../endpoint/detect_exchange_web_shell.yml | 31 ++-- .../endpoint/detect_html_help_renamed.yml | 5 +- .../detect_html_help_spawn_child_process.yml | 5 +- .../detect_html_help_url_in_command_line.yml | 5 +- ...l_help_using_infotech_storage_handlers.yml | 5 +- ...z_with_powershell_script_block_logging.yml | 2 +- .../detect_mshta_inline_hta_execution.yml | 5 +- detections/endpoint/detect_mshta_renamed.yml | 5 +- .../detect_mshta_url_in_command_line.yml | 5 +- .../detect_new_local_admin_account.yml | 5 +- .../detect_outlook_exe_writing_a_zip_file.yml | 5 +- ...word_spray_attack_behavior_from_source.yml | 5 +- ...password_spray_attack_behavior_on_user.yml | 5 +- ...nterception_by_creation_of_program_exe.yml | 5 +- ...ohibited_applications_spawning_cmd_exe.yml | 5 +- .../detect_psexec_with_accepteula_flag.yml | 5 +- .../detect_rclone_command_line_usage.yml | 2 +- .../detect_regasm_spawning_a_process.yml | 5 +- .../detect_regasm_with_network_connection.yml | 5 +- ..._regasm_with_no_command_line_arguments.yml | 5 +- .../detect_regsvcs_spawning_a_process.yml | 5 +- ...detect_regsvcs_with_network_connection.yml | 5 +- ...regsvcs_with_no_command_line_arguments.yml | 5 +- ...ct_regsvr32_application_control_bypass.yml | 5 +- ...tect_remote_access_software_usage_file.yml | 9 +- ..._remote_access_software_usage_fileinfo.yml | 12 +- ...t_remote_access_software_usage_process.yml | 9 +- ..._remote_access_software_usage_registry.yml | 3 +- detections/endpoint/detect_renamed_7_zip.yml | 5 +- detections/endpoint/detect_renamed_psexec.yml | 8 +- detections/endpoint/detect_renamed_winrar.yml | 8 +- .../endpoint/detect_rtlo_in_file_name.yml | 5 +- .../endpoint/detect_rtlo_in_process.yml | 5 +- ...2_application_control_bypass___advpack.yml | 5 +- ..._application_control_bypass___setupapi.yml | 5 +- ..._application_control_bypass___syssetup.yml | 5 +- .../detect_rundll32_inline_hta_execution.yml | 5 +- ...tect_sharphound_command_line_arguments.yml | 12 +- .../detect_sharphound_file_modifications.yml | 12 +- .../endpoint/detect_sharphound_usage.yml | 12 +- ...ssnames_using_pretrained_model_in_dsdl.yml | 2 +- ..._cmd_exe_to_launch_script_interpreters.yml | 5 +- ...ect_wmi_event_subscription_persistence.yml | 5 +- .../disable_amsi_through_registry.yml | 5 +- .../disable_defender_antivirus_registry.yml | 5 +- ...able_defender_blockatfirstseen_feature.yml | 5 +- ...disable_defender_enhanced_notification.yml | 5 +- .../disable_defender_mpengine_registry.yml | 5 +- .../disable_defender_spynet_reporting.yml | 5 +- ...efender_submit_samples_consent_feature.yml | 5 +- .../endpoint/disable_etw_through_registry.yml | 5 +- .../endpoint/disable_logs_using_wevtutil.yml | 5 +- detections/endpoint/disable_registry_tool.yml | 7 +- detections/endpoint/disable_schedule_task.yml | 5 +- .../endpoint/disable_show_hidden_files.yml | 10 +- .../disable_uac_remote_restriction.yml | 5 +- .../endpoint/disable_windows_app_hotkeys.yml | 7 +- .../disable_windows_behavior_monitoring.yml | 5 +- ...disable_windows_smartscreen_protection.yml | 5 +- ...thentication_discovery_with_get_aduser.yml | 5 +- ...uthentication_discovery_with_powerview.yml | 5 +- .../endpoint/disabling_cmd_application.yml | 7 +- .../endpoint/disabling_controlpanel.yml | 7 +- .../endpoint/disabling_defender_services.yml | 5 +- .../disabling_firewall_with_netsh.yml | 5 +- ...isabling_folderoptions_windows_feature.yml | 5 +- .../endpoint/disabling_norun_windows_app.yml | 7 +- .../disabling_remote_user_account_control.yml | 5 +- .../endpoint/disabling_task_manager.yml | 5 +- .../dns_exfiltration_using_nslookup_app.yml | 2 +- .../domain_account_discovery_with_dsquery.yml | 5 +- .../domain_account_discovery_with_wmic.yml | 5 +- ...main_group_discovery_with_adsisearcher.yml | 5 +- .../domain_group_discovery_with_dsquery.yml | 5 +- .../domain_group_discovery_with_wmic.yml | 5 +- .../endpoint/drop_icedid_license_dat.yml | 5 +- .../endpoint/dsquery_domain_discovery.yml | 2 +- .../endpoint/dump_lsass_via_comsvcs_dll.yml | 5 +- .../endpoint/dump_lsass_via_procdump.yml | 5 +- ...levated_group_discovery_with_powerview.yml | 5 +- .../elevated_group_discovery_with_wmic.yml | 5 +- detections/endpoint/esentutl_sam_copy.yml | 5 +- detections/endpoint/etw_registry_disabled.yml | 7 +- detections/endpoint/eventvwr_uac_bypass.yml | 5 +- ...r_of_service_control_start_as_disabled.yml | 5 +- .../excessive_usage_of_sc_service_utility.yml | 5 +- .../endpoint/excessive_usage_of_taskkill.yml | 5 +- .../exchange_powershell_module_usage.yml | 5 +- ...le_written_in_administrative_smb_share.yml | 5 +- ...cute_javascript_with_jscript_com_clsid.yml | 5 +- ...ution_of_file_with_multiple_extensions.yml | 5 +- .../endpoint/file_with_samsam_extension.yml | 2 +- .../firewall_allowed_program_enable.yml | 5 +- ...irst_time_seen_running_windows_service.yml | 5 +- detections/endpoint/fodhelper_uac_bypass.yml | 5 +- .../endpoint/get_aduser_with_powershell.yml | 5 +- ...et_aduser_with_powershell_script_block.yml | 5 +- .../get_domainuser_with_powershell.yml | 5 +- ...omainuser_with_powershell_script_block.yml | 5 +- .../get_wmiobject_group_discovery.yml | 5 +- ...up_discovery_with_script_block_logging.yml | 5 +- .../endpoint/getadgroup_with_powershell.yml | 5 +- ...etadgroup_with_powershell_script_block.yml | 5 +- .../getdomaingroup_with_powershell.yml | 5 +- ...maingroup_with_powershell_script_block.yml | 5 +- .../endpoint/getlocaluser_with_powershell.yml | 5 +- ...localuser_with_powershell_script_block.yml | 7 +- .../getwmiobject_ds_group_with_powershell.yml | 5 +- ..._ds_group_with_powershell_script_block.yml | 5 +- .../getwmiobject_ds_user_with_powershell.yml | 5 +- ...t_ds_user_with_powershell_script_block.yml | 5 +- ...wmiobject_user_account_with_powershell.yml | 5 +- ...r_account_with_powershell_script_block.yml | 7 +- ...no_command_line_arguments_with_network.yml | 2 +- ...dless_browser_mockbin_or_mocky_request.yml | 2 +- .../hide_user_account_from_sign_in_screen.yml | 5 +- ..._files_and_directories_with_attrib_exe.yml | 5 +- ...did_exfiltrated_archived_file_creation.yml | 5 +- ...ateral_movement_commandline_parameters.yml | 5 +- ...ovement_smbexec_commandline_parameters.yml | 5 +- ...ovement_wmiexec_commandline_parameters.yml | 5 +- ...ion_on_remote_endpoint_with_powershell.yml | 5 +- .../jscript_execution_using_cscript_app.yml | 5 +- ...asting_spn_request_with_rc4_encryption.yml | 5 +- ...on_flag_disabled_in_useraccountcontrol.yml | 8 +- ...tication_flag_disabled_with_powershell.yml | 5 +- ...ce_ticket_request_using_rc4_encryption.yml | 5 +- .../endpoint/kerberos_user_enumeration.yml | 5 +- ...nt_manipulation_of_ssh_config_and_keys.yml | 7 +- ...add_files_in_known_crontab_directories.yml | 5 +- .../endpoint/linux_add_user_account.yml | 5 +- ...ux_adding_crontab_using_list_parameter.yml | 5 +- .../linux_apt_get_privilege_escalation.yml | 5 +- .../linux_apt_privilege_escalation.yml | 5 +- .../linux_at_allow_config_file_creation.yml | 5 +- .../linux_at_application_execution.yml | 5 +- .../linux_auditd_add_user_account.yml | 5 +- .../linux_auditd_add_user_account_type.yml | 5 +- .../linux_auditd_at_application_execution.yml | 5 +- ...linux_auditd_change_file_owner_to_root.yml | 42 +++-- ...ditd_disable_or_modify_system_firewall.yml | 5 +- .../linux_auditd_doas_conf_file_creation.yml | 5 +- .../linux_auditd_doas_tool_execution.yml | 5 +- ...linux_auditd_edit_cron_table_parameter.yml | 5 +- ...file_permission_modification_via_chmod.yml | 10 +- ...le_permissions_modification_via_chattr.yml | 39 +++-- ...ind_credentials_from_password_managers.yml | 26 +++- ..._find_credentials_from_password_stores.yml | 45 ++++-- .../linux_auditd_find_ssh_private_keys.yml | 45 ++++-- ..._hidden_files_and_directories_creation.yml | 8 +- ...ert_kernel_module_using_insmod_utility.yml | 11 +- ...l_kernel_module_using_modprobe_utility.yml | 41 +++-- ...ditd_kernel_module_using_rmmod_utility.yml | 5 +- ..._auditd_nopasswd_entry_in_sudoers_file.yml | 8 +- ...ss_or_modification_of_sshd_config_file.yml | 5 +- ...td_possible_access_to_credential_files.yml | 8 +- ...auditd_possible_access_to_sudoers_file.yml | 8 +- ...cronjob_entry_on_existing_cronjob_file.yml | 11 +- ...ux_auditd_preload_hijack_library_calls.yml | 8 +- ...auditd_preload_hijack_via_preload_file.yml | 8 +- ...ivate_keys_and_certificate_enumeration.yml | 47 ++++-- .../linux_auditd_service_restarted.yml | 5 +- .../endpoint/linux_auditd_service_started.yml | 9 +- ...inux_auditd_setuid_using_chmod_utility.yml | 5 +- ...nux_auditd_setuid_using_setcap_utility.yml | 45 ++++-- .../linux_auditd_sudo_or_su_execution.yml | 42 +++-- ..._unix_shell_configuration_modification.yml | 5 +- ...inux_auditd_unload_module_via_modprobe.yml | 43 ++++-- .../linux_awk_privilege_escalation.yml | 5 +- .../linux_busybox_privilege_escalation.yml | 5 +- .../linux_c89_privilege_escalation.yml | 5 +- .../linux_c99_privilege_escalation.yml | 5 +- .../linux_change_file_owner_to_root.yml | 5 +- ...x_common_process_for_elevation_control.yml | 8 +- .../linux_composer_privilege_escalation.yml | 5 +- .../linux_cpulimit_privilege_escalation.yml | 5 +- .../linux_csvtool_privilege_escalation.yml | 5 +- .../linux_data_destruction_command.yml | 2 +- .../endpoint/linux_decode_base64_to_shell.yml | 2 +- .../endpoint/linux_deletion_of_cron_jobs.yml | 7 +- .../linux_deletion_of_init_daemon_script.yml | 7 +- .../endpoint/linux_deletion_of_services.yml | 7 +- .../linux_deletion_of_ssl_certificate.yml | 7 +- .../linux_doas_conf_file_creation.yml | 5 +- .../endpoint/linux_doas_tool_execution.yml | 5 +- .../linux_docker_privilege_escalation.yml | 5 +- .../linux_edit_cron_table_parameter.yml | 5 +- .../linux_emacs_privilege_escalation.yml | 5 +- ...ile_created_in_kernel_driver_directory.yml | 5 +- ...x_file_creation_in_init_boot_directory.yml | 8 +- ...nux_file_creation_in_profile_directory.yml | 5 +- .../linux_find_privilege_escalation.yml | 5 +- .../linux_gdb_privilege_escalation.yml | 5 +- .../linux_gem_privilege_escalation.yml | 5 +- .../linux_gnu_awk_privilege_escalation.yml | 5 +- ...quency_of_file_deletion_in_boot_folder.yml | 7 +- ...equency_of_file_deletion_in_etc_folder.yml | 7 +- .../linux_impair_defenses_process_kill.yml | 5 +- ...ndicator_removal_service_file_deletion.yml | 5 +- ...ert_kernel_module_using_insmod_utility.yml | 5 +- ...l_kernel_module_using_modprobe_utility.yml | 5 +- .../linux_iptables_firewall_modification.yml | 8 +- .../endpoint/linux_java_spawning_shell.yml | 2 +- .../linux_kernel_module_enumeration.yml | 2 +- ...orker_process_in_writable_process_path.yml | 5 +- .../linux_make_privilege_escalation.yml | 5 +- .../linux_mysql_privilege_escalation.yml | 5 +- .../linux_ngrok_reverse_proxy_usage.yml | 2 +- .../linux_node_privilege_escalation.yml | 5 +- .../linux_nopasswd_entry_in_sudoers_file.yml | 8 +- ...ted_files_or_information_base64_decode.yml | 2 +- .../linux_octave_privilege_escalation.yml | 5 +- .../linux_openvpn_privilege_escalation.yml | 5 +- .../linux_php_privilege_escalation.yml | 5 +- .../linux_pkexec_privilege_escalation.yml | 2 +- ...ss_or_modification_of_sshd_config_file.yml | 5 +- ...ux_possible_access_to_credential_files.yml | 8 +- .../linux_possible_access_to_sudoers_file.yml | 8 +- ...append_command_to_at_allow_config_file.yml | 5 +- ..._append_command_to_profile_config_file.yml | 5 +- ...cronjob_entry_on_existing_cronjob_file.yml | 5 +- ...sible_cronjob_modification_with_editor.yml | 5 +- .../linux_possible_ssh_key_file_creation.yml | 5 +- .../linux_preload_hijack_library_calls.yml | 8 +- .../endpoint/linux_proxy_socks_curl.yml | 2 +- .../linux_puppet_privilege_escalation.yml | 5 +- .../linux_rpm_privilege_escalation.yml | 5 +- .../linux_ruby_privilege_escalation.yml | 5 +- ...vice_file_created_in_systemd_directory.yml | 5 +- .../endpoint/linux_service_restarted.yml | 5 +- .../linux_service_started_or_enabled.yml | 5 +- .../linux_setuid_using_chmod_utility.yml | 5 +- .../linux_setuid_using_setcap_utility.yml | 5 +- .../linux_sqlite3_privilege_escalation.yml | 5 +- ...linux_ssh_authorized_keys_modification.yml | 2 +- ...nux_ssh_remote_services_script_execute.yml | 2 +- ...ux_stdout_redirection_to_dev_null_file.yml | 5 +- .../endpoint/linux_sudo_or_su_execution.yml | 5 +- .../linux_sudoers_tmp_file_creation.yml | 8 +- ..._unix_shell_enable_all_sysrq_functions.yml | 5 +- .../linux_visudo_utility_execution.yml | 5 +- .../endpoint/loading_of_dynwrapx_module.yml | 5 +- .../local_account_discovery_with_wmic.yml | 5 +- .../logon_script_event_trigger_execution.yml | 5 +- detections/endpoint/macos_lolbin.yml | 5 +- .../endpoint/mailsniper_invoke_functions.yml | 5 +- ...cious_powershell_executed_as_a_service.yml | 5 +- ...hell_process___execution_policy_bypass.yml | 8 +- ...ll_process_with_obfuscation_techniques.yml | 5 +- .../microsoft_defender_atp_alerts.yml | 2 +- .../microsoft_defender_incident_alerts.yml | 2 +- ...z_passtheticket_commandline_parameters.yml | 5 +- .../mmc_lolbas_execution_process_spawn.yml | 5 +- ...nitor_registry_keys_for_print_monitors.yml | 5 +- ...on_service_writing_active_server_pages.yml | 9 +- ..._scripting_process_loading_ldap_module.yml | 5 +- ...s_scripting_process_loading_wmi_module.yml | 5 +- ...d_suspicious_spawned_by_script_process.yml | 5 +- ..._spawning_rundll32_or_regsvr32_process.yml | 5 +- ...msi_module_loaded_by_non_system_binary.yml | 5 +- .../msmpeng_application_dll_side_loading.yml | 5 +- .../endpoint/net_profiler_uac_bypass.yml | 5 +- ...work_discovery_using_route_windows_app.yml | 5 +- ...active_directory_web_services_protocol.yml | 12 +- .../endpoint/nishang_powershelltcponeline.yml | 5 +- ...e_process_accessing_chrome_default_dir.yml | 8 +- ...fox_process_access_firefox_profile_dir.yml | 5 +- ...notepad_with_no_command_line_arguments.yml | 2 +- detections/endpoint/ntdsutil_export_ntds.yml | 5 +- .../overwriting_accessibility_binaries.yml | 5 +- ...mission_modification_using_takeown_app.yml | 8 +- .../endpoint/ping_sleep_batch_command.yml | 5 +- .../possible_browser_pass_view_parameter.yml | 5 +- ...ible_lateral_movement_powershell_spawn.yml | 7 +- ...twork_configuration_discovery_activity.yml | 2 +- .../endpoint/powershell_4104_hunting.yml | 8 +- ...connect_to_internet_with_hidden_window.yml | 5 +- ..._hijacking_inprocserver32_modification.yml | 7 +- .../powershell_creating_thread_mutex.yml | 5 +- ...powershell_disable_security_monitoring.yml | 5 +- .../powershell_domain_enumeration.yml | 5 +- .../powershell_enable_powershell_remoting.yml | 5 +- ...powershell_enable_smb1protocol_feature.yml | 5 +- .../powershell_execute_com_object.yml | 7 +- ...s_process_injection_via_getprocaddress.yml | 5 +- ...script_contains_base64_encoded_content.yml | 5 +- .../powershell_get_localgroup_discovery.yml | 5 +- ...up_discovery_with_script_block_logging.yml | 5 +- .../powershell_load_module_in_meterpreter.yml | 5 +- ...ding_dotnet_into_memory_via_reflection.yml | 40 +++-- .../powershell_processing_stream_of_data.yml | 5 +- ...rshell_remote_services_add_trustedhost.yml | 5 +- ...hell_remove_windows_defender_directory.yml | 5 +- .../powershell_start_bitstransfer.yml | 2 +- ...wershell_using_memory_as_backing_store.yml | 5 +- ...ll_windows_defender_exclusion_commands.yml | 5 +- ...nt_automatic_repair_mode_using_bcdedit.yml | 2 +- .../print_processor_registry_autostart.yml | 5 +- .../print_spooler_adding_a_printer_driver.yml | 5 +- ...print_spooler_failed_to_load_a_plug_in.yml | 5 +- ...eating_lnk_file_in_suspicious_location.yml | 5 +- .../process_kill_base_on_file_path.yml | 5 +- .../endpoint/processes_launching_netsh.yml | 5 +- ...randomly_generated_scheduled_task_name.yml | 5 +- ...andomly_generated_windows_service_name.yml | 5 +- .../recon_avproduct_through_pwh_or_wmi.yml | 2 +- ...rsive_delete_of_directory_in_batch_cmd.yml | 5 +- ...ulating_windows_services_registry_keys.yml | 5 +- ...istry_keys_for_creating_shim_databases.yml | 5 +- .../registry_keys_used_for_persistence.yml | 8 +- ...try_keys_used_for_privilege_escalation.yml | 5 +- ...2_silent_and_install_param_dll_loading.yml | 5 +- ...svr32_with_known_silent_switch_cmdline.yml | 5 +- ...mote_desktop_process_running_on_system.yml | 5 +- ..._instantiation_via_dcom_and_powershell.yml | 5 +- ...n_via_dcom_and_powershell_script_block.yml | 5 +- ...instantiation_via_winrm_and_powershell.yml | 5 +- ..._via_winrm_and_powershell_script_block.yml | 5 +- ...cess_instantiation_via_winrm_and_winrs.yml | 5 +- .../rubeus_command_line_parameters.yml | 6 +- ...ticket_exports_through_winlogon_access.yml | 5 +- .../runas_execution_in_commandline.yml | 5 +- .../endpoint/rundll32_control_rundll_hunt.yml | 5 +- ...ontrol_rundll_world_writable_directory.yml | 5 +- detections/endpoint/rundll32_dnsquery.yml | 5 +- .../endpoint/rundll32_lockworkstation.yml | 5 +- ...undll32_process_creating_exe_dll_files.yml | 5 +- ...no_command_line_arguments_with_network.yml | 5 +- .../rundll_loading_dll_by_ordinal.yml | 5 +- .../endpoint/ryuk_wake_on_lan_command.yml | 5 +- .../sam_database_file_access_attempt.yml | 5 +- .../sc_exe_manipulating_windows_services.yml | 5 +- ..._by_app_connect_and_create_adsi_object.yml | 5 +- ...k_creation_on_remote_endpoint_using_at.yml | 5 +- ...eduled_task_deleted_or_created_via_cmd.yml | 8 +- ...led_task_initiation_on_remote_endpoint.yml | 5 +- ...htasks_scheduling_job_on_remote_system.yml | 5 +- .../schtasks_used_for_forcing_a_reboot.yml | 5 +- .../screensaver_event_trigger_execution.yml | 5 +- detections/endpoint/sdclt_uac_bypass.yml | 5 +- .../sdelete_application_execution.yml | 7 +- .../secretdumps_offline_ntds_dumping_tool.yml | 5 +- ...ceprincipalnames_discovery_with_setspn.yml | 2 +- ...ervices_lolbas_execution_process_spawn.yml | 5 +- ...ution_policy_to_unrestricted_or_bypass.yml | 5 +- .../endpoint/shim_database_file_creation.yml | 5 +- ...nstallation_with_suspicious_parameters.yml | 25 ++- .../endpoint/short_lived_windows_accounts.yml | 7 +- .../endpoint/silentcleanup_uac_bypass.yml | 5 +- .../single_letter_process_on_endpoint.yml | 5 +- detections/endpoint/slui_runas_elevated.yml | 5 +- .../endpoint/slui_spawning_a_process.yml | 5 +- .../endpoint/spoolsv_spawning_rundll32.yml | 5 +- .../spoolsv_suspicious_loaded_modules.yml | 5 +- .../spoolsv_suspicious_process_access.yml | 2 +- detections/endpoint/spoolsv_writing_a_dll.yml | 5 +- .../spoolsv_writing_a_dll___sysmon.yml | 5 +- ...uspicious_computer_account_name_change.yml | 5 +- .../endpoint/suspicious_copy_on_system32.yml | 5 +- .../suspicious_event_log_service_behavior.yml | 5 +- .../suspicious_icedid_rundll32_cmdline.yml | 5 +- ...icious_kerberos_service_ticket_request.yml | 5 +- ...ous_microsoft_workflow_compiler_rename.yml | 7 +- .../endpoint/suspicious_msbuild_path.yml | 6 +- .../endpoint/suspicious_msbuild_rename.yml | 6 +- .../endpoint/suspicious_msbuild_spawn.yml | 5 +- .../suspicious_mshta_child_process.yml | 5 +- .../endpoint/suspicious_mshta_spawn.yml | 5 +- .../endpoint/suspicious_plistbuddy_usage.yml | 5 +- ...uspicious_plistbuddy_usage_via_osquery.yml | 5 +- ...ess_dns_query_known_abuse_web_services.yml | 5 +- ...picious_process_with_discord_dns_query.yml | 5 +- .../endpoint/suspicious_reg_exe_process.yml | 2 +- ...ious_regsvr32_register_suspicious_path.yml | 8 +- .../suspicious_rundll32_dllregisterserver.yml | 5 +- ...ous_rundll32_no_command_line_arguments.yml | 5 +- .../suspicious_rundll32_plugininit.yml | 5 +- .../endpoint/suspicious_rundll32_startw.yml | 5 +- ...s_scheduled_task_from_public_directory.yml | 8 +- ...picious_ticket_granting_ticket_request.yml | 5 +- .../endpoint/suspicious_wevtutil_usage.yml | 5 +- ...svchost_lolbas_execution_process_spawn.yml | 5 +- ...rocesses_run_from_unexpected_locations.yml | 5 +- .../system_user_discovery_with_query.yml | 9 +- .../time_provider_persistence_registry.yml | 5 +- .../uac_bypass_mmc_load_unsigned_dll.yml | 7 +- .../uac_bypass_with_colorui_com_object.yml | 5 +- .../endpoint/uninstall_app_using_msiexec.yml | 5 +- .../endpoint/unload_sysmon_filter_driver.yml | 5 +- .../unloading_amsi_via_reflection.yml | 7 +- ..._of_kerberos_service_tickets_requested.yml | 5 +- .../vbscript_execution_using_wscript_app.yml | 5 +- .../endpoint/verclsid_clsid_execution.yml | 5 +- detections/endpoint/w3wp_spawning_shell.yml | 5 +- .../wbemprox_com_object_execution.yml | 5 +- ...ss_connecting_to_ip_check_web_services.yml | 5 +- ...ss_token_manipulation_sedebugprivilege.yml | 8 +- ...lation_winlogon_duplicate_token_handle.yml | 5 +- ...ogon_duplicate_handle_in_uncommon_path.yml | 5 +- ...account_access_removal_via_logoff_exec.yml | 41 +++-- ...iscovery_for_none_disable_user_account.yml | 5 +- ...ows_ad_abnormal_object_access_activity.yml | 5 +- .../windows_ad_adminsdholder_acl_modified.yml | 2 +- ...s_ad_cross_domain_sid_history_addition.yml | 5 +- ...ows_ad_domain_replication_acl_addition.yml | 2 +- ...rivileged_account_sid_history_addition.yml | 5 +- ...s_ad_privileged_object_access_activity.yml | 5 +- ...tion_request_initiated_by_user_account.yml | 5 +- ...t_initiated_from_unsanctioned_location.yml | 5 +- ...ws_ad_same_domain_sid_history_addition.yml | 5 +- ...dows_ad_sid_history_attribute_modified.yml | 5 +- ...n_default_group_policy_object_modified.yml | 5 +- ...dows_admon_group_policy_object_created.yml | 5 +- ..._alternate_datastream___base64_content.yml | 5 +- ...ernate_datastream___executable_content.yml | 5 +- ...ternate_datastream___process_execution.yml | 5 +- .../windows_apache_benchmark_binary.yml | 2 +- ...windows_archive_collected_data_via_rar.yml | 8 +- ...ndows_attempt_to_stop_security_service.yml | 47 ++++-- .../endpoint/windows_autoit3_execution.yml | 2 +- ...roxy_execution_mavinject_dll_injection.yml | 5 +- ...indows_bitlockertogo_process_execution.yml | 4 +- ..._autostart_execution_in_startup_folder.yml | 5 +- .../endpoint/windows_bootloader_inventory.yml | 5 +- ...ws_cached_domain_credentials_reg_query.yml | 5 +- ...ws_certutil_download_with_url_argument.yml | 2 +- ...fault_file_association_for_no_file_ext.yml | 5 +- ..._tool_execution_from_non_shell_process.yml | 47 ++++-- ..._hijacking_inprocserver32_modification.yml | 5 +- ...s_command_shell_dcrat_forkbomb_payload.yml | 5 +- .../endpoint/windows_create_local_account.yml | 5 +- ...te_local_administrator_account_via_net.yml | 44 +++++- ...ential_dumping_lsass_memory_createdump.yml | 2 +- ...sword_stores_chrome_copied_in_temp_dir.yml | 5 +- ...from_web_browsers_saved_in_temp_folder.yml | 5 +- ...dows_credentials_in_registry_reg_query.yml | 5 +- ...ndows_curl_download_to_suspicious_path.yml | 2 +- ...dows_curl_upload_to_remote_destination.yml | 2 +- ...s_default_group_policy_object_modified.yml | 5 +- ...group_policy_object_modified_with_gpme.yml | 5 +- ...dows_defender_exclusion_registry_entry.yml | 5 +- ...ndows_delete_or_modify_system_firewall.yml | 5 +- ...indows_detect_network_scanner_behavior.yml | 143 ++++++++++-------- .../windows_disable_memory_crash_dump.yml | 2 +- ...s_disable_or_modify_tools_via_taskkill.yml | 5 +- ...indows_disable_or_stop_browser_process.yml | 7 +- ...ows_event_logging_disable_http_logging.yml | 8 +- .../windows_disableantispyware_registry.yml | 5 +- .../endpoint/windows_dism_remove_defender.yml | 5 +- ...earch_order_hijacking_hunt_with_sysmon.yml | 5 +- ...l_search_order_hijacking_with_iscsicpl.yml | 2 +- .../windows_dll_side_loading_in_calc.yml | 5 +- ...dll_side_loading_process_child_of_calc.yml | 5 +- ..._dns_query_request_by_telegram_bot_api.yml | 39 +++-- ..._account_discovery_via_get_netcomputer.yml | 5 +- ...ows_dotnet_binary_in_non_standard_path.yml | 6 +- .../windows_driver_load_non_standard_path.yml | 6 +- ...dows_esx_admins_group_creation_via_net.yml | 2 +- ...x_admins_group_creation_via_powershell.yml | 2 +- .../windows_event_for_service_disabled.yml | 5 +- .../endpoint/windows_event_log_cleared.yml | 5 +- ...dows_excessive_disabled_services_event.yml | 5 +- .../windows_excessive_usage_of_net_app.yml | 2 +- ...s_execute_arbitrary_commands_with_msdt.yml | 2 +- .../endpoint/windows_export_certificate.yml | 5 +- ...er_protocol_in_non_common_process_path.yml | 5 +- ..._access_rights_modification_via_icacls.yml | 5 +- ..._organizational_units_with_getdomainou.yml | 5 +- ...ting_acl_with_findinterestingdomainacl.yml | 5 +- .../windows_findstr_gpp_discovery.yml | 5 +- ..._forest_discovery_with_getforestdomain.yml | 5 +- ..._gather_victim_host_information_camera.yml | 5 +- ...indows_gather_victim_identity_sam_info.yml | 5 +- ...ork_info_through_ip_check_web_services.yml | 5 +- ..._local_admin_with_findlocaladminaccess.yml | 5 +- .../windows_group_discovery_via_net.yml | 39 +++-- .../windows_group_policy_object_created.yml | 7 +- ...k_execution_flow_version_dll_side_load.yml | 5 +- ...ttp_network_communication_from_msiexec.yml | 2 +- ...hunting_system_account_targeting_lsass.yml | 5 +- .../windows_iis_components_add_new_module.yml | 5 +- ...nents_get_webglobalmodule_module_query.yml | 5 +- ...s_iis_components_module_failed_to_load.yml | 5 +- ...indows_iis_components_new_module_added.yml | 5 +- ...impair_defense_add_xml_applocker_rules.yml | 5 +- ...ge_win_defender_health_check_intervals.yml | 5 +- ...hange_win_defender_quick_scan_interval.yml | 5 +- ...ense_change_win_defender_throttle_rate.yml | 5 +- ...ense_change_win_defender_tracing_level.yml | 5 +- ..._defense_configure_app_install_control.yml | 5 +- ...ense_define_win_defender_threat_action.yml | 5 +- ...fense_delete_win_defender_context_menu.yml | 5 +- ...e_delete_win_defender_profile_registry.yml | 5 +- ..._deny_security_software_with_applocker.yml | 5 +- ...fense_disable_controlled_folder_access.yml | 5 +- ..._disable_defender_firewall_and_network.yml | 5 +- ..._disable_defender_protocol_recognition.yml | 5 +- ..._impair_defense_disable_pua_protection.yml | 5 +- ...se_disable_realtime_signature_delivery.yml | 5 +- ..._impair_defense_disable_web_evaluation.yml | 5 +- ...defense_disable_win_defender_app_guard.yml | 5 +- ...sable_win_defender_compute_file_hashes.yml | 5 +- ...fense_disable_win_defender_gen_reports.yml | 5 +- ...isable_win_defender_network_protection.yml | 5 +- ..._disable_win_defender_report_infection.yml | 5 +- ...se_disable_win_defender_scan_on_update.yml | 5 +- ...able_win_defender_signature_retirement.yml | 5 +- ...e_overide_win_defender_phishing_filter.yml | 5 +- ...ir_defense_override_smartscreen_prompt.yml | 5 +- ...in_defender_smart_screen_level_to_warn.yml | 5 +- ...r_defenses_disable_auto_logger_session.yml | 8 +- ...nses_disable_av_autostart_via_registry.yml | 2 +- .../windows_impair_defenses_disable_hvci.yml | 5 +- ...nses_disable_win_defender_auto_logging.yml | 5 +- ...s_ingress_tool_transfer_using_explorer.yml | 2 +- ..._input_capture_using_credential_ui_dll.yml | 5 +- .../windows_installutil_credential_theft.yml | 5 +- ...ndows_installutil_in_non_standard_path.yml | 6 +- ..._installutil_remote_network_connection.yml | 5 +- .../windows_installutil_uninstall_option.yml | 5 +- ...tallutil_uninstall_option_with_network.yml | 5 +- ...indows_installutil_url_in_command_line.yml | 5 +- .../windows_iso_lnk_file_creation.yml | 8 +- .../endpoint/windows_java_spawning_shells.yml | 2 +- .../windows_known_abused_dll_created.yml | 5 +- ...s_known_abused_dll_loaded_suspiciously.yml | 5 +- ...s_known_graphicalproton_loaded_modules.yml | 5 +- ...ndows_ldifde_directory_object_behavior.yml | 2 +- ...dows_linked_policies_in_adsi_discovery.yml | 5 +- ...ocal_administrator_credential_stuffing.yml | 5 +- ...indows_lolbas_executed_as_renamed_file.yml | 5 +- ..._lolbas_executed_outside_expected_path.yml | 5 +- ...il_protocol_in_non_common_process_path.yml | 5 +- ...masquerading_explorer_as_child_process.yml | 5 +- .../windows_mimikatz_binary_execution.yml | 2 +- ...ws_modify_registry_valleyrat_c2_config.yml | 2 +- ...odify_registry_valleyrat_pwn_reg_entry.yml | 2 +- ...tem_firewall_with_notable_process_path.yml | 5 +- ..._mof_event_triggered_execution_via_wmi.yml | 2 +- ...change_management_mailbox_cmdlet_usage.yml | 5 +- .../windows_msiexec_dllregisterserver.yml | 2 +- ..._msiexec_hidewindow_rundll32_execution.yml | 5 +- .../windows_msiexec_remote_download.yml | 2 +- ...indows_msiexec_spawn_discovery_command.yml | 2 +- .../endpoint/windows_msiexec_spawn_windbg.yml | 2 +- ...s_msiexec_unregister_dllregisterserver.yml | 2 +- ...dows_multi_hop_proxy_tor_website_query.yml | 5 +- ...rs_failed_to_authenticate_wth_kerberos.yml | 5 +- ...rs_fail_to_authenticate_using_kerberos.yml | 5 +- ...sers_failed_to_authenticate_using_ntlm.yml | 5 +- ...tiple_ntlm_null_domain_authentications.yml | 5 +- ...o_authenticate_wth_explicitcredentials.yml | 5 +- ...d_to_authenticate_from_host_using_ntlm.yml | 5 +- ...rs_failed_to_authenticate_from_process.yml | 5 +- ..._failed_to_authenticate_using_kerberos.yml | 5 +- ...otely_failed_to_authenticate_from_host.yml | 5 +- ...ity_descriptor_set_on_eventlog_channel.yml | 19 +-- ...new_default_file_association_value_set.yml | 42 +++-- .../windows_ngrok_reverse_proxy_usage.yml | 2 +- .../endpoint/windows_nirsoft_advancedrun.yml | 2 +- ...ws_njrat_fileless_storage_via_registry.yml | 5 +- ...ows_non_system_account_targeting_lsass.yml | 5 +- .../endpoint/windows_odbcconf_load_dll.yml | 2 +- .../windows_odbcconf_load_response_file.yml | 2 +- ...office_product_dropped_cab_or_inf_file.yml | 33 +++- ...s_office_product_dropped_uncommon_file.yml | 34 ++++- ...ws_office_product_loaded_mshtml_module.yml | 38 +++-- ...ws_office_product_loading_taskschd_dll.yml | 40 +++-- ...indows_office_product_loading_vbe7_dll.yml | 40 +++-- ...uct_spawned_child_process_for_download.yml | 42 ++++- ...windows_office_product_spawned_control.yml | 15 +- .../windows_office_product_spawned_msdt.yml | 15 +- ...e_product_spawned_rundll32_with_no_dll.yml | 15 +- ...ffice_product_spawned_uncommon_process.yml | 50 ++++-- .../windows_papercut_ng_spawn_shell.yml | 2 +- ...dows_parent_pid_spoofing_with_explorer.yml | 5 +- ...ws_phishing_pdf_file_executes_url_link.yml | 5 +- ...dows_phishing_recent_iso_exec_registry.yml | 5 +- .../windows_possible_credential_dumping.yml | 5 +- ...ll_add_module_to_global_assembly_cache.yml | 5 +- ...dows_powershell_cryptography_namespace.yml | 5 +- ...indows_powershell_disable_http_logging.yml | 8 +- .../windows_powershell_export_certificate.yml | 5 +- ...ndows_powershell_export_pfxcertificate.yml | 5 +- ...l_iis_components_webglobalmodule_usage.yml | 5 +- ...ows_powershell_import_applocker_policy.yml | 6 +- ...ndows_powershell_logoff_user_via_quser.yml | 42 +++-- .../windows_powershell_remotesigned_file.yml | 5 +- .../windows_powershell_scheduletask.yml | 5 +- ...dows_powershell_wmi_win32_scheduledjob.yml | 5 +- .../windows_powersploit_gpp_discovery.yml | 5 +- ...erview_kerberos_service_ticket_request.yml | 5 +- .../windows_powerview_spn_discovery.yml | 5 +- .../windows_private_keys_discovery.yml | 5 +- ...scalation_suspicious_process_elevation.yml | 2 +- ..._process_executed_from_removable_media.yml | 81 ++++++++++ .../windows_process_execution_in_temp_dir.yml | 87 +++++++++++ ...windows_process_injection_into_notepad.yml | 5 +- ...s_injection_of_wermgr_to_known_browser.yml | 5 +- ...indows_process_injection_remote_thread.yml | 5 +- ...cess_injection_with_public_source_path.yml | 5 +- ...s_with_netexec_command_line_parameters.yml | 138 +++++++++-------- .../windows_protocol_tunneling_with_plink.yml | 2 +- .../endpoint/windows_proxy_via_netsh.yml | 5 +- .../endpoint/windows_proxy_via_registry.yml | 5 +- ...indows_raccine_scheduled_task_deletion.yml | 2 +- .../windows_rasautou_dll_execution.yml | 5 +- ...ws_raw_access_to_disk_volume_partition.yml | 10 +- ...raw_access_to_master_boot_record_drive.yml | 10 +- .../windows_registry_certificate_added.yml | 5 +- ...y_dotnet_etw_disabled_via_env_variable.yml | 5 +- ...modification_for_safe_mode_persistence.yml | 5 +- .../windows_registry_payload_injection.yml | 5 +- .../windows_regsvr32_renamed_binary.yml | 5 +- ...ows_remote_assistance_spawning_process.yml | 2 +- .../windows_remote_create_service.yml | 5 +- ...remote_service_rdpwinst_tool_execution.yml | 5 +- ..._remote_services_allow_rdp_in_firewall.yml | 5 +- ...emote_services_allow_remote_assistance.yml | 5 +- .../windows_remote_services_rdp_enable.yml | 5 +- ..._root_domain_linked_policies_discovery.yml | 5 +- ...s_rundll32_apply_user_settings_changes.yml | 5 +- .../windows_rundll32_webdav_request.yml | 2 +- ...undll32_webdav_with_network_connection.yml | 2 +- ...windows_scheduled_task_created_via_xml.yml | 5 +- ...scheduled_task_with_highest_privileges.yml | 5 +- .../windows_schtasks_create_run_as_system.yml | 5 +- ...dows_security_and_backup_services_stop.yml | 78 ++++++++++ ...ws_security_support_provider_reg_query.yml | 5 +- ...ows_sensitive_group_discovery_with_net.yml | 43 +++++- ...ive_registry_hive_dump_via_commandline.yml | 46 ++++-- ...tware_component_gacutil_install_to_gac.yml | 5 +- ...dows_service_create_kernel_mode_driver.yml | 7 +- .../windows_service_create_remcomsvc.yml | 5 +- .../windows_service_create_sliverc2.yml | 5 +- .../windows_service_create_with_tscon.yml | 7 +- ...e_created_with_suspicious_service_path.yml | 8 +- ...ows_service_created_within_public_path.yml | 5 +- ...ws_service_creation_on_remote_endpoint.yml | 5 +- .../windows_service_execution_remcom.yml | 2 +- ..._service_initiation_on_remote_endpoint.yml | 5 +- .../windows_soaphound_binary_execution.yml | 12 +- ...hment_connect_to_none_ms_office_domain.yml | 5 +- ...hishing_attachment_onenote_spawn_mshta.yml | 5 +- .../windows_sql_spawning_certutil.yml | 2 +- ...thentication_certificates___esc1_abuse.yml | 2 +- ...ion_certificates___esc1_authentication.yml | 2 +- ...ntication_certificates_certutil_backup.yml | 2 +- ...cation_certificates_export_certificate.yml | 2 +- ...ion_certificates_export_pfxcertificate.yml | 2 +- ...ct_process_with_authentication_traffic.yml | 6 +- ...s_child_process_spawned_from_webserver.yml | 5 +- .../windows_suspicious_driver_loaded_path.yml | 75 +++++++++ .../windows_suspicious_process_file_path.yml | 121 +++++++++++++++ ...execution_compiled_html_file_decompile.yml | 5 +- ...ows_system_remote_discovery_with_query.yml | 64 ++++++++ ...oxy_execution_syncappvpublishingserver.yml | 2 +- .../windows_terminating_lsass_process.yml | 5 +- .../endpoint/windows_time_based_evasion.yml | 5 +- ...ows_time_based_evasion_via_choice_exec.yml | 5 +- ...ws_uac_bypass_suspicious_child_process.yml | 5 +- ..._bypass_suspicious_escalation_behavior.yml | 5 +- ..._dll_side_loading_in_same_process_path.yml | 8 +- ...abled_users_failed_auth_using_kerberos.yml | 5 +- ...alid_users_fail_to_auth_using_kerberos.yml | 5 +- ...nvalid_users_failed_to_auth_using_ntlm.yml | 5 +- ...s_fail_to_auth_wth_explicitcredentials.yml | 5 +- ...of_users_failed_to_auth_using_kerberos.yml | 5 +- ...rs_failed_to_authenticate_from_process.yml | 5 +- ...sers_failed_to_authenticate_using_ntlm.yml | 5 +- ...sers_remotely_failed_to_auth_from_host.yml | 5 +- ..._authentication_destinations_by_source.yml | 5 +- ...lm_authentication_destinations_by_user.yml | 5 +- ...lm_authentication_users_by_destination.yml | 5 +- ...al_ntlm_authentication_users_by_source.yml | 5 +- ...dows_usbstor_registry_key_modification.yml | 67 ++++++++ .../windows_user_deletion_via_net.yml | 2 +- .../windows_user_disabled_via_net.yml | 2 +- .../windows_user_discovery_via_net.yml | 23 ++- ..._execution_malicious_url_shortcut_file.yml | 5 +- .../windows_windbg_spawning_autoit3.yml | 2 +- ...s_wpdbusenum_registry_key_modification.yml | 67 ++++++++ ..._scheduled_task_created_to_spawn_shell.yml | 8 +- ...eduled_task_created_within_public_path.yml | 8 +- .../endpoint/winhlp32_spawning_a_process.yml | 2 +- .../winrar_spawning_shell_application.yml | 2 +- ..._permanent_event_subscription___sysmon.yml | 5 +- detections/endpoint/wmic_group_discovery.yml | 5 +- ...wmic_noninteractive_app_uninstallation.yml | 5 +- .../endpoint/wmic_xsl_execution_via_url.yml | 2 +- ...pt_or_cscript_suspicious_child_process.yml | 7 +- ...rovhost_lolbas_execution_process_spawn.yml | 5 +- detections/endpoint/wsreset_uac_bypass.yml | 5 +- detections/endpoint/xmrig_driver_loaded.yml | 5 +- .../xsl_script_execution_with_wmic.yml | 2 +- detections/network/detect_arp_poisoning.yml | 5 +- ...ct_ipv6_network_infrastructure_threats.yml | 5 +- .../detect_large_outbound_icmp_packets.yml | 2 +- .../network/detect_outbound_smb_traffic.yml | 13 +- .../detect_port_security_violation.yml | 5 +- ...etect_remote_access_software_usage_dns.yml | 11 +- ...t_remote_access_software_usage_traffic.yml | 14 +- ...ct_software_download_to_network_device.yml | 5 +- .../network/detect_traffic_mirroring.yml | 9 +- .../dns_query_length_outliers___mltk.yml | 5 +- ...ry_length_with_high_standard_deviation.yml | 5 +- detections/network/excessive_dns_failures.yml | 5 +- ...e_of_network_traffic_from_email_server.yml | 5 +- .../large_volume_of_dns_any_queries.yml | 5 +- .../network/protocol_or_port_mismatch.yml | 5 +- .../remote_desktop_network_bruteforce.yml | 51 ------- .../remote_desktop_network_traffic.yml | 5 +- detections/network/smb_traffic_spike.yml | 5 +- .../network/smb_traffic_spike___mltk.yml | 14 +- detections/network/tor_traffic.yml | 5 +- ...windows_ad_replication_service_traffic.yml | 5 +- ...ote_desktop_network_bruteforce_attempt.yml | 60 ++++++++ ...etect_remote_access_software_usage_url.yml | 9 +- ...ng_application_via_apache_commons_text.yml | 9 +- ...ltiple_archive_files_http_post_traffic.yml | 5 +- .../web/plain_http_post_exfiltrated_data.yml | 5 +- .../web/spring4shell_payload_url_request.yml | 9 +- detections/web/web_jsp_request_via_url.yml | 9 +- ...caler_adware_activities_threat_blocked.yml | 2 +- ...caler_behavior_analysis_threat_blocked.yml | 2 +- .../web/zscaler_exploit_threat_blocked.yml | 2 +- ...scaler_malware_activity_threat_blocked.yml | 2 +- ...caler_potentially_abused_file_download.yml | 2 +- ...ivacy_risk_destinations_threat_blocked.yml | 2 +- ...caler_scam_destinations_threat_blocked.yml | 2 +- .../zscaler_virus_download_threat_blocked.yml | 2 +- 1033 files changed, 4864 insertions(+), 3734 deletions(-) create mode 100644 detections/cloud/o365_email_transport_rule_changed.yml create mode 100644 detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml create mode 100644 detections/cloud/o365_sharepoint_suspicious_search_behavior.yml rename detections/{endpoint => deprecated}/known_services_killed_by_ransomware.yml (93%) create mode 100644 detections/deprecated/remote_desktop_network_bruteforce.yml rename detections/{endpoint => deprecated}/suspicious_driver_loaded_path.yml (93%) rename detections/{endpoint => deprecated}/suspicious_process_file_path.yml (95%) create mode 100644 detections/endpoint/windows_process_executed_from_removable_media.yml create mode 100644 detections/endpoint/windows_process_execution_in_temp_dir.yml create mode 100644 detections/endpoint/windows_security_and_backup_services_stop.yml create mode 100644 detections/endpoint/windows_suspicious_driver_loaded_path.yml create mode 100644 detections/endpoint/windows_suspicious_process_file_path.yml create mode 100644 detections/endpoint/windows_system_remote_discovery_with_query.yml create mode 100644 detections/endpoint/windows_usbstor_registry_key_modification.yml create mode 100644 detections/endpoint/windows_wpdbusenum_registry_key_modification.yml delete mode 100644 detections/network/remote_desktop_network_bruteforce.yml create mode 100644 detections/network/windows_remote_desktop_network_bruteforce_attempt.yml diff --git a/detections/application/detect_distributed_password_spray_attempts.yml b/detections/application/detect_distributed_password_spray_attempts.yml index a25a797b90..db367690c3 100644 --- a/detections/application/detect_distributed_password_spray_attempts.yml +++ b/detections/application/detect_distributed_password_spray_attempts.yml @@ -1,7 +1,7 @@ name: Detect Distributed Password Spray Attempts id: b1a82fc8-8a9f-4344-9ec2-bde5c5331b57 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: Hunting @@ -65,7 +65,6 @@ tags: - 90bc2e54-6c84-47a5-9439-0a2a92b4b175 mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/detect_password_spray_attempts.yml b/detections/application/detect_password_spray_attempts.yml index 9089026b9d..62c51cbc0e 100644 --- a/detections/application/detect_password_spray_attempts.yml +++ b/detections/application/detect_password_spray_attempts.yml @@ -1,7 +1,7 @@ name: Detect Password Spray Attempts id: 086ab581-8877-42b3-9aee-4a7ecb0923af -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -83,7 +83,6 @@ tags: - 90bc2e54-6c84-47a5-9439-0a2a92b4b175 mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/email_files_written_outside_of_the_outlook_directory.yml b/detections/application/email_files_written_outside_of_the_outlook_directory.yml index b60204ed4f..0530cd1aa9 100644 --- a/detections/application/email_files_written_outside_of_the_outlook_directory.yml +++ b/detections/application/email_files_written_outside_of_the_outlook_directory.yml @@ -1,7 +1,7 @@ name: Email files written outside of the Outlook directory id: 8d52cf03-ba25-4101-aa78-07994aed4f74 -version: 6 -date: '2025-01-21' +version: 7 +date: '2025-02-10' author: Bhavin Patel, Splunk status: experimental type: TTP @@ -44,7 +44,6 @@ tags: - Collection and Staging asset_type: Endpoint mitre_attack_id: - - T1114 - T1114.001 product: - Splunk Enterprise diff --git a/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml b/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml index 7a4e2f7bd3..ccbe394899 100644 --- a/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml +++ b/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml @@ -1,7 +1,7 @@ name: Email servers sending high volume traffic to hosts id: 7f5fb3e1-4209-4914-90db-0ec21b556378 -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Splunk status: experimental type: Anomaly @@ -51,7 +51,6 @@ tags: - HAFNIUM Group asset_type: Endpoint mitre_attack_id: - - T1114 - T1114.002 product: - Splunk Enterprise diff --git a/detections/application/okta_authentication_failed_during_mfa_challenge.yml b/detections/application/okta_authentication_failed_during_mfa_challenge.yml index 48faea347a..67546ddaf4 100644 --- a/detections/application/okta_authentication_failed_during_mfa_challenge.yml +++ b/detections/application/okta_authentication_failed_during_mfa_challenge.yml @@ -1,7 +1,7 @@ name: Okta Authentication Failed During MFA Challenge id: e2b99e7d-d956-411a-a120-2b14adfdde93 -version: 4 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk data_source: - Okta @@ -59,10 +59,8 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 - T1621 product: - Splunk Enterprise diff --git a/detections/application/okta_multi_factor_authentication_disabled.yml b/detections/application/okta_multi_factor_authentication_disabled.yml index fbef02e3e1..96cda4186d 100644 --- a/detections/application/okta_multi_factor_authentication_disabled.yml +++ b/detections/application/okta_multi_factor_authentication_disabled.yml @@ -1,7 +1,7 @@ name: Okta Multi-Factor Authentication Disabled id: 7c0348ce-bdf9-45f6-8a57-c18b5976f00a -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Okta @@ -57,7 +57,6 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1556 - T1556.006 product: - Splunk Enterprise diff --git a/detections/application/okta_new_api_token_created.yml b/detections/application/okta_new_api_token_created.yml index 7a8e0e78e3..27e4bf7c50 100644 --- a/detections/application/okta_new_api_token_created.yml +++ b/detections/application/okta_new_api_token_created.yml @@ -1,7 +1,7 @@ name: Okta New API Token Created id: c3d22720-35d3-4da4-bd0a-740d37192bd4 -version: 6 -date: '2025-01-21' +version: 7 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1078 - T1078.001 product: - Splunk Enterprise diff --git a/detections/application/okta_new_device_enrolled_on_account.yml b/detections/application/okta_new_device_enrolled_on_account.yml index a95db4b8ce..0b28586594 100644 --- a/detections/application/okta_new_device_enrolled_on_account.yml +++ b/detections/application/okta_new_device_enrolled_on_account.yml @@ -1,7 +1,7 @@ name: Okta New Device Enrolled on Account id: bb27cbce-d4de-432c-932f-2e206e9130fb -version: 6 -date: '2025-01-21' +version: 7 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1098 - T1098.005 product: - Splunk Enterprise diff --git a/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml b/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml index 8171b96c75..f2fe0f1b3c 100644 --- a/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml +++ b/detections/application/okta_phishing_detection_with_fastpass_origin_check.yml @@ -1,7 +1,7 @@ name: Okta Phishing Detection with FastPass Origin Check id: f4ca0057-cbf3-44f8-82ea-4e330ee901d3 -version: 4 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Okta, Inc, Michael Haag, Splunk type: TTP status: experimental @@ -38,7 +38,6 @@ tags: - Okta Account Takeover asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.001 - T1556 product: diff --git a/detections/application/okta_successful_single_factor_authentication.yml b/detections/application/okta_successful_single_factor_authentication.yml index 1c0f03def8..a5a4a3bf14 100644 --- a/detections/application/okta_successful_single_factor_authentication.yml +++ b/detections/application/okta_successful_single_factor_authentication.yml @@ -1,7 +1,7 @@ name: Okta Successful Single Factor Authentication id: 98f6ad4f-4325-4096-9d69-45dc8e638e82 -version: 4 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk data_source: - Okta @@ -55,10 +55,8 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 - T1621 product: - Splunk Enterprise diff --git a/detections/application/okta_suspicious_activity_reported.yml b/detections/application/okta_suspicious_activity_reported.yml index 363f2487b6..1f2662268e 100644 --- a/detections/application/okta_suspicious_activity_reported.yml +++ b/detections/application/okta_suspicious_activity_reported.yml @@ -1,7 +1,7 @@ name: Okta Suspicious Activity Reported id: bfc840f5-c9c6-454c-aa13-b46fd0bf1e79 -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - Okta Account Takeover asset_type: Okta Tenant mitre_attack_id: - - T1078 - T1078.001 product: - Splunk Enterprise diff --git a/detections/application/okta_threatinsight_threat_detected.yml b/detections/application/okta_threatinsight_threat_detected.yml index 04d5e1e5fe..264bf76c91 100644 --- a/detections/application/okta_threatinsight_threat_detected.yml +++ b/detections/application/okta_threatinsight_threat_detected.yml @@ -1,7 +1,7 @@ name: Okta ThreatInsight Threat Detected id: 140504ae-5fe2-4d65-b2bc-a211813fbca6 -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: - Okta Account Takeover asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.004 product: - Splunk Enterprise diff --git a/detections/application/pingid_mismatch_auth_source_and_verification_response.yml b/detections/application/pingid_mismatch_auth_source_and_verification_response.yml index 021ec93c2e..17e059d927 100644 --- a/detections/application/pingid_mismatch_auth_source_and_verification_response.yml +++ b/detections/application/pingid_mismatch_auth_source_and_verification_response.yml @@ -1,6 +1,6 @@ name: PingID Mismatch Auth Source and Verification Response id: 15b0694e-caa2-4009-8d83-a1f98b86d086 -version: 4 +version: 5 date: '2025-01-21' author: Steven Dick status: production diff --git a/detections/application/suspicious_email_attachment_extensions.yml b/detections/application/suspicious_email_attachment_extensions.yml index 3a44f76bfa..f557b97bca 100644 --- a/detections/application/suspicious_email_attachment_extensions.yml +++ b/detections/application/suspicious_email_attachment_extensions.yml @@ -1,7 +1,7 @@ name: Suspicious Email Attachment Extensions id: 473bd65f-06ca-4dfe-a2b8-ba04ab4a0084 -version: 6 -date: '2025-01-21' +version: 7 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -48,7 +48,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_dangerous_deny_acl_modification.yml b/detections/application/windows_ad_dangerous_deny_acl_modification.yml index 40076288f5..29ab4c180d 100644 --- a/detections/application/windows_ad_dangerous_deny_acl_modification.yml +++ b/detections/application/windows_ad_dangerous_deny_acl_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Dangerous Deny ACL Modification id: 8e897153-2ebd-4cb2-85d3-09ad57db2fb7 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -76,9 +76,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_dangerous_group_acl_modification.yml b/detections/application/windows_ad_dangerous_group_acl_modification.yml index c6bffd639e..047d9274eb 100644 --- a/detections/application/windows_ad_dangerous_group_acl_modification.yml +++ b/detections/application/windows_ad_dangerous_group_acl_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Dangerous Group ACL Modification id: 59b0fc85-7a0d-4585-97ec-06a382801990 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -85,9 +85,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_dangerous_user_acl_modification.yml b/detections/application/windows_ad_dangerous_user_acl_modification.yml index f298e0616d..7163e0aa3a 100644 --- a/detections/application/windows_ad_dangerous_user_acl_modification.yml +++ b/detections/application/windows_ad_dangerous_user_acl_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Dangerous User ACL Modification id: ec5b6790-595a-4fb8-ad43-56e5b55a9617 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -82,9 +82,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_domain_root_acl_deletion.yml b/detections/application/windows_ad_domain_root_acl_deletion.yml index c4bfa9c916..8ca60c13b1 100644 --- a/detections/application/windows_ad_domain_root_acl_deletion.yml +++ b/detections/application/windows_ad_domain_root_acl_deletion.yml @@ -1,7 +1,7 @@ name: Windows AD Domain Root ACL Deletion id: 3cb56e57-5642-4638-907f-8dfde9afb889 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -75,9 +75,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_domain_root_acl_modification.yml b/detections/application/windows_ad_domain_root_acl_modification.yml index 56d121c7d2..4b30ed7b3a 100644 --- a/detections/application/windows_ad_domain_root_acl_modification.yml +++ b/detections/application/windows_ad_domain_root_acl_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Domain Root ACL Modification id: 4981e2db-1372-440d-816e-3e7e2ed74433 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -75,9 +75,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_gpo_new_cse_addition.yml b/detections/application/windows_ad_gpo_new_cse_addition.yml index 4f0f4fce8f..194bf251ab 100644 --- a/detections/application/windows_ad_gpo_new_cse_addition.yml +++ b/detections/application/windows_ad_gpo_new_cse_addition.yml @@ -1,7 +1,7 @@ name: Windows AD GPO New CSE Addition id: 700c11d1-da09-47b2-81aa-358c143c7986 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -64,10 +64,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1484.001 - - T1222 - T1222.001 + - T1484.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_hidden_ou_creation.yml b/detections/application/windows_ad_hidden_ou_creation.yml index 2885f00678..358a32bc0f 100644 --- a/detections/application/windows_ad_hidden_ou_creation.yml +++ b/detections/application/windows_ad_hidden_ou_creation.yml @@ -1,7 +1,7 @@ name: Windows AD Hidden OU Creation id: 66b6ad5e-339a-40af-b721-dacefc7bdb75 -version: 3 -date: '2025-01-21' +version: 4 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -74,9 +74,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_object_owner_updated.yml b/detections/application/windows_ad_object_owner_updated.yml index fb234c3f1a..51abfc6ca8 100644 --- a/detections/application/windows_ad_object_owner_updated.yml +++ b/detections/application/windows_ad_object_owner_updated.yml @@ -1,7 +1,7 @@ name: Windows AD Object Owner Updated id: 4af01f6b-d8d4-4f96-8635-758a01557130 -version: 4 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -66,9 +66,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1222 - T1222.001 + - T1484 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_suspicious_attribute_modification.yml b/detections/application/windows_ad_suspicious_attribute_modification.yml index df005bfae6..da62dd68ba 100644 --- a/detections/application/windows_ad_suspicious_attribute_modification.yml +++ b/detections/application/windows_ad_suspicious_attribute_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Suspicious Attribute Modification id: 5682052e-ce55-4f9f-8d28-59191420b7e0 -version: 3 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Dean Luxton status: production type: TTP @@ -62,9 +62,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1550 - - T1222 - T1222.001 + - T1550 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/application/windows_ad_suspicious_gpo_modification.yml b/detections/application/windows_ad_suspicious_gpo_modification.yml index 976ed7ea7d..c70acfb5ed 100644 --- a/detections/application/windows_ad_suspicious_gpo_modification.yml +++ b/detections/application/windows_ad_suspicious_gpo_modification.yml @@ -1,7 +1,7 @@ name: Windows AD Suspicious GPO Modification id: 0a2afc18-a3b5-4452-b60a-2e774214f9bf -version: 3 -date: '2025-01-21' +version: 5 +date: '2025-02-10' author: Dean Luxton status: experimental type: TTP @@ -70,10 +70,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1484.001 - - T1222 - T1222.001 + - T1484.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index 969f05f721..6581d23fca 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -1,7 +1,7 @@ name: Abnormally High Number Of Cloud Infrastructure API Calls id: 0840ddf1-8c89-46ff-b730-c8d6722478c0 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -46,7 +46,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml b/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml index 8175e9709c..e9bcb75db0 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml @@ -1,7 +1,7 @@ name: Abnormally High Number Of Cloud Instances Destroyed id: ef629fc9-1583-4590-b62a-f2247fbf7bbf -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -48,7 +48,6 @@ tags: asset_type: Cloud Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml b/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml index e88f2c8f16..9edf6d5b9a 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml @@ -1,7 +1,7 @@ name: Abnormally High Number Of Cloud Instances Launched id: f2361e9f-3928-496c-a556-120cd4223a65 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -48,7 +48,6 @@ tags: asset_type: Cloud Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index 2360113251..761e9de23d 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -1,7 +1,7 @@ name: Abnormally High Number Of Cloud Security Group API Calls id: d4dfb7f3-7a37-498a-b5df-f19334e871af -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -46,7 +46,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/asl_aws_create_access_key.yml b/detections/cloud/asl_aws_create_access_key.yml index eeb433eaa8..f73e4719af 100644 --- a/detections/cloud/asl_aws_create_access_key.yml +++ b/detections/cloud/asl_aws_create_access_key.yml @@ -1,16 +1,33 @@ name: ASL AWS Create Access Key id: 81a9f2fe-1697-473c-af1d-086b0d8b63c8 -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Hunting -description: The following analytic identifies the creation of AWS IAM access keys by a user for another user, which can indicate privilege escalation. It leverages AWS CloudTrail logs to detect instances where the user creating the access key is different from the user for whom the key is created. This activity is significant because unauthorized access key creation can allow attackers to establish persistence or exfiltrate data via AWS APIs. If confirmed malicious, this could lead to unauthorized access to AWS services, data exfiltration, and long-term persistence in the environment. -data_source: +description: The following analytic identifies the creation of AWS IAM access keys + by a user for another user, which can indicate privilege escalation. It leverages + AWS CloudTrail logs to detect instances where the user creating the access key is + different from the user for whom the key is created. This activity is significant + because unauthorized access key creation can allow attackers to establish persistence + or exfiltrate data via AWS APIs. If confirmed malicious, this could lead to unauthorized + access to AWS services, data exfiltration, and long-term persistence in the environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=CreateAccessKey | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_create_access_key_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. +search: '`amazon_security_lake` api.operation=CreateAccessKey | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as + user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + |`asl_aws_create_access_key_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately created keys for another user. references: - https://bishopfox.com/blog/privilege-escalation-in-aws - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ @@ -20,7 +37,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security @@ -29,6 +45,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml index d4620bd070..d7f2b0d689 100644 --- a/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml +++ b/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml @@ -1,16 +1,36 @@ name: ASL AWS Create Policy Version to allow all resources id: 22cc7a62-3884-48c4-82da-592b8199b72f -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic identifies the creation of a new AWS IAM policy version that allows access to all resources. It detects this activity by analyzing AWS CloudTrail logs for the CreatePolicyVersion event with a policy document that grants broad permissions. This behavior is significant because it violates the principle of least privilege, potentially exposing the environment to misuse or abuse. If confirmed malicious, an attacker could gain extensive access to AWS resources, leading to unauthorized actions, data exfiltration, or further compromise of the AWS environment. -data_source: +description: The following analytic identifies the creation of a new AWS IAM policy + version that allows access to all resources. It detects this activity by analyzing + AWS CloudTrail logs for the CreatePolicyVersion event with a policy document that + grants broad permissions. This behavior is significant because it violates the principle + of least privilege, potentially exposing the environment to misuse or abuse. If + confirmed malicious, an attacker could gain extensive access to AWS resources, leading + to unauthorized actions, data exfiltration, or further compromise of the AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=CreatePolicy | spath input=api.request.data | spath input=policyDocument | regex Statement{}.Action="\*" | regex Statement{}.Resource="\*" | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`asl_aws_create_policy_version_to_allow_all_resources_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources and you must verify this activity. +search: '`amazon_security_lake` api.operation=CreatePolicy | spath input=api.request.data + | spath input=policyDocument | regex Statement{}.Action="\*" | regex Statement{}.Resource="\*" + | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation + actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region + api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region + as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`|`asl_aws_create_policy_version_to_allow_all_resources_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately created a policy to allow a user to access all + resources. That said, AWS strongly advises against granting full control to all + AWS resources and you must verify this activity. references: - https://bishopfox.com/blog/privilege-escalation-in-aws - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ @@ -20,11 +40,17 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: User $user$ created a policy version that allows them to access any resource in their account + message: User $user$ created a policy version that allows them to access any resource + in their account risk_objects: - field: user type: user @@ -36,7 +62,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security @@ -45,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_credential_access_getpassworddata.yml b/detections/cloud/asl_aws_credential_access_getpassworddata.yml index 4c112af04c..808dfd47e7 100644 --- a/detections/cloud/asl_aws_credential_access_getpassworddata.yml +++ b/detections/cloud/asl_aws_credential_access_getpassworddata.yml @@ -1,16 +1,34 @@ name: ASL AWS Credential Access GetPasswordData id: a79b607a-50cc-4704-bb9d-eff280cb78c2 -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly -description: The following analytic identifiesGetPasswordData API calls in your AWS account. It leverages CloudTrail logs from Amazon Security Lake to detect this activity by counting the distinct instance IDs accessed. This behavior is significant as it may indicate an attempt to retrieve encrypted administrator passwords for running Windows instances, which is a critical security concern. If confirmed malicious, attackers could gain unauthorized access to administrative credentials, potentially leading to full control over the affected instances and further compromise of the AWS environment. -data_source: +description: The following analytic identifiesGetPasswordData API calls in your AWS + account. It leverages CloudTrail logs from Amazon Security Lake to detect this + activity by counting the distinct instance IDs accessed. This behavior is significant + as it may indicate an attempt to retrieve encrypted administrator passwords for + running Windows instances, which is a critical security concern. If confirmed malicious, + attackers could gain unauthorized access to administrative credentials, potentially + leading to full control over the affected instances and further compromise of the + AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=GetPasswordData | spath input=api.request.data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region instanceId | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_credential_access_getpassworddata_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: Administrator tooling or automated scripts may make these calls but it is highly unlikely to make several calls in a short period of time. +search: '`amazon_security_lake` api.operation=GetPasswordData | spath input=api.request.data + | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation + actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region + instanceId | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region + as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` |`asl_aws_credential_access_getpassworddata_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: Administrator tooling or automated scripts may make these calls + but it is highly unlikely to make several calls in a short period of time. references: - https://attack.mitre.org/techniques/T1552/ - https://stratus-red-team.cloud/attack-techniques/AWS/aws.credential-access.ec2-get-password-data/ @@ -20,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -37,10 +60,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.001 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_credential_access_rds_password_reset.yml b/detections/cloud/asl_aws_credential_access_rds_password_reset.yml index 300892fee9..c7248c18e7 100644 --- a/detections/cloud/asl_aws_credential_access_rds_password_reset.yml +++ b/detections/cloud/asl_aws_credential_access_rds_password_reset.yml @@ -1,15 +1,34 @@ name: ASL AWS Credential Access RDS Password reset id: d15e9bd9-ef64-4d84-bc04-f62955a9fee8 -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects the resetting of the master user password for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword` parameter. This activity is significant because unauthorized password resets can grant attackers access to sensitive data stored in production databases, such as credit card information, PII, and healthcare data. If confirmed malicious, this could lead to data breaches, regulatory non-compliance, and significant reputational damage. Immediate investigation is required to determine the legitimacy of the password reset. -data_source: +description: The following analytic detects the resetting of the master user password + for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security + Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword` + parameter. This activity is significant because unauthorized password resets can + grant attackers access to sensitive data stored in production databases, such as + credit card information, PII, and healthcare data. If confirmed malicious, this + could lead to data breaches, regulatory non-compliance, and significant reputational + damage. Immediate investigation is required to determine the legitimacy of the password + reset. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=ModifyDBInstance OR api.operation=ModifyDBCluster | spath input=api.request.data | search masterUserPassword=* | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_credential_access_rds_password_reset_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. +search: '`amazon_security_lake` api.operation=ModifyDBInstance OR api.operation=ModifyDBCluster + | spath input=api.request.data | search masterUserPassword=* | fillnull | stats + count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid + actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data + | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, + http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + |`asl_aws_credential_access_rds_password_reset_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. known_false_positives: Users may genuinely reset the RDS password. references: - https://aws.amazon.com/premiumsupport/knowledge-center/reset-master-user-password-rds @@ -19,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -36,9 +60,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - T1110 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -47,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.002/aws_rds_password_reset/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.002/aws_rds_password_reset/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml b/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml index bc99f507d0..a04efd1649 100644 --- a/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml +++ b/detections/cloud/asl_aws_defense_evasion_delete_cloudtrail.yml @@ -1,16 +1,33 @@ name: ASL AWS Defense Evasion Delete Cloudtrail id: 1f0b47e5-0134-43eb-851c-e3258638945e -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects AWS `DeleteTrail` events within CloudTrail logs. It leverages Amazon Security Lake logs parsed in the Open Cybersecurity Schema Framework (OCSF) format to identify when a CloudTrail is deleted. This activity is significant because adversaries may delete CloudTrail logs to evade detection and operate with stealth. If confirmed malicious, this action could allow attackers to cover their tracks, making it difficult to trace their activities and investigate other potential compromises within the AWS environment. -data_source: +description: The following analytic detects AWS `DeleteTrail` events within CloudTrail + logs. It leverages Amazon Security Lake logs parsed in the Open Cybersecurity Schema + Framework (OCSF) format to identify when a CloudTrail is deleted. This activity + is significant because adversaries may delete CloudTrail logs to evade detection + and operate with stealth. If confirmed malicious, this action could allow attackers + to cover their tracks, making it difficult to trace their activities and investigate + other potential compromises within the AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=DeleteTrail | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudtrail_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has stopped cloudTrail logging. Please investigate this activity. +search: '`amazon_security_lake` api.operation=DeleteTrail | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as + user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| + `asl_aws_defense_evasion_delete_cloudtrail_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has stopped cloudTrail logging. Please investigate this activity. references: - https://attack.mitre.org/techniques/T1562/008/ drilldown_searches: @@ -42,7 +59,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -51,6 +67,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml b/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml index 7a1806f3c9..cccf09434f 100644 --- a/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml +++ b/detections/cloud/asl_aws_defense_evasion_delete_cloudwatch_log_group.yml @@ -1,16 +1,34 @@ name: ASL AWS Defense Evasion Delete CloudWatch Log Group id: 0f701b38-a0fb-43fd-a83d-d12265f71f33 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects the deletion of CloudWatch log groups in AWS, identified through `DeleteLogGroup` events in CloudTrail logs. This method leverages Amazon Security Lake logs parsed in the OCSF format. The activity is significant because attackers may delete log groups to evade detection and disrupt logging capabilities, hindering incident response efforts. If confirmed malicious, this action could allow attackers to cover their tracks, making it difficult to trace their activities and potentially leading to undetected data breaches or further malicious actions within the compromised AWS environment. -data_source: +description: The following analytic detects the deletion of CloudWatch log groups + in AWS, identified through `DeleteLogGroup` events in CloudTrail logs. This method + leverages Amazon Security Lake logs parsed in the OCSF format. The activity is significant + because attackers may delete log groups to evade detection and disrupt logging capabilities, + hindering incident response efforts. If confirmed malicious, this action could allow + attackers to cover their tracks, making it difficult to trace their activities and + potentially leading to undetected data breaches or further malicious actions within + the compromised AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=DeleteLogGroup | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudwatch_log_group_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has deleted CloudWatch logging. Please investigate this activity. +search: '`amazon_security_lake` api.operation=DeleteLogGroup | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as + user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| + `asl_aws_defense_evasion_delete_cloudwatch_log_group_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has deleted CloudWatch logging. Please investigate this activity. references: - https://attack.mitre.org/techniques/T1562/008/ drilldown_searches: @@ -41,7 +59,6 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562 - T1562.008 product: - Splunk Enterprise diff --git a/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml b/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml index a6a76f9130..33368956c8 100644 --- a/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml +++ b/detections/cloud/asl_aws_defense_evasion_impair_security_services.yml @@ -1,16 +1,35 @@ name: ASL AWS Defense Evasion Impair Security Services id: 5029b681-0462-47b7-82e7-f7e3d37f5a2d -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Bhavin Patel, Gowthamaraj Rajendran, Splunk status: production type: Hunting -description: The following analytic detects the deletion of critical AWS Security Services configurations, such as CloudWatch alarms, GuardDuty detectors, and Web Application Firewall rules. It leverages Amazon Security Lake logs to identify specific API calls like "DeleteLogStream" and "DeleteDetector." This activity is significant because adversaries often use these actions to disable security monitoring and evade detection. If confirmed malicious, this could allow attackers to operate undetected, leading to potential data breaches, unauthorized access, and prolonged persistence within the AWS environment. -data_source: +description: The following analytic detects the deletion of critical AWS Security + Services configurations, such as CloudWatch alarms, GuardDuty detectors, and Web + Application Firewall rules. It leverages Amazon Security Lake logs to identify specific + API calls like "DeleteLogStream" and "DeleteDetector." This activity is significant + because adversaries often use these actions to disable security monitoring and evade + detection. If confirmed malicious, this could allow attackers to operate undetected, + leading to potential data breaches, unauthorized access, and prolonged persistence + within the AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms") | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_impair_security_services_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. +search: '`amazon_security_lake` api.operation IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms") + | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation + actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region + | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, + http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_impair_security_services_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that it is a legitimate admin activity. Please consider filtering out these noisy + events using userAgent, user_arn field names. references: - https://docs.aws.amazon.com/cli/latest/reference/guardduty/index.html - https://docs.aws.amazon.com/cli/latest/reference/waf/index.html @@ -21,7 +40,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -30,6 +48,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml b/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml index 2b843cd24f..1ae40f392d 100644 --- a/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml +++ b/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml @@ -1,16 +1,36 @@ name: ASL AWS Defense Evasion PutBucketLifecycle id: 986565a2-7707-48ea-9590-37929cebc938 -version: 1 -date: '2024-12-16' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Hunting -description: The following analytic detects `PutBucketLifecycle` events in AWS CloudTrail logs where a user sets a lifecycle rule for an S3 bucket with an expiration period of fewer than three days. This detection leverages CloudTrail logs to identify suspicious lifecycle configurations. This activity is significant because attackers may use it to delete CloudTrail logs quickly, thereby evading detection and impairing forensic investigations. If confirmed malicious, this could allow attackers to cover their tracks, making it difficult to trace their actions and respond to the breach effectively. +description: The following analytic detects `PutBucketLifecycle` events in AWS CloudTrail + logs where a user sets a lifecycle rule for an S3 bucket with an expiration period + of fewer than three days. This detection leverages CloudTrail logs to identify suspicious + lifecycle configurations. This activity is significant because attackers may use + it to delete CloudTrail logs quickly, thereby evading detection and impairing forensic + investigations. If confirmed malicious, this could allow attackers to cover their + tracks, making it difficult to trace their actions and respond to the breach effectively. data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=PutBucketLifecycle | spath input=api.request.data path=LifecycleConfiguration.Rule.NoncurrentVersionExpiration.NoncurrentDays output=NoncurrentDays | where NoncurrentDays < 3 | spath input=api.request.data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region NoncurrentDays bucketName | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_putbucketlifecycle_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. +search: '`amazon_security_lake` api.operation=PutBucketLifecycle | spath input=api.request.data + path=LifecycleConfiguration.Rule.NoncurrentVersionExpiration.NoncurrentDays output=NoncurrentDays + | where NoncurrentDays < 3 | spath input=api.request.data | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region NoncurrentDays bucketName | + rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, + http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_defense_evasion_putbucketlifecycle_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that it is a legitimate admin activity. Please consider filtering out these noisy + events using userAgent, user_arn field names. references: - https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/ tags: @@ -18,10 +38,8 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562.008 - - T1562 - T1485.001 - - T1485 + - T1562.008 product: - Splunk Enterprise - Splunk Enterprise Security @@ -30,6 +48,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml b/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml index 28a9d9a628..ab0b74e5d6 100644 --- a/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml +++ b/detections/cloud/asl_aws_defense_evasion_stop_logging_cloudtrail.yml @@ -1,17 +1,36 @@ name: ASL AWS Defense Evasion Stop Logging Cloudtrail id: 0b78a8f9-1d31-4d23-85c8-56ad13d5b4c1 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects `StopLogging` events within AWS CloudTrail logs, a critical action that adversaries may use to evade detection. By halting the logging of their malicious activities, attackers aim to operate undetected within a compromised AWS environment. This detection is achieved by monitoring for specific CloudTrail log entries that indicate the cessation of logging activities. Identifying such behavior is crucial for a Security Operations Center (SOC), as it signals an attempt to undermine the integrity of logging mechanisms, potentially allowing malicious activities to proceed without observation. The impact of this evasion tactic is significant, as it can severely hamper incident response and forensic investigations by obscuring the attacker's actions. -data_source: +description: The following analytic detects `StopLogging` events within AWS CloudTrail + logs, a critical action that adversaries may use to evade detection. By halting + the logging of their malicious activities, attackers aim to operate undetected within + a compromised AWS environment. This detection is achieved by monitoring for specific + CloudTrail log entries that indicate the cessation of logging activities. Identifying + such behavior is crucial for a Security Operations Center (SOC), as it signals an + attempt to undermine the integrity of logging mechanisms, potentially allowing malicious + activities to proceed without observation. The impact of this evasion tactic is + significant, as it can severely hamper incident response and forensic investigations + by obscuring the attacker's actions. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=StopLogging | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid - as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_stop_logging_cloudtrail_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has stopped cloudtrail logging. Please investigate this activity. +search: '`amazon_security_lake` api.operation=StopLogging | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as + user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_stop_logging_cloudtrail_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has stopped cloudtrail logging. Please investigate this activity. references: - https://attack.mitre.org/techniques/T1562/008/ drilldown_searches: @@ -44,7 +63,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -53,6 +71,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail_2.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail_2.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml b/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml index 1b45a81b7f..55888e23cc 100644 --- a/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml +++ b/detections/cloud/asl_aws_defense_evasion_update_cloudtrail.yml @@ -1,16 +1,35 @@ name: ASL AWS Defense Evasion Update Cloudtrail id: f3eb471c-16d0-404d-897c-7653f0a78cba -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects `UpdateTrail` events within AWS CloudTrail logs, aiming to identify attempts by attackers to evade detection by altering logging configurations. By updating CloudTrail settings with incorrect parameters, such as changing multi-regional logging to a single region, attackers can impair the logging of their activities across other regions. This behavior is crucial for Security Operations Centers (SOCs) to identify, as it indicates an adversary's intent to operate undetected within a compromised AWS environment. The impact of such evasion tactics is significant, potentially allowing malicious activities to proceed without being logged, thereby hindering incident response and forensic investigations. -data_source: +description: The following analytic detects `UpdateTrail` events within AWS CloudTrail + logs, aiming to identify attempts by attackers to evade detection by altering logging + configurations. By updating CloudTrail settings with incorrect parameters, such + as changing multi-regional logging to a single region, attackers can impair the + logging of their activities across other regions. This behavior is crucial for Security + Operations Centers (SOCs) to identify, as it indicates an adversary's intent to + operate undetected within a compromised AWS environment. The impact of such evasion + tactics is significant, potentially allowing malicious activities to proceed without + being logged, thereby hindering incident response and forensic investigations. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=UpdateTrail | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_update_cloudtrail_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has updated cloudtrail logging. Please investigate this activity. +search: '`amazon_security_lake` api.operation=UpdateTrail | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as + user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_update_cloudtrail_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has updated cloudtrail logging. Please investigate this activity. references: - https://attack.mitre.org/techniques/T1562/008/ drilldown_searches: @@ -42,7 +61,6 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562 - T1562.008 product: - Splunk Enterprise @@ -52,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml b/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml index 6222a0b4f0..c4a461916e 100644 --- a/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml +++ b/detections/cloud/asl_aws_ecr_container_upload_outside_business_hours.yml @@ -1,16 +1,35 @@ name: ASL AWS ECR Container Upload Outside Business Hours id: 739ed682-27e9-4ba0-80e5-a91b97698213 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly -description: The following analytic detects the upload of new containers to AWS Elastic Container Service (ECR) outside of standard business hours through AWS CloudTrail events. It identifies this behavior by monitoring for `PutImage` events occurring before 8 AM or after 8 PM, as well as any uploads on weekends. This activity is significant for a SOC to investigate as it may indicate unauthorized access or malicious deployments, potentially leading to compromised services or data breaches. Identifying and addressing such uploads promptly can mitigate the risk of security incidents and their associated impacts. -data_source: +description: The following analytic detects the upload of new containers to AWS Elastic + Container Service (ECR) outside of standard business hours through AWS CloudTrail + events. It identifies this behavior by monitoring for `PutImage` events occurring + before 8 AM or after 8 PM, as well as any uploads on weekends. This activity is + significant for a SOC to investigate as it may indicate unauthorized access or malicious + deployments, potentially leading to compromised services or data breaches. Identifying + and addressing such uploads promptly can mitigate the risk of security incidents + and their associated impacts. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=PutImage | eval hour=strftime(time/pow(10,3), "%H"), weekday=strftime(time/pow(10,3), "%A") | where hour >= 20 OR hour < 8 OR weekday=Saturday OR weekday=Sunday | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent cloud.region | rename actor.user.uid as user, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_ecr_container_upload_outside_business_hours_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: When your development is spreaded in different time zones, applying this rule can be difficult. +search: '`amazon_security_lake` api.operation=PutImage | eval hour=strftime(time/pow(10,3), + "%H"), weekday=strftime(time/pow(10,3), "%A") | where hour >= 20 OR hour < 8 OR + weekday=Saturday OR weekday=Sunday | fillnull | stats count min(_time) as firstTime + max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent + cloud.region | rename actor.user.uid as user, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_ecr_container_upload_outside_business_hours_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: When your development is spreaded in different time zones, + applying this rule can be difficult. references: - https://attack.mitre.org/techniques/T1204/003/ drilldown_searches: @@ -40,16 +59,17 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud security_domain: network - manual_test: Can't be tested automatically because of outside of business hours time + manual_test: Can't be tested automatically because of outside of business hours + time tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml b/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml index 156aab0bc0..9f92aaa8b3 100644 --- a/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml +++ b/detections/cloud/asl_aws_ecr_container_upload_unknown_user.yml @@ -1,15 +1,34 @@ name: ASL AWS ECR Container Upload Unknown User id: 886a8f46-d7e2-4439-b9ba-aec238e31732 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly -description: The following analytic detects unauthorized container uploads to AWS Elastic Container Service (ECR) by monitoring AWS CloudTrail events. It identifies instances where a new container is uploaded by a user not previously recognized as authorized. This detection is crucial for a SOC as it can indicate a potential compromise or misuse of AWS ECR, which could lead to unauthorized access to sensitive data or the deployment of malicious containers. By identifying and investigating these events, organizations can mitigate the risk of data breaches or other security incidents resulting from unauthorized container uploads. The impact of such an attack could be significant, compromising the integrity and security of the organization's cloud environment. -data_source: +description: The following analytic detects unauthorized container uploads to AWS + Elastic Container Service (ECR) by monitoring AWS CloudTrail events. It identifies + instances where a new container is uploaded by a user not previously recognized + as authorized. This detection is crucial for a SOC as it can indicate a potential + compromise or misuse of AWS ECR, which could lead to unauthorized access to sensitive + data or the deployment of malicious containers. By identifying and investigating + these events, organizations can mitigate the risk of data breaches or other security + incidents resulting from unauthorized container uploads. The impact of such an attack + could be significant, compromising the integrity and security of the organization's + cloud environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=PutImage NOT `aws_ecr_users_asl` | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_ecr_container_upload_unknown_user_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. +search: '`amazon_security_lake` api.operation=PutImage NOT `aws_ecr_users_asl` | stats + count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid + actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename + actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_ecr_container_upload_unknown_user_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. known_false_positives: unknown references: - https://attack.mitre.org/techniques/T1204/003/ @@ -42,7 +61,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security @@ -51,6 +69,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_iam_successful_group_deletion.yml b/detections/cloud/asl_aws_iam_successful_group_deletion.yml index 0eb874ecb5..c6b0e18965 100644 --- a/detections/cloud/asl_aws_iam_successful_group_deletion.yml +++ b/detections/cloud/asl_aws_iam_successful_group_deletion.yml @@ -1,16 +1,32 @@ name: ASL AWS IAM Successful Group Deletion id: 1bbe54f1-93d7-4764-8a01-ddaa12ece7ac -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Hunting -description: The following analytic detects the successful deletion of a group within AWS IAM, leveraging CloudTrail IAM events. This action, while not inherently malicious, can serve as a precursor to more sinister activities, such as unauthorized access or privilege escalation attempts. By monitoring for such deletions, the analytic aids in identifying potential preparatory steps towards an attack, allowing for early detection and mitigation. The identification of this behavior is crucial for a SOC to prevent the potential impact of an attack, which could include unauthorized access to sensitive resources or disruption of AWS environment operations. -data_source: +description: The following analytic detects the successful deletion of a group within + AWS IAM, leveraging CloudTrail IAM events. This action, while not inherently malicious, + can serve as a precursor to more sinister activities, such as unauthorized access + or privilege escalation attempts. By monitoring for such deletions, the analytic + aids in identifying potential preparatory steps towards an attack, allowing for + early detection and mitigation. The identification of this behavior is crucial for + a SOC to prevent the potential impact of an attack, which could include unauthorized + access to sensitive resources or disruption of AWS environment operations. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=DeleteGroup status=Success | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_iam_successful_group_deletion_filter`' -how_to_implement: You must install the Data Lake Federated Analytics App and ingest the logs into Splunk. -known_false_positives: This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege). +search: '`amazon_security_lake` api.operation=DeleteGroup status=Success | fillnull + | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid + actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename + actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_iam_successful_group_deletion_filter`' +how_to_implement: You must install the Data Lake Federated Analytics App and ingest + the logs into Splunk. +known_false_positives: This detection will require tuning to provide high fidelity + detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) + or by groups of users. Not every user with AWS access should have permission to + delete groups (least privilege). references: - https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html - https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html @@ -21,7 +37,6 @@ tags: mitre_attack_id: - T1069.003 - T1098 - - T1069 product: - Splunk Enterprise - Splunk Enterprise Security @@ -30,6 +45,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml b/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml index a26e3c1500..0a6a467261 100644 --- a/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml +++ b/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml @@ -1,16 +1,34 @@ name: ASL AWS Multi-Factor Authentication Disabled id: 4d2df5e0-1092-4817-88a8-79c7fa054668 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects attempts to disable multi-factor authentication (MFA) for an AWS IAM user. It leverages Amazon Security Lake logs, specifically monitoring for `DeleteVirtualMFADevice` or `DeactivateMFADevice` API operations. This activity is significant as disabling MFA can indicate an adversary attempting to weaken account security to maintain persistence using a compromised account. If confirmed malicious, this action could allow attackers to retain access to the AWS environment without detection, potentially leading to unauthorized access to sensitive resources and prolonged compromise. -data_source: +description: The following analytic detects attempts to disable multi-factor authentication + (MFA) for an AWS IAM user. It leverages Amazon Security Lake logs, specifically + monitoring for `DeleteVirtualMFADevice` or `DeactivateMFADevice` API operations. + This activity is significant as disabling MFA can indicate an adversary attempting + to weaken account security to maintain persistence using a compromised account. + If confirmed malicious, this action could allow attackers to retain access to the + AWS environment without detection, potentially leading to unauthorized access to + sensitive resources and prolonged compromise. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice) | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_multi_factor_authentication_disabled_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: AWS Administrators may disable MFA but it is highly unlikely for this event to occur without prior notice to the company +search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice) + | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation + actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region + | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, + http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_multi_factor_authentication_disabled_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: AWS Administrators may disable MFA but it is highly unlikely + for this event to occur without prior notice to the company references: - https://attack.mitre.org/techniques/T1621/ - https://aws.amazon.com/what-is/mfa/ @@ -42,11 +60,9 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 + - T1556.006 - T1586.003 - T1621 - - T1556 - - T1556.006 product: - Splunk Enterprise - Splunk Enterprise Security @@ -55,6 +71,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/aws_mfa_disabled/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/aws_mfa_disabled/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml index 7d42dfa04e..62a56cf3bb 100644 --- a/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml +++ b/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml @@ -1,26 +1,41 @@ name: ASL AWS Network Access Control List Created with All Open Ports id: a2625034-c2de-44fc-b45c-7bac9c4a7974 -version: 1 -date: '2025-01-09' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects the creation of AWS Network Access Control Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry` actions with rules allowing all traffic. This activity is significant because it can expose the network to unauthorized access, increasing the risk of data breaches and other malicious activities. If confirmed malicious, an attacker could exploit this misconfiguration to gain unrestricted access to the network, potentially leading to data exfiltration, service disruption, or further compromise of the AWS environment. -data_source: +description: The following analytic detects the creation of AWS Network Access Control + Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail + events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry` + actions with rules allowing all traffic. This activity is significant because it + can expose the network to unauthorized access, increasing the risk of data breaches + and other malicious activities. If confirmed malicious, an attacker could exploit + this misconfiguration to gain unrestricted access to the network, potentially leading + to data exfiltration, service disruption, or further compromise of the AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=CreateNetworkAclEntry OR api.operation=ReplaceNetworkAclEntry status=Success - | spath input=api.request.data path=ruleAction output=ruleAction - | spath input=api.request.data path=egress output=egress - | spath input=api.request.data path=aclProtocol output=aclProtocol - | spath input=api.request.data path=cidrBlock output=cidrBlock - | spath input=api.request.data path=networkAclId output=networkAclId +search: '`amazon_security_lake` api.operation=CreateNetworkAclEntry OR api.operation=ReplaceNetworkAclEntry + status=Success | spath input=api.request.data path=ruleAction output=ruleAction + | spath input=api.request.data path=egress output=egress | spath input=api.request.data + path=aclProtocol output=aclProtocol | spath input=api.request.data path=cidrBlock + output=cidrBlock | spath input=api.request.data path=networkAclId output=networkAclId | search ruleAction=allow AND egress=false AND aclProtocol=-1 AND cidrBlock=0.0.0.0/0 - | fillnull - | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region networkAclId cidrBlock - | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid as aws_account_id - | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_created_with_all_open_ports_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: It's possible that an admin has created this ACL with all ports open for some legitimate purpose however, this should be scoped and not allowed in production environment. + | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation + actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region + networkAclId cidrBlock | rename actor.user.uid as user, src_endpoint.ip as src_ip, + cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid + as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` + | `asl_aws_network_access_control_list_created_with_all_open_ports_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: It's possible that an admin has created this ACL with all ports + open for some legitimate purpose however, this should be scoped and not allowed + in production environment. references: [] drilldown_searches: - name: View the detection results for - "$user$" @@ -28,7 +43,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -46,7 +66,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -55,6 +74,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_network_access_control_list_deleted.yml b/detections/cloud/asl_aws_network_access_control_list_deleted.yml index 067e4b543f..23067c2c55 100644 --- a/detections/cloud/asl_aws_network_access_control_list_deleted.yml +++ b/detections/cloud/asl_aws_network_access_control_list_deleted.yml @@ -1,23 +1,35 @@ name: ASL AWS Network Access Control List Deleted id: e010ddf5-e9a5-44e5-bdd6-0c919ba8fc8b -version: 1 -date: '2025-01-09' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly -description: The following analytic detects the deletion of AWS Network Access Control Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes a network ACL entry. This activity is significant because deleting a network ACL can remove critical access restrictions, potentially allowing unauthorized access to cloud instances. If confirmed malicious, this action could enable attackers to bypass network security controls, leading to unauthorized access, data exfiltration, or further compromise of the cloud environment. -data_source: +description: The following analytic detects the deletion of AWS Network Access Control + Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes + a network ACL entry. This activity is significant because deleting a network ACL + can remove critical access restrictions, potentially allowing unauthorized access + to cloud instances. If confirmed malicious, this action could enable attackers to + bypass network security controls, leading to unauthorized access, data exfiltration, + or further compromise of the cloud environment. +data_source: - ASL AWS CloudTrail search: '`amazon_security_lake` api.operation=DeleteNetworkAclEntry status=Success - | spath input=api.request.data path=egress output=egress - | spath input=api.request.data path=networkAclId output=networkAclId - | search egress=false - | fillnull - | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region networkAclId - | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id - | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_deleted_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: It's possible that a user has legitimately deleted a network ACL. + | spath input=api.request.data path=egress output=egress | spath input=api.request.data + path=networkAclId output=networkAclId | search egress=false | fillnull | stats count + min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid + http_request.user_agent src_endpoint.ip cloud.region networkAclId | rename actor.user.uid + as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent, actor.user.account_uid as aws_account_id | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_deleted_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: It's possible that a user has legitimately deleted a network + ACL. references: [] drilldown_searches: - name: View the detection results for - "$user$" @@ -25,7 +37,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -43,7 +60,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -52,6 +68,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml b/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml index bf67c362b9..e787dbcf30 100644 --- a/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml +++ b/detections/cloud/asl_aws_new_mfa_method_registered_for_user.yml @@ -1,16 +1,34 @@ name: ASL AWS New MFA Method Registered For User id: 33ae0931-2a03-456b-b1d7-b016c5557fbd -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: experimental type: TTP -description: The following analytic identifies the registration of a new Multi-Factor Authentication (MFA) method for an AWS account, as logged through Amazon Security Lake (ASL). It detects this activity by monitoring the `CreateVirtualMFADevice` API operation within ASL logs. This behavior is significant because adversaries who gain unauthorized access to an AWS account may register a new MFA method to maintain persistence. If confirmed malicious, this activity could allow attackers to secure their access, making it harder to detect and remove their presence from the compromised environment. -data_source: +description: The following analytic identifies the registration of a new Multi-Factor + Authentication (MFA) method for an AWS account, as logged through Amazon Security + Lake (ASL). It detects this activity by monitoring the `CreateVirtualMFADevice` + API operation within ASL logs. This behavior is significant because adversaries + who gain unauthorized access to an AWS account may register a new MFA method to + maintain persistence. If confirmed malicious, this activity could allow attackers + to secure their access, making it harder to detect and remove their presence from + the compromised environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=CreateVirtualMFADevice | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_new_mfa_method_registered_for_user_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: Newly onboarded users who are registering an MFA method for the first time will also trigger this detection. +search: '`amazon_security_lake` api.operation=CreateVirtualMFADevice | fillnull | + stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid + actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename + actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_new_mfa_method_registered_for_user_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: Newly onboarded users who are registering an MFA method for + the first time will also trigger this detection. references: - https://aws.amazon.com/blogs/security/you-can-now-assign-multiple-mfa-devices-in-iam/ - https://attack.mitre.org/techniques/T1556/ @@ -30,7 +48,6 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1556 - T1556.006 product: - Splunk Enterprise @@ -40,6 +57,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/asl_aws_updateloginprofile.yml b/detections/cloud/asl_aws_updateloginprofile.yml index eab3050952..c6f1588db7 100644 --- a/detections/cloud/asl_aws_updateloginprofile.yml +++ b/detections/cloud/asl_aws_updateloginprofile.yml @@ -1,20 +1,34 @@ name: ASL AWS UpdateLoginProfile id: 5b3f63a3-865b-4637-9941-f98bd1a50c0d -version: 1 -date: '2025-01-09' +version: 2 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP -description: The following analytic detects an AWS CloudTrail event where a user with permissions updates the login profile of another user. It leverages CloudTrail logs to identify instances where the user making the change is different from the user whose profile is being updated. This activity is significant because it can indicate privilege escalation attempts, where an attacker uses a compromised account to gain higher privileges. If confirmed malicious, this could allow the attacker to escalate their privileges, potentially leading to unauthorized access and control over sensitive resources within the AWS environment. -data_source: +description: The following analytic detects an AWS CloudTrail event where a user with + permissions updates the login profile of another user. It leverages CloudTrail logs + to identify instances where the user making the change is different from the user + whose profile is being updated. This activity is significant because it can indicate + privilege escalation attempts, where an attacker uses a compromised account to gain + higher privileges. If confirmed malicious, this could allow the attacker to escalate + their privileges, potentially leading to unauthorized access and control over sensitive + resources within the AWS environment. +data_source: - ASL AWS CloudTrail -search: '`amazon_security_lake` api.operation=UpdateLoginProfile - | fillnull - | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region - | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_updateloginprofile_filter`' -how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. -known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. +search: '`amazon_security_lake` api.operation=UpdateLoginProfile | fillnull | stats + count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid + actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename + actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent + as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `asl_aws_updateloginprofile_filter`' +how_to_implement: The detection is based on Amazon Security Lake events from Amazon + Web Services (AWS), which is a centralized data lake that provides security-related + data from AWS services. To use this detection, you must ingest CloudTrail logs from + Amazon Security Lake into Splunk. To run this search, ensure that you ingest events + using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) + or the Federated Analytics App. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately created keys for another user. references: - https://bishopfox.com/blog/privilege-escalation-in-aws - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ @@ -24,12 +38,18 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: User $user$ from IP address $src_ip$ updated the login profile of another user - risk_objects: + message: User $user$ from IP address $src_ip$ updated the login profile of another + user + risk_objects: - field: user type: user score: 30 @@ -42,7 +62,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security @@ -51,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/asl_ocsf_cloudtrail.json + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/asl_ocsf_cloudtrail.json sourcetype: aws:asl source: aws_asl diff --git a/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml b/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml index 7938f15e75..f8f6815c8d 100644 --- a/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml +++ b/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml @@ -1,7 +1,7 @@ name: AWS Console Login Failed During MFA Challenge id: 55349868-5583-466f-98ab-d3beb321961e -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Compromised User Account asset_type: AWS Account mitre_attack_id: - - T1586 - T1586.003 - T1621 product: diff --git a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml index 5f46f6eb98..13339e55f9 100644 --- a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml +++ b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml @@ -1,7 +1,7 @@ name: AWS Create Policy Version to allow all resources id: 2a9b80d3-6340-4345-b5ad-212bf3d0dac4 -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_createaccesskey.yml b/detections/cloud/aws_createaccesskey.yml index 5e4a3636e3..8e4db2dd78 100644 --- a/detections/cloud/aws_createaccesskey.yml +++ b/detections/cloud/aws_createaccesskey.yml @@ -1,7 +1,7 @@ name: AWS CreateAccessKey id: 2a9b80d3-6340-4345-11ad-212bf3d0d111 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Hunting @@ -33,7 +33,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_createloginprofile.yml b/detections/cloud/aws_createloginprofile.yml index d72c2ed8a9..8e8b47aab4 100644 --- a/detections/cloud/aws_createloginprofile.yml +++ b/detections/cloud/aws_createloginprofile.yml @@ -1,7 +1,7 @@ name: AWS CreateLoginProfile id: 2a9b80d3-6340-4345-11ad-212bf444d111 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_credential_access_failed_login.yml b/detections/cloud/aws_credential_access_failed_login.yml index 7b19d32062..4034c85a31 100644 --- a/detections/cloud/aws_credential_access_failed_login.yml +++ b/detections/cloud/aws_credential_access_failed_login.yml @@ -1,7 +1,7 @@ name: AWS Credential Access Failed Login id: a19b354d-0d7f-47f3-8ea6-1a7c36434968 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Bhavin Patel, Splunk status: production type: TTP @@ -54,10 +54,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.001 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_credential_access_getpassworddata.yml b/detections/cloud/aws_credential_access_getpassworddata.yml index 24b5b4f9f6..78e473d83e 100644 --- a/detections/cloud/aws_credential_access_getpassworddata.yml +++ b/detections/cloud/aws_credential_access_getpassworddata.yml @@ -1,7 +1,7 @@ name: AWS Credential Access GetPasswordData id: 4d347c4a-306e-41db-8d10-b46baf71b3e2 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -57,10 +57,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.001 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_credential_access_rds_password_reset.yml b/detections/cloud/aws_credential_access_rds_password_reset.yml index 16d5d8fce2..344ab68bfa 100644 --- a/detections/cloud/aws_credential_access_rds_password_reset.yml +++ b/detections/cloud/aws_credential_access_rds_password_reset.yml @@ -1,7 +1,7 @@ name: AWS Credential Access RDS Password reset id: 6153c5ea-ed30-4878-81e6-21ecdb198189 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -52,9 +52,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - T1110 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml b/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml index 15acf34a9a..94cb3378c3 100644 --- a/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml +++ b/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion Delete Cloudtrail id: 82092925-9ca1-4e06-98b8-85a2d3889552 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml b/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml index 50d8d4f9f7..1ed54c1b07 100644 --- a/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml +++ b/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion Delete CloudWatch Log Group id: d308b0f1-edb7-4a62-a614-af321160710f -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562 - T1562.008 product: - Splunk Enterprise diff --git a/detections/cloud/aws_defense_evasion_impair_security_services.yml b/detections/cloud/aws_defense_evasion_impair_security_services.yml index 1f05298c2f..e4575b1b7d 100644 --- a/detections/cloud/aws_defense_evasion_impair_security_services.yml +++ b/detections/cloud/aws_defense_evasion_impair_security_services.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion Impair Security Services id: b28c4957-96a6-47e0-a965-6c767aac1458 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Gowthamaraj Rajendran, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml b/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml index 4d98499ce9..036da0fa9e 100644 --- a/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml +++ b/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion PutBucketLifecycle id: ce1c0e2b-9303-4903-818b-0d9002fc6ea4 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel status: production type: Hunting @@ -33,10 +33,8 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562.008 - - T1562 - T1485.001 - - T1485 + - T1562.008 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml b/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml index e59c2100ae..e459980cb4 100644 --- a/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml +++ b/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion Stop Logging Cloudtrail id: 8a2f3ca2-4eb5-4389-a549-14063882e537 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1562.008 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_defense_evasion_update_cloudtrail.yml b/detections/cloud/aws_defense_evasion_update_cloudtrail.yml index 89559d06de..8e6052f1b5 100644 --- a/detections/cloud/aws_defense_evasion_update_cloudtrail.yml +++ b/detections/cloud/aws_defense_evasion_update_cloudtrail.yml @@ -1,7 +1,7 @@ name: AWS Defense Evasion Update Cloudtrail id: 7c921d28-ef48-4f1b-85b3-0af8af7697db -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - AWS Defense Evasion asset_type: AWS Account mitre_attack_id: - - T1562 - T1562.008 product: - Splunk Enterprise diff --git a/detections/cloud/aws_ecr_container_scanning_findings_high.yml b/detections/cloud/aws_ecr_container_scanning_findings_high.yml index 2d8b0c01a9..5725fbb00d 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_high.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_high.yml @@ -1,7 +1,7 @@ name: AWS ECR Container Scanning Findings High id: 30a0e9f8-f1dd-4f9d-8fc2-c622461d781c -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml index 12c75e5cdc..b9aa8443f3 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml @@ -1,7 +1,7 @@ name: AWS ECR Container Scanning Findings Low Informational Unknown id: cbc95e44-7c22-443f-88fd-0424478f5589 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Eric McGinnis Splunk status: production type: Anomaly @@ -57,7 +57,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml index 74e533680f..92b1b9ea7d 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml @@ -1,7 +1,7 @@ name: AWS ECR Container Scanning Findings Medium id: 0b80e2c8-c746-4ddb-89eb-9efd892220cf -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml index 0f3a5de777..c72dfc4012 100644 --- a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml +++ b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml @@ -1,7 +1,7 @@ name: AWS ECR Container Upload Outside Business Hours id: d4c4d4eb-3994-41ca-a25e-a82d64e125bb -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_ecr_container_upload_unknown_user.yml b/detections/cloud/aws_ecr_container_upload_unknown_user.yml index bdb09cde4c..345bf6d589 100644 --- a/detections/cloud/aws_ecr_container_upload_unknown_user.yml +++ b/detections/cloud/aws_ecr_container_upload_unknown_user.yml @@ -1,7 +1,7 @@ name: AWS ECR Container Upload Unknown User id: 300688e4-365c-4486-a065-7c884462b31d -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -54,7 +54,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml index 58d7a9e5e7..330c094796 100644 --- a/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml @@ -1,7 +1,7 @@ name: AWS High Number Of Failed Authentications From Ip id: f75b7f1a-b8eb-4975-a214-ff3e0a944757 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -55,7 +55,6 @@ tags: - Compromised User Account asset_type: AWS Account mitre_attack_id: - - T1110 - T1110.003 - T1110.004 product: diff --git a/detections/cloud/aws_iam_successful_group_deletion.yml b/detections/cloud/aws_iam_successful_group_deletion.yml index 82f8c5e8fb..cc47b126e9 100644 --- a/detections/cloud/aws_iam_successful_group_deletion.yml +++ b/detections/cloud/aws_iam_successful_group_deletion.yml @@ -1,7 +1,7 @@ name: AWS IAM Successful Group Deletion id: e776d06c-9267-11eb-819b-acde48001122 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -36,7 +36,6 @@ tags: mitre_attack_id: - T1069.003 - T1098 - - T1069 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_multi_factor_authentication_disabled.yml b/detections/cloud/aws_multi_factor_authentication_disabled.yml index 827af91c86..6d85bd5101 100644 --- a/detections/cloud/aws_multi_factor_authentication_disabled.yml +++ b/detections/cloud/aws_multi_factor_authentication_disabled.yml @@ -1,7 +1,7 @@ name: AWS Multi-Factor Authentication Disabled id: 374832b1-3603-420c-b456-b373e24d34c0 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -56,11 +56,9 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 + - T1556.006 - T1586.003 - T1621 - - T1556 - - T1556.006 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml b/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml index 0e087f273c..4f1a8a187f 100644 --- a/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml +++ b/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml @@ -1,7 +1,7 @@ name: AWS Multiple Failed MFA Requests For User id: 1fece617-e614-4329-9e61-3ba228c0f353 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel status: production type: Anomaly @@ -54,7 +54,6 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - T1586.003 - T1621 product: diff --git a/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml index 7fdb466244..82e904fe15 100644 --- a/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml +++ b/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml @@ -1,7 +1,7 @@ name: AWS Multiple Users Failing To Authenticate From Ip id: 71e1fb89-dd5f-4691-8523-575420de4630 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel status: production type: Anomaly @@ -57,7 +57,6 @@ tags: - Compromised User Account asset_type: AWS Account mitre_attack_id: - - T1110 - T1110.003 - T1110.004 product: diff --git a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml index 9c3254ca93..a392435e99 100644 --- a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml +++ b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml @@ -1,7 +1,7 @@ name: AWS Network Access Control List Created with All Open Ports id: ada0f478-84a8-4641-a3f1-d82362d6bd75 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Patrick Bareiss, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_network_access_control_list_deleted.yml b/detections/cloud/aws_network_access_control_list_deleted.yml index 8499371040..fe044edec0 100644 --- a/detections/cloud/aws_network_access_control_list_deleted.yml +++ b/detections/cloud/aws_network_access_control_list_deleted.yml @@ -1,7 +1,7 @@ name: AWS Network Access Control List Deleted id: ada0f478-84a8-4641-a3f1-d82362d6fd75 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Patrick Bareiss, Splunk status: production type: Anomaly @@ -54,7 +54,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_new_mfa_method_registered_for_user.yml b/detections/cloud/aws_new_mfa_method_registered_for_user.yml index 1891036414..50a9b9bc57 100644 --- a/detections/cloud/aws_new_mfa_method_registered_for_user.yml +++ b/detections/cloud/aws_new_mfa_method_registered_for_user.yml @@ -1,7 +1,7 @@ name: AWS New MFA Method Registered For User id: 4e3c26f2-4fb9-4bd7-ab46-1b76ffa2a23b -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1556 - T1556.006 product: - Splunk Enterprise diff --git a/detections/cloud/aws_setdefaultpolicyversion.yml b/detections/cloud/aws_setdefaultpolicyversion.yml index b927809aa5..a1fef13c96 100644 --- a/detections/cloud/aws_setdefaultpolicyversion.yml +++ b/detections/cloud/aws_setdefaultpolicyversion.yml @@ -1,7 +1,7 @@ name: AWS SetDefaultPolicyVersion id: 2a9b80d3-6340-4345-11ad-212bf3d0dac4 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_successful_single_factor_authentication.yml b/detections/cloud/aws_successful_single_factor_authentication.yml index 0e3b986294..86f0eff62a 100644 --- a/detections/cloud/aws_successful_single_factor_authentication.yml +++ b/detections/cloud/aws_successful_single_factor_authentication.yml @@ -1,7 +1,7 @@ name: AWS Successful Single-Factor Authentication id: a520b1fe-cc9e-4f56-b762-18354594c52f -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -56,10 +56,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml index 6e86b15927..1ba8b2c8a4 100644 --- a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml @@ -1,7 +1,7 @@ name: AWS Unusual Number of Failed Authentications From Ip id: 0b5c9c2b-e2cb-4831-b4f1-af125ceb1386 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -57,11 +57,9 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Account mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml index a8ffb62a72..c90f5d742a 100644 --- a/detections/cloud/aws_updateloginprofile.yml +++ b/detections/cloud/aws_updateloginprofile.yml @@ -1,7 +1,7 @@ name: AWS UpdateLoginProfile id: 2a9b80d3-6a40-4115-11ad-212bf3d0d111 -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_active_directory_high_risk_sign_in.yml b/detections/cloud/azure_active_directory_high_risk_sign_in.yml index 0153fff2b2..a7a0c90d5f 100644 --- a/detections/cloud/azure_active_directory_high_risk_sign_in.yml +++ b/detections/cloud/azure_active_directory_high_risk_sign_in.yml @@ -1,7 +1,7 @@ name: Azure Active Directory High Risk Sign-in id: 1ecff169-26d7-4161-9a7b-2ac4c8e61bea -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -58,10 +58,8 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_application_administrator_role_assigned.yml b/detections/cloud/azure_ad_application_administrator_role_assigned.yml index 33eb6d2a8d..6cad0084c7 100644 --- a/detections/cloud/azure_ad_application_administrator_role_assigned.yml +++ b/detections/cloud/azure_ad_application_administrator_role_assigned.yml @@ -1,7 +1,7 @@ name: Azure AD Application Administrator Role Assigned id: eac4de87-7a56-4538-a21b-277897af6d8d -version: 6 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Azure Active Directory atomic_guid: [] mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml b/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml index 0ccbb9b85a..85366a53f5 100644 --- a/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml +++ b/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml @@ -1,7 +1,7 @@ name: Azure AD Authentication Failed During MFA Challenge id: e62c9c2e-bf51-4719-906c-3074618fcc1c -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk, 0xC0FFEEEE status: production type: TTP @@ -70,10 +70,8 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 - T1621 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_azurehound_useragent_detected.yml b/detections/cloud/azure_ad_azurehound_useragent_detected.yml index 12b044f4c3..b81c81b399 100644 --- a/detections/cloud/azure_ad_azurehound_useragent_detected.yml +++ b/detections/cloud/azure_ad_azurehound_useragent_detected.yml @@ -1,6 +1,6 @@ name: Azure AD AzureHound UserAgent Detected id: d62852db-a1f1-40db-a7fc-c3d56fa8bda3 -version: 1 +version: 2 date: '2025-01-06' author: Dean Luxton data_source: diff --git a/detections/cloud/azure_ad_device_code_authentication.yml b/detections/cloud/azure_ad_device_code_authentication.yml index dbe2c55afe..42e16cab04 100644 --- a/detections/cloud/azure_ad_device_code_authentication.yml +++ b/detections/cloud/azure_ad_device_code_authentication.yml @@ -1,7 +1,7 @@ name: Azure AD Device Code Authentication id: d68d8732-6f7e-4ee5-a6eb-737f2b990b91 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Azure Tenant mitre_attack_id: - T1528 - - T1566 - T1566.002 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_external_guest_user_invited.yml b/detections/cloud/azure_ad_external_guest_user_invited.yml index 0a30335c00..b21df736a9 100644 --- a/detections/cloud/azure_ad_external_guest_user_invited.yml +++ b/detections/cloud/azure_ad_external_guest_user_invited.yml @@ -1,6 +1,6 @@ name: Azure AD External Guest User Invited id: c1fb4edb-cab1-4359-9b40-925ffd797fb5 -version: 5 +version: 6 date: '2024-11-14' author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk status: production diff --git a/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml b/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml index 2ebfe3128c..f095735f34 100644 --- a/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml +++ b/detections/cloud/azure_ad_high_number_of_failed_authentications_for_user.yml @@ -1,7 +1,7 @@ name: Azure AD High Number Of Failed Authentications For User id: 630b1694-210a-48ee-a450-6f79e7679f2c -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Tenant mitre_attack_id: - - T1110 - T1110.001 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml b/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml index 9829ad4b7a..27095cce04 100644 --- a/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/azure_ad_high_number_of_failed_authentications_from_ip.yml @@ -1,7 +1,7 @@ name: Azure AD High Number Of Failed Authentications From Ip id: e5ab41bf-745d-4f72-a393-2611151afd8e -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Bhavin Patel, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: - NOBELIUM Group asset_type: Azure Tenant mitre_attack_id: - - T1110 - T1110.001 - T1110.003 product: diff --git a/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml b/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml index 9ede5d603b..850e70b076 100644 --- a/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml +++ b/detections/cloud/azure_ad_multi_factor_authentication_disabled.yml @@ -1,7 +1,7 @@ name: Azure AD Multi-Factor Authentication Disabled id: 482dd42a-acfa-486b-a0bb-d6fcda27318e -version: 5 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -60,10 +60,8 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1556 - T1556.006 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml b/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml index 01e3e46116..c0d6bedc46 100644 --- a/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml +++ b/detections/cloud/azure_ad_multi_source_failed_authentications_spike.yml @@ -1,7 +1,7 @@ name: Azure AD Multi-Source Failed Authentications Spike id: 116e11a9-63ea-41eb-a66a-6a13bdc7d2c7 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -53,11 +53,9 @@ tags: asset_type: Azure Tenant atomic_guid: [] mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml b/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml index c132716d7b..19537e44b7 100644 --- a/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml +++ b/detections/cloud/azure_ad_multiple_failed_mfa_requests_for_user.yml @@ -1,7 +1,7 @@ name: Azure AD Multiple Failed MFA Requests For User id: 264ea131-ab1f-41b8-90e0-33ad1a1888ea -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -62,11 +62,9 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 + - T1078.004 - T1586.003 - T1621 - - T1078 - - T1078.004 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml index db156f8d6c..6e6a789764 100644 --- a/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml +++ b/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml @@ -1,7 +1,7 @@ name: Azure AD Multiple Users Failing To Authenticate From Ip id: 94481a6a-8f59-4c86-957f-55a71e3612a6 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -60,11 +60,9 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_new_custom_domain_added.yml b/detections/cloud/azure_ad_new_custom_domain_added.yml index 9e8a4514bd..07d389a8a6 100644 --- a/detections/cloud/azure_ad_new_custom_domain_added.yml +++ b/detections/cloud/azure_ad_new_custom_domain_added.yml @@ -1,7 +1,7 @@ name: Azure AD New Custom Domain Added id: 30c47f45-dd6a-4720-9963-0bca6c8686ef -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Active Directory mitre_attack_id: - - T1484 - T1484.002 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_new_federated_domain_added.yml b/detections/cloud/azure_ad_new_federated_domain_added.yml index 18765ab8c2..0f9a57ccca 100644 --- a/detections/cloud/azure_ad_new_federated_domain_added.yml +++ b/detections/cloud/azure_ad_new_federated_domain_added.yml @@ -1,7 +1,7 @@ name: Azure AD New Federated Domain Added id: a87cd633-076d-4ab2-9047-977751a3c1a0 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Active Directory mitre_attack_id: - - T1484 - T1484.002 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_new_mfa_method_registered.yml b/detections/cloud/azure_ad_new_mfa_method_registered.yml index 548366097d..7519b45a46 100644 --- a/detections/cloud/azure_ad_new_mfa_method_registered.yml +++ b/detections/cloud/azure_ad_new_mfa_method_registered.yml @@ -1,7 +1,7 @@ name: Azure AD New MFA Method Registered id: 0488e814-eb81-42c3-9f1f-b2244973e3a3 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Tenant mitre_attack_id: - - T1098 - T1098.005 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml b/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml index aa0fd57ecc..5192c93cff 100644 --- a/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml +++ b/detections/cloud/azure_ad_new_mfa_method_registered_for_user.yml @@ -1,7 +1,7 @@ name: Azure AD New MFA Method Registered For User id: 2628b087-4189-403f-9044-87403f777a1b -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1556 - T1556.006 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_pim_role_assigned.yml b/detections/cloud/azure_ad_pim_role_assigned.yml index 62cf108b66..51d57975fc 100644 --- a/detections/cloud/azure_ad_pim_role_assigned.yml +++ b/detections/cloud/azure_ad_pim_role_assigned.yml @@ -1,7 +1,7 @@ name: Azure AD PIM Role Assigned id: fcd6dfeb-191c-46a0-a29c-c306382145ab -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Active Directory mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_pim_role_assignment_activated.yml b/detections/cloud/azure_ad_pim_role_assignment_activated.yml index 7904b536f7..08536eba75 100644 --- a/detections/cloud/azure_ad_pim_role_assignment_activated.yml +++ b/detections/cloud/azure_ad_pim_role_assignment_activated.yml @@ -1,7 +1,7 @@ name: Azure AD PIM Role Assignment Activated id: 952e80d0-e343-439b-83f4-808c3e6fbf2e -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Active Directory mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_privileged_role_assigned.yml b/detections/cloud/azure_ad_privileged_role_assigned.yml index e08cfb1eea..c1316e7829 100644 --- a/detections/cloud/azure_ad_privileged_role_assigned.yml +++ b/detections/cloud/azure_ad_privileged_role_assigned.yml @@ -1,7 +1,7 @@ name: Azure AD Privileged Role Assigned id: a28f0bc3-3400-4a6e-a2da-89b9e95f0d2a -version: 6 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - NOBELIUM Group asset_type: Azure Active Directory mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml b/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml index 5cc46e6989..e054e3954c 100644 --- a/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml +++ b/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml @@ -1,7 +1,7 @@ name: Azure AD Privileged Role Assigned to Service Principal id: 5dfaa3d3-e2e4-4053-8252-16d9ee528c41 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - NOBELIUM Group asset_type: Azure Active Directory mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_service_principal_enumeration.yml b/detections/cloud/azure_ad_service_principal_enumeration.yml index 67af2a74cc..67efb06d67 100644 --- a/detections/cloud/azure_ad_service_principal_enumeration.yml +++ b/detections/cloud/azure_ad_service_principal_enumeration.yml @@ -1,6 +1,6 @@ name: Azure AD Service Principal Enumeration id: 3f0647ce-add5-4436-8039-cbd1abe74563 -version: 1 +version: 2 date: '2025-01-06' author: Dean Luxton data_source: diff --git a/detections/cloud/azure_ad_service_principal_new_client_credentials.yml b/detections/cloud/azure_ad_service_principal_new_client_credentials.yml index c737df98b8..d61c4114f4 100644 --- a/detections/cloud/azure_ad_service_principal_new_client_credentials.yml +++ b/detections/cloud/azure_ad_service_principal_new_client_credentials.yml @@ -1,7 +1,7 @@ name: Azure AD Service Principal New Client Credentials id: e3adc0d3-9e4b-4b5d-b662-12cec1adff2a -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: - NOBELIUM Group asset_type: Azure Active Directory mitre_attack_id: - - T1098 - T1098.001 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_service_principal_owner_added.yml b/detections/cloud/azure_ad_service_principal_owner_added.yml index 652d5977ff..70759d0bbc 100644 --- a/detections/cloud/azure_ad_service_principal_owner_added.yml +++ b/detections/cloud/azure_ad_service_principal_owner_added.yml @@ -1,6 +1,6 @@ name: Azure AD Service Principal Owner Added id: 7ddf2084-6cf3-4a44-be83-474f7b73c701 -version: 7 +version: 8 date: '2024-11-14' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/cloud/azure_ad_service_principal_privilege_escalation.yml b/detections/cloud/azure_ad_service_principal_privilege_escalation.yml index 29720e929f..ea9b383f6a 100644 --- a/detections/cloud/azure_ad_service_principal_privilege_escalation.yml +++ b/detections/cloud/azure_ad_service_principal_privilege_escalation.yml @@ -1,24 +1,35 @@ name: Azure AD Service Principal Privilege Escalation id: 29eb39d3-2bc8-49cc-99b3-35593191a588 -version: 1 -date: '2025-01-06' +version: 2 +date: '2025-02-10' author: Dean Luxton data_source: - Azure Active Directory Add app role assignment to service principal type: TTP status: production -description: This detection identifies when an Azure Service Principal elevates privileges by adding themself to a new app role assignment. +description: This detection identifies when an Azure Service Principal elevates privileges + by adding themself to a new app role assignment. search: >- - `azure_monitor_aad` category=AuditLogs operationName="Add app role assignment to service principal" properties.initiatedBy.app.displayName=* properties.result=Success - | spath path=properties{}.targetResources{}.modifiedProperties{} output=targetResources - | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) as targetServicePrincipal values(eval(mvindex('properties.targetResources{}.displayName',0))) as targetAppContext values(user_agent) as user_agent values(identity) as servicePrincipal values(properties.initiatedBy.app.servicePrincipalId) as servicePrincipalId by operationName tenantId correlationId + `azure_monitor_aad` category=AuditLogs operationName="Add app role assignment to + service principal" properties.initiatedBy.app.displayName=* properties.result=Success | + spath path=properties{}.targetResources{}.modifiedProperties{} output=targetResources + | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) + as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) + as targetServicePrincipal values(eval(mvindex('properties.targetResources{}.displayName',0))) + as targetAppContext values(user_agent) as user_agent values(identity) as servicePrincipal + values(properties.initiatedBy.app.servicePrincipalId) as servicePrincipalId by operationName + tenantId correlationId | spath input=appRole path=newValue output=appRole | spath input=targetServicePrincipal path=newValue output=targetServicePrincipal - | eval appRole=trim(replace(appRole, "\"", "")), targetServicePrincipal=trim(replace(targetServicePrincipal, "\"", "")) + | eval appRole=trim(replace(appRole, "\"", "")), targetServicePrincipal=trim(replace(targetServicePrincipal, + "\"", "")) | where servicePrincipal=targetServicePrincipal - | table _time operationName servicePrincipal servicePrincipalId appRole targetAppContext user_agent tenantId correlationId + | table _time operationName servicePrincipal servicePrincipalId appRole targetAppContext + user_agent tenantId correlationId | `azure_ad_service_principal_privilege_escalation_filter` -how_to_implement: The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest EntraID audit logs via Azure EventHub. See reference for links for further details on how to onboard this log source. +how_to_implement: The Splunk Add-on for Microsoft Cloud Services add-on is required + to ingest EntraID audit logs via Azure EventHub. See reference for links for further + details on how to onboard this log source. known_false_positives: Unknown references: - https://splunkbase.splunk.com/app/3110 @@ -32,11 +43,17 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$servicePrincipal$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ -rba: - message: Service Principal $servicePrincipal$ has elevated privileges by adding themself to app role $appRole$ +rba: + message: Service Principal $servicePrincipal$ has elevated privileges by adding + themself to app role $appRole$ risk_objects: - field: servicePrincipal type: user @@ -50,7 +67,6 @@ tags: asset_type: Azure Tenant mitre_attack_id: - T1098.003 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security @@ -59,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log sourcetype: azure:monitor:aad source: Azure AD diff --git a/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml b/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml index 84f19bd9f2..a8a8cf0127 100644 --- a/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml +++ b/detections/cloud/azure_ad_successful_authentication_from_different_ips.yml @@ -1,7 +1,7 @@ name: Azure AD Successful Authentication From Different Ips id: be6d868d-33b6-4aaa-912e-724fb555b11a -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Tenant mitre_attack_id: - - T1110 - T1110.001 - T1110.003 product: diff --git a/detections/cloud/azure_ad_successful_powershell_authentication.yml b/detections/cloud/azure_ad_successful_powershell_authentication.yml index 40fc93f31e..47cb6d8ad7 100644 --- a/detections/cloud/azure_ad_successful_powershell_authentication.yml +++ b/detections/cloud/azure_ad_successful_powershell_authentication.yml @@ -1,7 +1,7 @@ name: Azure AD Successful PowerShell Authentication id: 62f10052-d7b3-4e48-b57b-56f8e3ac7ceb -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -60,10 +60,8 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_successful_single_factor_authentication.yml b/detections/cloud/azure_ad_successful_single_factor_authentication.yml index 08b55c21be..0df441eb5a 100644 --- a/detections/cloud/azure_ad_successful_single_factor_authentication.yml +++ b/detections/cloud/azure_ad_successful_single_factor_authentication.yml @@ -1,7 +1,7 @@ name: Azure AD Successful Single-Factor Authentication id: a560e7f6-1711-4353-885b-40be53101fcd -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -57,10 +57,8 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml b/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml index af3e2f430f..9e187787e0 100644 --- a/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml +++ b/detections/cloud/azure_ad_tenant_wide_admin_consent_granted.yml @@ -1,7 +1,7 @@ name: Azure AD Tenant Wide Admin Consent Granted id: dc02c0ee-6ac0-4c7f-87ba-8ce43a4e4418 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: - NOBELIUM Group asset_type: Azure Tenant mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml index 24fdfff29f..b8d2b2b680 100644 --- a/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml @@ -1,7 +1,7 @@ name: Azure AD Unusual Number of Failed Authentications From Ip id: 3d8d3a36-93b8-42d7-8d91-c5f24cec223d -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -62,11 +62,9 @@ tags: - Azure Active Directory Account Takeover asset_type: Azure Active Directory mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/azure_ad_user_enabled_and_password_reset.yml b/detections/cloud/azure_ad_user_enabled_and_password_reset.yml index 5cd6090c48..f3601f5b68 100644 --- a/detections/cloud/azure_ad_user_enabled_and_password_reset.yml +++ b/detections/cloud/azure_ad_user_enabled_and_password_reset.yml @@ -1,6 +1,6 @@ name: Azure AD User Enabled And Password Reset id: 1347b9e8-2daa-4a6f-be73-b421d3d9e268 -version: 6 +version: 7 date: '2024-11-14' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml b/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml index 597d44032d..bb46d01420 100644 --- a/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml +++ b/detections/cloud/azure_ad_user_immutableid_attribute_updated.yml @@ -1,6 +1,6 @@ name: Azure AD User ImmutableId Attribute Updated id: 0c0badad-4536-4a84-a561-5ff760f3c00e -version: 5 +version: 6 date: '2024-11-14' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/cloud/azure_automation_account_created.yml b/detections/cloud/azure_automation_account_created.yml index 61c90cb7d6..9bbaf90a45 100644 --- a/detections/cloud/azure_automation_account_created.yml +++ b/detections/cloud/azure_automation_account_created.yml @@ -1,7 +1,7 @@ name: Azure Automation Account Created id: 860902fd-2e76-46b3-b050-ba548dab576c -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Tenant mitre_attack_id: - - T1136 - T1136.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_automation_runbook_created.yml b/detections/cloud/azure_automation_runbook_created.yml index 30cd14ac36..2188fcc83f 100644 --- a/detections/cloud/azure_automation_runbook_created.yml +++ b/detections/cloud/azure_automation_runbook_created.yml @@ -1,7 +1,7 @@ name: Azure Automation Runbook Created id: 178d696d-6dc6-4ee8-9d25-93fee34eaf5b -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Tenant mitre_attack_id: - - T1136 - T1136.003 product: - Splunk Enterprise diff --git a/detections/cloud/azure_runbook_webhook_created.yml b/detections/cloud/azure_runbook_webhook_created.yml index f380d8cff2..d53e163981 100644 --- a/detections/cloud/azure_runbook_webhook_created.yml +++ b/detections/cloud/azure_runbook_webhook_created.yml @@ -1,7 +1,7 @@ name: Azure Runbook Webhook Created id: e98944a9-92e4-443c-81b8-a322e33ce75a -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - Azure Active Directory Persistence asset_type: Azure Tenant mitre_attack_id: - - T1078 - T1078.004 product: - Splunk Enterprise diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index 4608e0889a..67198da281 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -1,7 +1,7 @@ name: Cloud Compute Instance Created By Previously Unseen User id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Anomaly @@ -46,7 +46,6 @@ tags: asset_type: Cloud Compute Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml index d3189b230e..ffe314acbf 100644 --- a/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml @@ -1,7 +1,7 @@ name: Cloud Instance Modified By Previously Unseen User id: 7fb15084-b14e-405a-bd61-a6de15a40722 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Anomaly @@ -44,7 +44,6 @@ tags: asset_type: AWS Instance mitre_attack_id: - T1078.004 - - T1078 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/detect_aws_console_login_by_new_user.yml b/detections/cloud/detect_aws_console_login_by_new_user.yml index ac6587474d..135b7f9126 100644 --- a/detections/cloud/detect_aws_console_login_by_new_user.yml +++ b/detections/cloud/detect_aws_console_login_by_new_user.yml @@ -1,7 +1,7 @@ name: Detect AWS Console Login by New User id: bc91a8cd-35e7-4bb2-6140-e756cc46fd71 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Hunting @@ -38,9 +38,8 @@ tags: - AWS Identity and Access Management Account Takeover asset_type: AWS Instance mitre_attack_id: - - T1586 - - T1586.003 - T1552 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml index 2fea4b9d13..041ef49278 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml @@ -1,7 +1,7 @@ name: Detect AWS Console Login by User from New City id: 121b0b11-f8ac-4ed6-a132-3800ca4fc07a -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Eric McGinnis Splunk status: production type: Hunting @@ -45,9 +45,8 @@ tags: - Compromised User Account asset_type: AWS Instance mitre_attack_id: - - T1586 - - T1586.003 - T1535 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml index afbc290db7..11effae0f4 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml @@ -1,7 +1,7 @@ name: Detect AWS Console Login by User from New Country id: 67bd3def-c41c-4bf6-837b-ae196b4257c6 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Eric McGinnis Splunk status: production type: Hunting @@ -45,9 +45,8 @@ tags: - Compromised User Account asset_type: AWS Instance mitre_attack_id: - - T1586 - - T1586.003 - T1535 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml index 8c47e6e6a9..9fc447b49b 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml @@ -1,7 +1,7 @@ name: Detect AWS Console Login by User from New Region id: 9f31aa8e-e37c-46bc-bce1-8b3be646d026 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Eric McGinnis Splunk status: production type: Hunting @@ -46,9 +46,8 @@ tags: - Compromised User Account asset_type: AWS Instance mitre_attack_id: - - T1586 - - T1586.003 - T1535 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml b/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml index 86cae6e982..be2a129f28 100644 --- a/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml +++ b/detections/cloud/gcp_authentication_failed_during_mfa_challenge.yml @@ -1,7 +1,7 @@ name: GCP Authentication Failed During MFA Challenge id: 345f7e1d-a3fe-4158-abd8-e630f9878323 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: TTP @@ -55,10 +55,8 @@ tags: - GCP Account Takeover asset_type: Google Cloud Platform tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 - T1621 product: - Splunk Enterprise diff --git a/detections/cloud/gcp_multi_factor_authentication_disabled.yml b/detections/cloud/gcp_multi_factor_authentication_disabled.yml index dc6b0479ea..adb0fa638a 100644 --- a/detections/cloud/gcp_multi_factor_authentication_disabled.yml +++ b/detections/cloud/gcp_multi_factor_authentication_disabled.yml @@ -1,7 +1,7 @@ name: GCP Multi-Factor Authentication Disabled id: b9bc5513-6fc1-4821-85a3-e1d81e451c83 -version: 5 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: TTP @@ -58,10 +58,8 @@ tags: - GCP Account Takeover asset_type: GCP mitre_attack_id: - - T1586 - - T1586.003 - - T1556 - T1556.006 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml b/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml index 613b536a54..1a8d679b8a 100644 --- a/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml +++ b/detections/cloud/gcp_multiple_failed_mfa_requests_for_user.yml @@ -1,7 +1,7 @@ name: GCP Multiple Failed MFA Requests For User id: cbb3cb84-c06f-4393-adcc-5cb6195621f1 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -60,11 +60,9 @@ tags: - GCP Account Takeover asset_type: Google Cloud Platform tenant mitre_attack_id: - - T1586 + - T1078.004 - T1586.003 - T1621 - - T1078 - - T1078.004 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml index e5b02c1c25..3d44e59505 100644 --- a/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml +++ b/detections/cloud/gcp_multiple_users_failing_to_authenticate_from_ip.yml @@ -1,7 +1,7 @@ name: GCP Multiple Users Failing To Authenticate From Ip id: da20828e-d6fb-4ee5-afb7-d0ac200923d5 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -61,11 +61,9 @@ tags: - GCP Account Takeover asset_type: Google Cloud Platform tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gcp_successful_single_factor_authentication.yml b/detections/cloud/gcp_successful_single_factor_authentication.yml index 3f13fa8928..8f1d80ddae 100644 --- a/detections/cloud/gcp_successful_single_factor_authentication.yml +++ b/detections/cloud/gcp_successful_single_factor_authentication.yml @@ -1,7 +1,7 @@ name: GCP Successful Single-Factor Authentication id: 40e17d88-87da-414e-b253-8dc1e4f9555b -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: TTP @@ -57,10 +57,8 @@ tags: - GCP Account Takeover asset_type: Google Cloud Platform tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1078 - T1078.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml index 7e59b0346a..1ab7a9b099 100644 --- a/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/gcp_unusual_number_of_failed_authentications_from_ip.yml @@ -1,7 +1,7 @@ name: GCP Unusual Number of Failed Authentications From Ip id: bd8097ed-958a-4873-87d9-44f2b4d85705 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -63,11 +63,9 @@ tags: - GCP Account Takeover asset_type: Google Cloud Platform tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/github_actions_disable_security_workflow.yml b/detections/cloud/github_actions_disable_security_workflow.yml index 8d8f8d8c2a..e9e0bdb045 100644 --- a/detections/cloud/github_actions_disable_security_workflow.yml +++ b/detections/cloud/github_actions_disable_security_workflow.yml @@ -1,7 +1,7 @@ name: GitHub Actions Disable Security Workflow id: 0459f1a5-c0ac-4987-82d6-65081209f854 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -57,7 +57,6 @@ tags: asset_type: GitHub mitre_attack_id: - T1195.002 - - T1195 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/github_dependabot_alert.yml b/detections/cloud/github_dependabot_alert.yml index 0e93d69aae..b4e1b2b108 100644 --- a/detections/cloud/github_dependabot_alert.yml +++ b/detections/cloud/github_dependabot_alert.yml @@ -1,7 +1,7 @@ name: GitHub Dependabot Alert id: 05032b04-4469-4034-9df7-05f607d75cba -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -52,7 +52,6 @@ tags: asset_type: GitHub mitre_attack_id: - T1195.001 - - T1195 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/github_pull_request_from_unknown_user.yml b/detections/cloud/github_pull_request_from_unknown_user.yml index 8cfcb7f5fc..44fcbc501e 100644 --- a/detections/cloud/github_pull_request_from_unknown_user.yml +++ b/detections/cloud/github_pull_request_from_unknown_user.yml @@ -1,7 +1,7 @@ name: GitHub Pull Request from Unknown User id: 9d7b9100-8878-4404-914e-ca5e551a641e -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -53,7 +53,6 @@ tags: asset_type: GitHub mitre_attack_id: - T1195.001 - - T1195 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_drive_share_in_external_email.yml b/detections/cloud/gsuite_drive_share_in_external_email.yml index 469c97577b..0ad1ce1463 100644 --- a/detections/cloud/gsuite_drive_share_in_external_email.yml +++ b/detections/cloud/gsuite_drive_share_in_external_email.yml @@ -1,7 +1,7 @@ name: Gsuite Drive Share In External Email id: f6ee02d6-fea0-11eb-b2c2-acde48001122 -version: 4 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: experimental type: Anomaly @@ -49,7 +49,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1567.002 - - T1567 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_email_suspicious_attachment.yml b/detections/cloud/gsuite_email_suspicious_attachment.yml index 7c29d2848b..36963d2120 100644 --- a/detections/cloud/gsuite_email_suspicious_attachment.yml +++ b/detections/cloud/gsuite_email_suspicious_attachment.yml @@ -1,7 +1,7 @@ name: GSuite Email Suspicious Attachment id: 6d663014-fe92-11eb-ab07-acde48001122 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml b/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml index 9a0e32f6bd..014b621125 100644 --- a/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml +++ b/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml @@ -1,7 +1,7 @@ name: Gsuite Email Suspicious Subject With Attachment id: 8ef3971e-00f2-11ec-b54f-acde48001122 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml b/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml index cc41adee08..6d4f09108b 100644 --- a/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml +++ b/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml @@ -1,7 +1,7 @@ name: Gsuite Email With Known Abuse Web Service Link id: 8630aa22-042b-11ec-af39-acde48001122 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml b/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml index e154a605f3..196839b387 100644 --- a/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml +++ b/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml @@ -1,7 +1,7 @@ name: Gsuite Outbound Email With Attachment To External Domain id: dc4dc3a8-ff54-11eb-8bf7-acde48001122 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Stanislav Miskovic, Splunk status: production type: Hunting @@ -37,7 +37,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1048.003 - - T1048 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_suspicious_shared_file_name.yml b/detections/cloud/gsuite_suspicious_shared_file_name.yml index 311f449b7f..a660e05c8c 100644 --- a/detections/cloud/gsuite_suspicious_shared_file_name.yml +++ b/detections/cloud/gsuite_suspicious_shared_file_name.yml @@ -1,7 +1,7 @@ name: Gsuite Suspicious Shared File Name id: 07eed200-03f5-11ec-98fb-acde48001122 -version: 4 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: GSuite mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/high_number_of_login_failures_from_a_single_source.yml b/detections/cloud/high_number_of_login_failures_from_a_single_source.yml index a42e10bb7f..7f6fe588f5 100644 --- a/detections/cloud/high_number_of_login_failures_from_a_single_source.yml +++ b/detections/cloud/high_number_of_login_failures_from_a_single_source.yml @@ -1,7 +1,7 @@ name: High Number of Login Failures from a single source id: 7f398cfb-918d-41f4-8db8-2e2474e02222 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: Anomaly @@ -60,7 +60,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1110.001 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_add_app_role_assignment_grant_user.yml b/detections/cloud/o365_add_app_role_assignment_grant_user.yml index 40dbc0137d..4137c89c71 100644 --- a/detections/cloud/o365_add_app_role_assignment_grant_user.yml +++ b/detections/cloud/o365_add_app_role_assignment_grant_user.yml @@ -1,7 +1,7 @@ name: O365 Add App Role Assignment Grant User id: b2c81cc6-6040-11eb-ae93-0242ac130002 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Rod Soto, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_added_service_principal.yml b/detections/cloud/o365_added_service_principal.yml index 239d6317b9..ead8633c06 100644 --- a/detections/cloud/o365_added_service_principal.yml +++ b/detections/cloud/o365_added_service_principal.yml @@ -1,7 +1,7 @@ name: O365 Added Service Principal id: 1668812a-6047-11eb-ae93-0242ac130002 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Rod Soto, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_advanced_audit_disabled.yml b/detections/cloud/o365_advanced_audit_disabled.yml index fde6c3a0f8..ac2211f458 100644 --- a/detections/cloud/o365_advanced_audit_disabled.yml +++ b/detections/cloud/o365_advanced_audit_disabled.yml @@ -1,7 +1,7 @@ name: O365 Advanced Audit Disabled id: 49862dd4-9cb2-4c48-a542-8c8a588d9361 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Office 365 Persistence Mechanisms asset_type: O365 Tenant mitre_attack_id: - - T1562 - T1562.008 product: - Splunk Enterprise diff --git a/detections/cloud/o365_application_available_to_other_tenants.yml b/detections/cloud/o365_application_available_to_other_tenants.yml index 0ecc7bab04..1f1a06b147 100644 --- a/detections/cloud/o365_application_available_to_other_tenants.yml +++ b/detections/cloud/o365_application_available_to_other_tenants.yml @@ -1,7 +1,7 @@ name: O365 Application Available To Other Tenants id: 942548a3-0273-47a4-8dbd-e5202437395c -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1098.003 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_applicationimpersonation_role_assigned.yml b/detections/cloud/o365_applicationimpersonation_role_assigned.yml index 777f8755aa..ece9018152 100644 --- a/detections/cloud/o365_applicationimpersonation_role_assigned.yml +++ b/detections/cloud/o365_applicationimpersonation_role_assigned.yml @@ -1,7 +1,7 @@ name: O365 ApplicationImpersonation Role Assigned id: 49cdce75-f814-4d56-a7a4-c64ec3a481f2 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - NOBELIUM Group asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml index 6ad687a266..e0b6f6f7fc 100644 --- a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml +++ b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml @@ -1,7 +1,7 @@ name: O365 Bypass MFA via Trusted IP id: c783dd98-c703-4252-9e8a-f19d9f66949e -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_compliance_content_search_exported.yml b/detections/cloud/o365_compliance_content_search_exported.yml index 74ff0f6355..56cbf61d9c 100644 --- a/detections/cloud/o365_compliance_content_search_exported.yml +++ b/detections/cloud/o365_compliance_content_search_exported.yml @@ -1,7 +1,7 @@ name: O365 Compliance Content Search Exported id: 2ce9f31d-ab4f-4179-b2b7-c77a9652e1d8 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -53,7 +53,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_compliance_content_search_started.yml b/detections/cloud/o365_compliance_content_search_started.yml index 2b4440c1d1..554aaf4c15 100644 --- a/detections/cloud/o365_compliance_content_search_started.yml +++ b/detections/cloud/o365_compliance_content_search_started.yml @@ -1,7 +1,7 @@ name: O365 Compliance Content Search Started id: f4cabbc7-c19a-4e41-8be5-98daeaccbb50 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -53,7 +53,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_elevated_mailbox_permission_assigned.yml b/detections/cloud/o365_elevated_mailbox_permission_assigned.yml index 361a0b8cf7..3b9ff5e1f8 100644 --- a/detections/cloud/o365_elevated_mailbox_permission_assigned.yml +++ b/detections/cloud/o365_elevated_mailbox_permission_assigned.yml @@ -1,7 +1,7 @@ name: O365 Elevated Mailbox Permission Assigned id: 2246c142-a678-45f8-8546-aaed7e0efd30 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Mauricio Velazco, Splunk data_source: [] type: TTP @@ -53,7 +53,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_email_access_by_security_administrator.yml b/detections/cloud/o365_email_access_by_security_administrator.yml index 99d7b99204..df598e1fa9 100644 --- a/detections/cloud/o365_email_access_by_security_administrator.yml +++ b/detections/cloud/o365_email_access_by_security_administrator.yml @@ -1,7 +1,7 @@ name: O365 Email Access By Security Administrator id: c6998a30-fef4-4e89-97ac-3bb0123719b4 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -54,9 +54,8 @@ tags: - Office 365 Account Takeover asset_type: O365 Tenant mitre_attack_id: - - T1567 - - T1114 - T1114.002 + - T1567 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_email_reported_by_admin_found_malicious.yml b/detections/cloud/o365_email_reported_by_admin_found_malicious.yml index 0a5d4aa0fa..405e008e80 100644 --- a/detections/cloud/o365_email_reported_by_admin_found_malicious.yml +++ b/detections/cloud/o365_email_reported_by_admin_found_malicious.yml @@ -1,7 +1,7 @@ name: O365 Email Reported By Admin Found Malicious id: 94396c3e-7728-422a-9956-e4b77b53dbdf -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -57,7 +57,6 @@ tags: - Suspicious Emails asset_type: O365 Tenant mitre_attack_id: - - T1566 - T1566.001 - T1566.002 product: diff --git a/detections/cloud/o365_email_reported_by_user_found_malicious.yml b/detections/cloud/o365_email_reported_by_user_found_malicious.yml index edbf3a10b7..685ecb2198 100644 --- a/detections/cloud/o365_email_reported_by_user_found_malicious.yml +++ b/detections/cloud/o365_email_reported_by_user_found_malicious.yml @@ -1,7 +1,7 @@ name: O365 Email Reported By User Found Malicious id: 7698b945-238e-4bb9-b172-81f5ca1685a1 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -59,7 +59,6 @@ tags: - Suspicious Emails asset_type: O365 Tenant mitre_attack_id: - - T1566 - T1566.001 - T1566.002 product: diff --git a/detections/cloud/o365_email_security_feature_changed.yml b/detections/cloud/o365_email_security_feature_changed.yml index 9afe560662..983ce4e11a 100644 --- a/detections/cloud/o365_email_security_feature_changed.yml +++ b/detections/cloud/o365_email_security_feature_changed.yml @@ -1,7 +1,7 @@ name: O365 Email Security Feature Changed id: 4d28013d-3a0f-4d65-a33f-4e8009fee0ae -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -51,9 +51,8 @@ tags: - Office 365 Account Takeover asset_type: O365 Tenant mitre_attack_id: - - T1562 - - T1562.008 - T1562.001 + - T1562.008 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_email_suspicious_behavior_alert.yml b/detections/cloud/o365_email_suspicious_behavior_alert.yml index f6770028e1..5714addcec 100644 --- a/detections/cloud/o365_email_suspicious_behavior_alert.yml +++ b/detections/cloud/o365_email_suspicious_behavior_alert.yml @@ -1,7 +1,7 @@ name: O365 Email Suspicious Behavior Alert id: 85c7555a-05af-4322-81aa-76b4ddf52baa -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -54,7 +54,6 @@ tags: - Office 365 Account Takeover asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_email_transport_rule_changed.yml b/detections/cloud/o365_email_transport_rule_changed.yml new file mode 100644 index 0000000000..bd7a4f1ee2 --- /dev/null +++ b/detections/cloud/o365_email_transport_rule_changed.yml @@ -0,0 +1,67 @@ +name: O365 Email Transport Rule Changed +id: 11ebb7c2-46bd-41c9-81e1-d0b4b34583a2 +version: 1 +date: '2025-01-15' +author: Steven Dick +status: production +type: Anomaly +description: The following analytic identifies when a user with sufficient access to Exchange Online alters the mail flow/transport rule configuration of the organization. Transport rules are a set of rules that can be used by attackers to modify or delete emails based on specific conditions, this activity could indicate an attacker hiding or exfiltrated data. +data_source: +- Office 365 Universal Audit Log +search: |- + `o365_management_activity` Workload=Exchange AND Operation IN ("Set-*","Disable-*","New-*","Remove-*") AND Operation="*TransportRule" + | eval object_name = case('Parameters{}.Name'=="Name",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Name$")),true(),ObjectId), object_id = case('Parameters{}.Name'=="Identity",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Identity$")),true(),Id) + | stats values(object_name) as object_name, min(_time) as firstTime, max(_time) as lastTime, count by object_id, UserId, Operation + | rename UserId as user, Operation as signature + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `o365_email_transport_rule_changed_filter` +how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. +known_false_positives: Legitimate administrative changes for business needs. +references: +- https://attack.mitre.org/techniques/T1114/003/ +- https://cardinalops.com/blog/cardinalops-contributes-new-mitre-attck-techniques-related-to-abuse-of-mail-transport-rules/ +- https://www.microsoft.com/en-us/security/blog/2022/09/22/malicious-OAuth-applications-used-to-compromise-email-servers-and-spread-spam/ +drilldown_searches: +- name: View the detection results for - "$user$" + search: '%original_detection_search% | search user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate changes by $user$ + search: '`o365_management_activity` Workload=Exchange AND Operation IN ("Set-*","Disable-*","New-*","Remove-*") AND Operation="*Transport*" UserId=$user$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The user [$user$] altered the exchange transport rule id [$object_name$] + risk_objects: + - field: user + type: user + score: 25 + threat_objects: + - field: object_id + type: signature + - field: object_name + type: signature +tags: + analytic_story: + - Data Exfiltration + - Office 365 Account Takeover + asset_type: O365 Tenant + mitre_attack_id: + - T1114.003 + - T1564.008 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: threat +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/transport_rule_change/transport_rule_change.log + source: o365 + sourcetype: o365:management:activity diff --git a/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml b/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml index 41d867d860..259430989e 100644 --- a/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml +++ b/detections/cloud/o365_high_number_of_failed_authentications_for_user.yml @@ -1,7 +1,7 @@ name: O365 High Number Of Failed Authentications for User id: 31641378-2fa9-42b1-948e-25e281cb98f7 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Office 365 Account Takeover asset_type: O365 Tenant mitre_attack_id: - - T1110 - T1110.001 product: - Splunk Enterprise diff --git a/detections/cloud/o365_high_privilege_role_granted.yml b/detections/cloud/o365_high_privilege_role_granted.yml index bbe4d281d2..57d53359d0 100644 --- a/detections/cloud/o365_high_privilege_role_granted.yml +++ b/detections/cloud/o365_high_privilege_role_granted.yml @@ -1,7 +1,7 @@ name: O365 High Privilege Role Granted id: e78a1037-4548-4072-bb1b-ad99ae416426 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - Office 365 Persistence Mechanisms asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_mailbox_email_forwarding_enabled.yml b/detections/cloud/o365_mailbox_email_forwarding_enabled.yml index 28c3e91e3f..d4f69f2bd4 100644 --- a/detections/cloud/o365_mailbox_email_forwarding_enabled.yml +++ b/detections/cloud/o365_mailbox_email_forwarding_enabled.yml @@ -1,7 +1,7 @@ name: O365 Mailbox Email Forwarding Enabled id: 0b6bc75c-05d1-4101-9fc3-97e706168f24 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Mauricio Velazco, Splunk data_source: [] type: TTP @@ -54,7 +54,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml b/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml index e3f85487ae..867df0355e 100644 --- a/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml +++ b/detections/cloud/o365_mailbox_folder_read_permission_assigned.yml @@ -1,7 +1,7 @@ name: O365 Mailbox Folder Read Permission Assigned id: 1435475e-2128-4417-a34f-59770733b0d5 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -55,7 +55,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_mailbox_folder_read_permission_granted.yml b/detections/cloud/o365_mailbox_folder_read_permission_granted.yml index 6b0939ee72..b6ad3e3269 100644 --- a/detections/cloud/o365_mailbox_folder_read_permission_granted.yml +++ b/detections/cloud/o365_mailbox_folder_read_permission_granted.yml @@ -1,7 +1,7 @@ name: O365 Mailbox Folder Read Permission Granted id: cd15c0a8-470e-4b12-9517-046e4927db30 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -54,7 +54,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml b/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml index 253de4acee..079ba2b14a 100644 --- a/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml +++ b/detections/cloud/o365_mailbox_inbox_folder_shared_with_all_users.yml @@ -1,7 +1,7 @@ name: O365 Mailbox Inbox Folder Shared with All Users id: 21421896-a692-4594-9888-5faeb8a53106 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: - Office 365 Persistence Mechanisms asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.002 product: - Splunk Enterprise diff --git a/detections/cloud/o365_mailbox_read_access_granted_to_application.yml b/detections/cloud/o365_mailbox_read_access_granted_to_application.yml index 73b115897f..ea65305c88 100644 --- a/detections/cloud/o365_mailbox_read_access_granted_to_application.yml +++ b/detections/cloud/o365_mailbox_read_access_granted_to_application.yml @@ -1,7 +1,7 @@ name: O365 Mailbox Read Access Granted to Application id: 27ab61c5-f08a-438a-b4d3-325e666490b3 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -59,10 +59,8 @@ tags: - Office 365 Persistence Mechanisms asset_type: O365 Tenant mitre_attack_id: - - T1114.002 - - T1114 - - T1098 - T1098.003 + - T1114.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_multi_source_failed_authentications_spike.yml b/detections/cloud/o365_multi_source_failed_authentications_spike.yml index 3c21195c01..275cba424d 100644 --- a/detections/cloud/o365_multi_source_failed_authentications_spike.yml +++ b/detections/cloud/o365_multi_source_failed_authentications_spike.yml @@ -1,7 +1,7 @@ name: O365 Multi-Source Failed Authentications Spike id: ea4e2c41-dbfb-4f5f-a7b6-9ac1b7f104aa -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -45,11 +45,9 @@ tags: asset_type: O365 Tenant atomic_guid: [] mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml b/detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml new file mode 100644 index 0000000000..743aca09e9 --- /dev/null +++ b/detections/cloud/o365_multiple_os_vendors_authenticating_from_user.yml @@ -0,0 +1,66 @@ +name: O365 Multiple OS Vendors Authenticating From User +id: 3451e58a-9457-4985-a600-b616b0cbfda1 +version: 1 +date: '2024-12-19' +author: Steven Dick +status: production +type: TTP +description: The following analytic identifies when multiple operating systems are used to authenticate to Azure/EntraID/Office 365 by the same user account over a short period of time. This activity could be indicative of attackers enumerating various logon capabilities of Azure/EntraID/Office 365 and attempting to discover weaknesses in the organizational MFA or conditional access configurations. Usage of the tools like "MFASweep" will trigger this detection. +data_source: +- Office 365 Universal Audit Log +search: |- + `o365_management_activity` Operation IN (UserLoginFailed,UserLoggedIn) + | eval -time = _time + | bin _time span=15m + | stats values(Operation) as signature, values(ErrorNumber) as signature_id, values(OS) as os_name, dc(OS) as os_count, count, min(-time) as firstTime, max(-time) as lastTime by ClientIP, UserId, _time + | where os_count >= 4 + | eval src = ClientIP, user = UserId + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `o365_multiple_os_vendors_authenticating_from_user_filter` +how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. The thresholds set within the analytic (such as unique OS) are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment. +known_false_positives: IP or users where the usage of multiple Operating systems is expected, filter accordingly. +references: +- https://attack.mitre.org/techniques/T1110 +- https://www.blackhillsinfosec.com/exploiting-mfa-inconsistencies-on-microsoft-services/ +- https://sra.io/blog/msspray-wait-how-many-endpoints-dont-have-mfa/ +- https://github.com/dafthack/MFASweep/tree/master +drilldown_searches: +- name: View the detection results for - "$user$" + search: '%original_detection_search% | search user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate logons from $user$ + search: '`o365_management_activity` Operation IN (UserLoginFailed,UserLoggedIn) "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The user account $user$ authenticated with $os_count$ unique operating system types over a short period from $src$. + risk_objects: + - field: user + type: user + score: 60 + threat_objects: + - field: src + type: ip_address +tags: + analytic_story: + - Office 365 Account Takeover + asset_type: O365 Tenant + mitre_attack_id: + - T1110 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: threat +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/azure_mfasweep_events/azure_mfasweep_events.log + source: o365 + sourcetype: o365:management:activity diff --git a/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml index 24496ddc87..70df08df04 100644 --- a/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml +++ b/detections/cloud/o365_multiple_users_failing_to_authenticate_from_ip.yml @@ -1,7 +1,7 @@ name: O365 Multiple Users Failing To Authenticate From Ip id: 8d486e2e-3235-4cfe-ac35-0d042e24ecb4 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,11 +58,9 @@ tags: - NOBELIUM Group asset_type: O365 Tenant mitre_attack_id: - - T1586 - - T1586.003 - - T1110 - T1110.003 - T1110.004 + - T1586.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_new_email_forwarding_rule_created.yml b/detections/cloud/o365_new_email_forwarding_rule_created.yml index cee90dcbdc..2ec1c2eb73 100644 --- a/detections/cloud/o365_new_email_forwarding_rule_created.yml +++ b/detections/cloud/o365_new_email_forwarding_rule_created.yml @@ -1,7 +1,7 @@ name: O365 New Email Forwarding Rule Created id: 68469fd0-1315-44ba-b7e4-e92847bb76d6 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -53,7 +53,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_new_email_forwarding_rule_enabled.yml b/detections/cloud/o365_new_email_forwarding_rule_enabled.yml index dcc6b1b909..f6ca3b2785 100644 --- a/detections/cloud/o365_new_email_forwarding_rule_enabled.yml +++ b/detections/cloud/o365_new_email_forwarding_rule_enabled.yml @@ -1,7 +1,7 @@ name: O365 New Email Forwarding Rule Enabled id: ac7c4d0a-06a3-4278-aa59-88a5e537f981 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -57,7 +57,6 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114 - T1114.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_new_federated_domain_added.yml b/detections/cloud/o365_new_federated_domain_added.yml index 6dcebc1fbe..c2cd3a3f0e 100644 --- a/detections/cloud/o365_new_federated_domain_added.yml +++ b/detections/cloud/o365_new_federated_domain_added.yml @@ -1,7 +1,7 @@ name: O365 New Federated Domain Added id: e155876a-6048-11eb-ae93-0242ac130002 -version: 6 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Rod Soto, Mauricio Velazco Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1136.003 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_new_mfa_method_registered.yml b/detections/cloud/o365_new_mfa_method_registered.yml index f5278b8e52..25bcbb5336 100644 --- a/detections/cloud/o365_new_mfa_method_registered.yml +++ b/detections/cloud/o365_new_mfa_method_registered.yml @@ -1,7 +1,7 @@ name: O365 New MFA Method Registered id: 4e12db1f-f7c7-486d-8152-a221cad6ac2b -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Office 365 Persistence Mechanisms asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.005 product: - Splunk Enterprise diff --git a/detections/cloud/o365_privileged_role_assigned.yml b/detections/cloud/o365_privileged_role_assigned.yml index 975cdaa4a0..349eb0ce48 100644 --- a/detections/cloud/o365_privileged_role_assigned.yml +++ b/detections/cloud/o365_privileged_role_assigned.yml @@ -1,7 +1,7 @@ name: O365 Privileged Role Assigned id: db435700-4ddc-4c23-892e-49e7525d7d39 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -62,7 +62,6 @@ tags: - Azure Active Directory Persistence asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml b/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml index f984d8f1de..cc56ca9835 100644 --- a/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml +++ b/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml @@ -1,7 +1,7 @@ name: O365 Privileged Role Assigned To Service Principal id: 80f3fc1b-705f-4080-bf08-f61bf013b900 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -66,7 +66,6 @@ tags: - Azure Active Directory Privilege Escalation asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_safe_links_detection.yml b/detections/cloud/o365_safe_links_detection.yml index 1c85c2120c..48f5edc84e 100644 --- a/detections/cloud/o365_safe_links_detection.yml +++ b/detections/cloud/o365_safe_links_detection.yml @@ -1,7 +1,7 @@ name: O365 Safe Links Detection id: 711d9e8c-2cb0-45cf-8813-5f191ecb9b26 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -52,7 +52,6 @@ tags: - Spearphishing Attachments asset_type: O365 Tenant mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/cloud/o365_security_and_compliance_alert_triggered.yml b/detections/cloud/o365_security_and_compliance_alert_triggered.yml index f7a2340203..b479777630 100644 --- a/detections/cloud/o365_security_and_compliance_alert_triggered.yml +++ b/detections/cloud/o365_security_and_compliance_alert_triggered.yml @@ -1,7 +1,7 @@ name: O365 Security And Compliance Alert Triggered id: 5b367cdd-8dfc-49ac-a9b7-6406cf27f33e -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: [] type: TTP @@ -58,7 +58,6 @@ tags: - Office 365 Account Takeover asset_type: O365 Tenant mitre_attack_id: - - T1078 - T1078.004 product: - Splunk Enterprise diff --git a/detections/cloud/o365_service_principal_new_client_credentials.yml b/detections/cloud/o365_service_principal_new_client_credentials.yml index 702f8ee8f9..fbb1bcb8bd 100644 --- a/detections/cloud/o365_service_principal_new_client_credentials.yml +++ b/detections/cloud/o365_service_principal_new_client_credentials.yml @@ -1,7 +1,7 @@ name: O365 Service Principal New Client Credentials id: a1b229e9-d962-4222-8c62-905a8a010453 -version: 5 -date: '2024-11-14' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - NOBELIUM Group asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.001 product: - Splunk Enterprise diff --git a/detections/cloud/o365_service_principal_privilege_escalation.yml b/detections/cloud/o365_service_principal_privilege_escalation.yml index ee93c75401..899a257bb4 100644 --- a/detections/cloud/o365_service_principal_privilege_escalation.yml +++ b/detections/cloud/o365_service_principal_privilege_escalation.yml @@ -1,23 +1,32 @@ name: O365 Service Principal Privilege Escalation id: b686d0bd-cca7-44ca-ae07-87f6465131d9 -version: 1 -date: '2025-01-06' +version: 2 +date: '2025-02-10' author: Dean Luxton data_source: - O365 Add app role assignment grant to user type: TTP status: production -description: This detection identifies when an Azure Service Principal elevates privileges by adding themself to a new app role assignment. -search: >- - `o365_management_activity` Operation="Add app role assignment to service principal." "Actor{}.ID"=ServicePrincipal ResultStatus=Success +description: This detection identifies when an Azure Service Principal elevates privileges + by adding themself to a new app role assignment. +search: >- + `o365_management_activity` Operation="Add app role assignment to service principal." + "Actor{}.ID"=ServicePrincipal ResultStatus=Success | spath path=ModifiedProperties{} output=targetResources - | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) as targetServicePrincipal values(object) as targetAppContext values(user_agent) as user_agent values(user) as servicePrincipal values(UserId) as servicePrincipalId by Operation InterSystemsId tenant_id + | stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) + as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) + as targetServicePrincipal values(object) as targetAppContext values(user_agent) + as user_agent values(user) as servicePrincipal values(UserId) as servicePrincipalId by + Operation InterSystemsId tenant_id | spath input=appRole path=NewValue output=appRole | spath input=targetServicePrincipal path=NewValue output=targetServicePrincipal | where servicePrincipal=targetServicePrincipal - | table _time Operation servicePrincipal servicePrincipalId appRole targetAppContext user_agent tenant_id InterSystemsId + | table _time Operation servicePrincipal servicePrincipalId appRole targetAppContext + user_agent tenant_id InterSystemsId | `o365_service_principal_privilege_escalation_filter` -how_to_implement: The Splunk Add-on for Microsoft Office 365 add-on is required to ingest EntraID audit logs via the 365 API. See references for links for further details on how to onboard this log source. +how_to_implement: The Splunk Add-on for Microsoft Office 365 add-on is required to + ingest EntraID audit logs via the 365 API. See references for links for further + details on how to onboard this log source. known_false_positives: Unknown references: - https://splunkbase.splunk.com/app/4055 @@ -30,11 +39,17 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$servicePrincipal$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: Service Principal $servicePrincipal$ has elevated privileges by adding themself to app role $appRole$ + message: Service Principal $servicePrincipal$ has elevated privileges by adding + themself to app role $appRole$ risk_objects: - field: servicePrincipal type: user @@ -49,7 +64,6 @@ tags: asset_type: Azure Tenant mitre_attack_id: - T1098.003 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security @@ -58,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/o365_spn_privesc/o365_spn_privesc.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/o365_spn_privesc/o365_spn_privesc.log sourcetype: o365:management:activity source: Office 365 diff --git a/detections/cloud/o365_sharepoint_malware_detection.yml b/detections/cloud/o365_sharepoint_malware_detection.yml index a3136a5595..e3ec3d7abc 100644 --- a/detections/cloud/o365_sharepoint_malware_detection.yml +++ b/detections/cloud/o365_sharepoint_malware_detection.yml @@ -1,7 +1,7 @@ name: O365 SharePoint Malware Detection id: 583c5de3-7709-44cb-abfc-0e828d301b59 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -53,7 +53,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1204.002 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml new file mode 100644 index 0000000000..52449ed52b --- /dev/null +++ b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml @@ -0,0 +1,67 @@ +name: O365 SharePoint Suspicious Search Behavior +id: 6ca919db-52f3-4c95-a4e9-7b189e8a043d +version: 1 +date: '2025-01-08' +author: Steven Dick +status: production +type: Anomaly +description: The following analytic identifies when the O365 SharePoint users search for suspicious keywords or have an excessive number of queries within a limited timeframe. This behavior may indicate malicious actor enumeration of SharePoint based data within O365. +data_source: +- Office 365 Universal Audit Log +search: |- + `o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* + | where NOT (match(SearchQueryText, "\*") OR match(SearchQueryText,"(\*)")) + | eval signature_id = CorrelationId, signature=Operation, src = ClientIP, user = UserId, object_name=EventData, command = SearchQueryText, -time = _time + | bin _time span=1hr + | stats values(object_name) as object_name values(command) as command, values(src) as src, dc(command) as count, min(-time) as firstTime, max(-time) as lastTime by user,signature,_time + | where count > 20 OR match(command, "(?i)password|credential|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing") + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `o365_sharepoint_suspicious_search_behavior_filter` +how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. The thresholds and match terms set within the analytic are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment. +known_false_positives: Users searching excessively or possible false positives related to matching conditions. +references: +- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a +- https://attack.mitre.org/techniques/T1213/002/ +drilldown_searches: +- name: View the detection results for - "$user$" + search: '%original_detection_search% | search user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate search behavior by $user$ + search: '`o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* AND UserId = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The SharePoint Online was searched suspiciously by $user$ + risk_objects: + - field: user + type: user + score: 25 + threat_objects: + - field: src + type: ip_address +tags: + analytic_story: + - Azure Active Directory Persistence + - Office 365 Account Takeover + - CISA AA22-320A + asset_type: O365 Tenant + mitre_attack_id: + - T1213.002 + - T1552 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: threat +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213.002/o365_sus_sharepoint_search/o365_sus_sharepoint_search.log + source: o365 + sourcetype: o365:management:activity diff --git a/detections/cloud/o365_tenant_wide_admin_consent_granted.yml b/detections/cloud/o365_tenant_wide_admin_consent_granted.yml index 5375087924..9d9a2e8780 100644 --- a/detections/cloud/o365_tenant_wide_admin_consent_granted.yml +++ b/detections/cloud/o365_tenant_wide_admin_consent_granted.yml @@ -1,7 +1,7 @@ name: O365 Tenant Wide Admin Consent Granted id: 50eaabf8-5180-4e86-bfb2-011472c359fc -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - NOBELIUM Group asset_type: O365 Tenant mitre_attack_id: - - T1098 - T1098.003 product: - Splunk Enterprise diff --git a/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml b/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml index b2142169f6..80ffe96469 100644 --- a/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml +++ b/detections/cloud/o365_threat_intelligence_suspicious_email_delivered.yml @@ -1,7 +1,7 @@ name: O365 Threat Intelligence Suspicious Email Delivered id: 605cc93a-70e4-4ee3-9a3d-1a62e8c9b6c2 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -63,7 +63,6 @@ tags: - Suspicious Emails asset_type: O365 Tenant mitre_attack_id: - - T1566 - T1566.001 - T1566.002 product: diff --git a/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml b/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml index d7fcb9eb0a..f6313dcc2c 100644 --- a/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml +++ b/detections/cloud/o365_threat_intelligence_suspicious_file_detected.yml @@ -1,7 +1,7 @@ name: O365 Threat Intelligence Suspicious File Detected id: 00958c7b-35db-4e7a-ad13-31550a7a7c64 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1204.002 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/o365_zap_activity_detection.yml b/detections/cloud/o365_zap_activity_detection.yml index b16c86afb1..daab34fb89 100644 --- a/detections/cloud/o365_zap_activity_detection.yml +++ b/detections/cloud/o365_zap_activity_detection.yml @@ -1,7 +1,7 @@ name: O365 ZAP Activity Detection id: 4df275fd-a0e5-4246-8b92-d3201edaef7a -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -58,7 +58,6 @@ tags: - Suspicious Emails asset_type: O365 Tenant mitre_attack_id: - - T1566 - T1566.001 - T1566.002 product: diff --git a/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml b/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml index f1555d3ff6..145748eea0 100644 --- a/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml +++ b/detections/cloud/risk_rule_for_dev_sec_ops_by_repository.yml @@ -1,7 +1,7 @@ name: Risk Rule for Dev Sec Ops by Repository id: 161bc0ca-4651-4c13-9c27-27770660cf67 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Bhavin Patel status: production type: Correlation @@ -47,7 +47,6 @@ tags: asset_type: Amazon Elastic Container Registry mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/account_discovery_with_net_app.yml b/detections/deprecated/account_discovery_with_net_app.yml index bf2568a3f0..074b4fba7a 100644 --- a/detections/deprecated/account_discovery_with_net_app.yml +++ b/detections/deprecated/account_discovery_with_net_app.yml @@ -1,7 +1,7 @@ name: Account Discovery With Net App id: 339805ce-ac30-11eb-b87d-acde48001122 -version: 8 -date: '2025-01-13' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community status: deprecated type: TTP @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/attempt_to_stop_security_service.yml b/detections/deprecated/attempt_to_stop_security_service.yml index 09f69ad572..1964d9b110 100644 --- a/detections/deprecated/attempt_to_stop_security_service.yml +++ b/detections/deprecated/attempt_to_stop_security_service.yml @@ -1,7 +1,7 @@ name: Attempt To Stop Security Service id: c8e349c6-b97c-486e-8949-bd7bcd1f3910 -version: 9 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Rico Valdez, Splunk status: deprecated type: TTP @@ -80,7 +80,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml index 38fdbf95b5..65c188a991 100644 --- a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -1,7 +1,7 @@ name: Attempted Credential Dump From Registry via Reg exe id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911 -version: 12 -date: '2025-01-15' +version: 14 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: TTP @@ -80,7 +80,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml index d59e586b5a..91a576d2f0 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml @@ -15,8 +15,8 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI sourceIPAddress | search City=* | stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup append=t previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, - City, Region, Country | outputlookup previously_seen_provisioning_activity_src | - stats min(firstTime) as firstTime max(lastTime) as lastTime by City | eval newCity=if(firstTime + City, Region, Country | outputlookup previously_seen_provisioning_activity_src + | stats min(firstTime) as firstTime max(lastTime) as lastTime by City | eval newCity=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) | where newCity=1 | table City] | spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, City, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_city_filter`' diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml index 05ecc67be0..986a31d1f0 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml @@ -14,13 +14,13 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI | search Country=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceIPAddress | search Country=* | stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup - append=t previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime - max(lastTime) as lastTime by sourceIPAddress, City, Region, Country | outputlookup - previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime max(lastTime) - as lastTime by Country | eval newCountry=if(firstTime >= relative_time(now(), "-70m@m"), - 1, 0) | where newCountry=1 | table Country] | spath output=user userIdentity.arn - | rename sourceIPAddress as src_ip | table _time, user, src_ip, Country, eventName, - errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter`' + append=t previously_seen_provisioning_activity_src | stats min(firstTime) as + firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country | + outputlookup previously_seen_provisioning_activity_src | stats min(firstTime) + as firstTime max(lastTime) as lastTime by Country | eval newCountry=if(firstTime + >= relative_time(now(), "-70m@m"), 1, 0) | where newCountry=1 | table Country] | + spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, + user, src_ip, Country, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter`' how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail inputs. This search works best when you run the "Previously Seen AWS Provisioning diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml index 7adba589db..5efa68a449 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml @@ -15,8 +15,8 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI sourceIPAddress | search Region=* | stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup append=t previously_seen_provisioning_activity_src | stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, - City, Region, Country | outputlookup previously_seen_provisioning_activity_src | - stats min(firstTime) as firstTime max(lastTime) as lastTime by Region | eval newRegion=if(firstTime + City, Region, Country | outputlookup previously_seen_provisioning_activity_src + | stats min(firstTime) as firstTime max(lastTime) as lastTime by Region | eval newRegion=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) | where newRegion=1 | table Region] | spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, Region, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_region_filter`' diff --git a/detections/deprecated/change_default_file_association.yml b/detections/deprecated/change_default_file_association.yml index b524230015..e5e583848a 100644 --- a/detections/deprecated/change_default_file_association.yml +++ b/detections/deprecated/change_default_file_association.yml @@ -1,7 +1,7 @@ name: Change Default File Association id: 462d17d8-1f71-11ec-ad07-acde48001122 -version: 5 -date: '2025-01-24' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.001 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml index 1df440f488..74087020ed 100644 --- a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml @@ -1,7 +1,7 @@ name: Cmdline Tool Not Executed In CMD Shell id: 6c3f7dd8-153c-11ec-ac2d-acde48001122 -version: 7 -date: '2025-01-24' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -86,7 +86,6 @@ tags: - Gozi Malware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.007 product: - Splunk Enterprise diff --git a/detections/deprecated/correlation_by_repository_and_risk.yml b/detections/deprecated/correlation_by_repository_and_risk.yml index 2629b408ff..681f046bf4 100644 --- a/detections/deprecated/correlation_by_repository_and_risk.yml +++ b/detections/deprecated/correlation_by_repository_and_risk.yml @@ -1,7 +1,7 @@ name: Correlation by Repository and Risk id: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: Correlation @@ -20,7 +20,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/correlation_by_user_and_risk.yml b/detections/deprecated/correlation_by_user_and_risk.yml index 63d9c738ae..d121453be9 100644 --- a/detections/deprecated/correlation_by_user_and_risk.yml +++ b/detections/deprecated/correlation_by_user_and_risk.yml @@ -1,7 +1,7 @@ name: Correlation by User and Risk id: 610e12dc-b6fa-4541-825e-4a0b3b6f6773 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: Correlation @@ -20,7 +20,6 @@ tags: asset_type: AWS Account mitre_attack_id: - T1204.003 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml index cf89f5b1ac..05bd612ba3 100644 --- a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml +++ b/detections/deprecated/create_local_admin_accounts_using_net_exe.yml @@ -1,7 +1,7 @@ name: Create local admin accounts using net exe id: b89919ed-fe5f-492c-b139-151bb162040e -version: 15 -date: '2025-01-24' +version: 17 +date: '2025-02-10' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -78,7 +78,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/deleting_of_net_users.yml b/detections/deprecated/deleting_of_net_users.yml index cb8dc58817..379264584f 100644 --- a/detections/deprecated/deleting_of_net_users.yml +++ b/detections/deprecated/deleting_of_net_users.yml @@ -1,18 +1,18 @@ name: Deleting Of Net Users id: 1c8c6f66-acce-11eb-aafb-acde48001122 -version: 7 +version: 8 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic detects - the use of net.exe or net1.exe command-line to delete a user account on a system. - It leverages data from Endpoint Detection and Response (EDR) agents, focusing on - process and command-line execution logs. This activity is significant as it may - indicate an attempt to impair user accounts or cover tracks during lateral movement. - If confirmed malicious, this could lead to unauthorized access removal, disruption - of legitimate user activities, or concealment of adversarial actions, complicating - incident response and forensic investigations. +description: The following analytic has been deprecated. + The following analytic detects the use of net.exe or net1.exe command-line + to delete a user account on a system. It leverages data from Endpoint Detection + and Response (EDR) agents, focusing on process and command-line execution logs. + This activity is significant as it may indicate an attempt to impair user accounts + or cover tracks during lateral movement. If confirmed malicious, this could lead + to unauthorized access removal, disruption of legitimate user activities, or concealment + of adversarial actions, complicating incident response and forensic investigations. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml index 0c13a55b87..9b6c9aec2c 100644 --- a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml @@ -1,7 +1,7 @@ name: Detect Activity Related to Pass the Hash Attacks id: f5939373-8054-40ad-8c64-cec478a22a4b -version: 9 -date: '2024-11-14' +version: 10 +date: '2025-02-10' author: Bhavin Patel, Patrick Bareiss, Splunk status: deprecated type: Hunting @@ -29,7 +29,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1550 - T1550.002 product: - Splunk Enterprise diff --git a/detections/deprecated/detect_critical_alerts_from_security_tools.yml b/detections/deprecated/detect_critical_alerts_from_security_tools.yml index 75848f931f..79ba56809d 100644 --- a/detections/deprecated/detect_critical_alerts_from_security_tools.yml +++ b/detections/deprecated/detect_critical_alerts_from_security_tools.yml @@ -8,40 +8,10 @@ type: TTP data_source: - Windows Defender Alerts - MS365 Defender Incident Alerts -description: The following analytic has been deprecated in favour of specific and - dedicated product analytics such as "Microsoft Defender ATP Alerts". The following - analytic is to detect high and critical alerts from endpoint security tools such - as Microsoft Defender, Carbon Black, and Crowdstrike. This query aggregates and - summarizes critical severity alerts from the Alerts data model, providing details - such as the alert signature, application, description, source, destination, and - timestamps, while applying custom filters and formatting for enhanced analysis in - a SIEM environment.This capability allows security teams to efficiently allocate - resources and maintain a strong security posture, while also supporting compliance - with regulatory requirements by providing a clear record of critical security events. - We tested these detections with logs from Microsoft Defender, however this detection - should work for any security alerts that are ingested into the alerts data model. - **Note** - We are dynamically creating the risk_score field based on the severity - of the alert in the SPL and that supersedes the risk score set in the detection. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime values(Alerts.description) as description values(Alerts.mitre_technique_id) - as annotations.mitre_attack.mitre_technique_id values(Alerts.severity) as severity - values(Alerts.type) as type values(Alerts.severity_id) as severity_id values(Alerts.signature) - as signature values(Alerts.signature_id) as signature_id values(Alerts.dest) as - dest from datamodel=Alerts where Alerts.severity IN ("high","critical") by Alerts.src - Alerts.user Alerts.id Alerts.vendor sourcetype | `drop_dm_object_name("Alerts")` - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | eval - risk_score=case(severity="informational", 2, severity="low", 5, severity="medium", - 10, severity="high", 50, severity="critical" , 100) | `detect_critical_alerts_from_security_tools_filter`' -how_to_implement: In order to properly run this search, you to ingest alerts data - from other security products such as Crowdstrike, Microsoft Defender, or Carbon - Black using appropriate TAs for that technology. Once ingested, the fields should - be mapped to the Alerts data model. Make sure to apply transformation on the data - if necessary. The risk_score field is used to calculate the risk score for the alerts - and the mitre_technique_id field is used to map the alerts to the MITRE ATT&CK framework - is dynamically created by the detection when this is triggered. These fields need - not be set in the adaptive response actions. -known_false_positives: False positives may vary by endpoint protection tool; monitor - and filter out the alerts that are not relevant to your environment. +description: The following analytic has been deprecated in favour of specific and dedicated product analytics such as "Microsoft Defender ATP Alerts". The following analytic is to detect high and critical alerts from endpoint security tools such as Microsoft Defender, Carbon Black, and Crowdstrike. This query aggregates and summarizes critical severity alerts from the Alerts data model, providing details such as the alert signature, application, description, source, destination, and timestamps, while applying custom filters and formatting for enhanced analysis in a SIEM environment.This capability allows security teams to efficiently allocate resources and maintain a strong security posture, while also supporting compliance with regulatory requirements by providing a clear record of critical security events. We tested these detections with logs from Microsoft Defender, however this detection should work for any security alerts that are ingested into the alerts data model. **Note** - We are dynamically creating the risk_score field based on the severity of the alert in the SPL and that supersedes the risk score set in the detection. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Alerts.description) as description values(Alerts.mitre_technique_id) as annotations.mitre_attack.mitre_technique_id values(Alerts.severity) as severity values(Alerts.type) as type values(Alerts.severity_id) as severity_id values(Alerts.signature) as signature values(Alerts.signature_id) as signature_id values(Alerts.dest) as dest from datamodel=Alerts where Alerts.severity IN ("high","critical") by Alerts.src Alerts.user Alerts.id Alerts.vendor sourcetype | `drop_dm_object_name("Alerts")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | eval risk_score=case(severity="informational", 2, severity="low", 5, severity="medium", 10, severity="high", 50, severity="critical" , 100) | `detect_critical_alerts_from_security_tools_filter`' +how_to_implement: In order to properly run this search, you to ingest alerts data from other security products such as Crowdstrike, Microsoft Defender, or Carbon Black using appropriate TAs for that technology. Once ingested, the fields should be mapped to the Alerts data model. Make sure to apply transformation on the data if necessary. The risk_score field is used to calculate the risk score for the alerts and the mitre_technique_id field is used to map the alerts to the MITRE ATT&CK framework is dynamically created by the detection when this is triggered. These fields need not be set in the adaptive response actions. +known_false_positives: False positives may vary by endpoint protection tool; monitor and filter out the alerts that are not relevant to your environment. references: - https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/accessing-microsoft-defender-for-cloud-alerts-in-splunk-using/ba-p/938228 - https://docs.splunk.com/Documentation/CIM/5.3.2/User/Alerts diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml index 67c72e7e14..2d4975f3ec 100644 --- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml +++ b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml @@ -31,9 +31,9 @@ how_to_implement: "You need to ingest data from your DNS logs in the Network_Res add the correct hostname to the \"Phantom Instance\" field in the Adaptive Response Actions when configuring this detection search, and set the corresponding Playbook to active.\n(Playbook link:`https://my.phantom.us/4.2/playbook/lets-encrypt-domain-investigate/`)" -known_false_positives: If a known good domain is not listed in the `legit_domains` - lookup, then the search could give you false postives. Please update that lookup - file to filter out DNS requests to legitimate domains. +known_false_positives: If a known good domain is not listed in the `legit_domains` lookup, + then the search could give you false postives. Please update that lookup file + to filter out DNS requests to legitimate domains. references: [] rba: message: DNS Request for EvilGinx2 Phishing Site diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/detections/deprecated/detect_mimikatz_using_loaded_images.yml index b002ff2bcc..75e66c0061 100644 --- a/detections/deprecated/detect_mimikatz_using_loaded_images.yml +++ b/detections/deprecated/detect_mimikatz_using_loaded_images.yml @@ -1,7 +1,7 @@ name: Detect Mimikatz Using Loaded Images id: 29e307ba-40af-4ab2-91b2-3c6b392bbba0 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: TTP @@ -49,7 +49,6 @@ tags: asset_type: Windows mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/detections/deprecated/detect_new_api_calls_from_user_roles.yml index cc41aecff1..5ed0943c52 100644 --- a/detections/deprecated/detect_new_api_calls_from_user_roles.yml +++ b/detections/deprecated/detect_new_api_calls_from_user_roles.yml @@ -12,9 +12,9 @@ search: '`cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=A [search `cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole | stats earliest(_time) as earliest latest(_time) as latest by userName eventName | inputlookup append=t previously_seen_api_calls_from_user_roles | stats min(earliest) - as earliest, max(latest) as latest by userName eventName | outputlookup previously_seen_api_calls_from_user_roles - | eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0) - | where newApiCallfromUserRole=1 | `security_content_ctime(earliest)` | `security_content_ctime(latest)` + as earliest, max(latest) as latest by userName eventName | outputlookup previously_seen_api_calls_from_user_roles | + eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0) | + where newApiCallfromUserRole=1 | `security_content_ctime(earliest)` | `security_content_ctime(latest)` | table eventName userName] |rename userName as user| stats values(eventName) earliest(_time) as earliest latest(_time) as latest by user | `security_content_ctime(earliest)` | `security_content_ctime(latest)` | `detect_new_api_calls_from_user_roles_filter`' diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/detections/deprecated/detect_new_user_aws_console_login.yml index 68c62a8d9c..1713d3b52d 100644 --- a/detections/deprecated/detect_new_user_aws_console_login.yml +++ b/detections/deprecated/detect_new_user_aws_console_login.yml @@ -13,9 +13,9 @@ description: This search looks for AWS CloudTrail events wherein a console login data_source: [] search: '`cloudtrail` eventName=ConsoleLogin | rename userIdentity.arn as user | stats earliest(_time) as firstTime latest(_time) as lastTime by user | inputlookup append=t - previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime) - as lastTime by user | eval userStatus=if(firstTime >= relative_time(now(), "-70m@m"), - "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`| + previously_seen_users_console_logins | stats min(firstTime) as firstTime + max(lastTime) as lastTime by user | eval userStatus=if(firstTime >= relative_time(now(), + "-70m@m"), "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`| where userStatus ="First Time Logging into AWS Console" | `detect_new_user_aws_console_login_filter`' how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail diff --git a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml index 05f6ff2bd6..d0851935d2 100644 --- a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml +++ b/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml @@ -1,19 +1,20 @@ name: Detect processes used for System Network Configuration Discovery id: a51bfe1a-94f0-48cc-b1e4-16ae10145893 -version: 7 +version: 8 date: '2025-01-24' author: Bhavin Patel, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic identifies - the rapid execution of processes used for system network configuration discovery - on an endpoint. It leverages data from Endpoint Detection and Response (EDR) agents, - focusing on process GUIDs, names, parent processes, and command-line executions. - This activity is significant as it may indicate an attacker attempting to map the - network, which is a common precursor to lateral movement or further exploitation. - If confirmed malicious, this behavior could allow an attacker to gain insights into - the network topology, identify critical systems, and plan subsequent attacks, potentially - leading to data exfiltration or system compromise. +description: The following analytic has been deprecated. + The following analytic identifies the rapid execution of processes used + for system network configuration discovery on an endpoint. It leverages data from + Endpoint Detection and Response (EDR) agents, focusing on process GUIDs, names, + parent processes, and command-line executions. This activity is significant as it + may indicate an attacker attempting to map the network, which is a common precursor + to lateral movement or further exploitation. If confirmed malicious, this behavior + could allow an attacker to gain insights into the network topology, identify critical + systems, and plan subsequent attacks, potentially leading to data exfiltration or + system compromise. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/detect_webshell_exploit_behavior.yml b/detections/deprecated/detect_webshell_exploit_behavior.yml index 5f61b3c0c8..a460946a1a 100644 --- a/detections/deprecated/detect_webshell_exploit_behavior.yml +++ b/detections/deprecated/detect_webshell_exploit_behavior.yml @@ -1,7 +1,7 @@ name: Detect Webshell Exploit Behavior id: 22597426-6dbd-49bd-bcdc-4ec19857192f -version: 7 -date: '2025-01-24' +version: 8 +date: '2025-02-10' author: Steven Dick status: deprecated type: TTP @@ -87,7 +87,6 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.003 product: - Splunk Enterprise diff --git a/detections/deprecated/disabling_net_user_account.yml b/detections/deprecated/disabling_net_user_account.yml index 615c9dea0b..409e89854a 100644 --- a/detections/deprecated/disabling_net_user_account.yml +++ b/detections/deprecated/disabling_net_user_account.yml @@ -1,18 +1,18 @@ name: Disabling Net User Account id: c0325326-acd6-11eb-98c2-acde48001122 -version: 7 +version: 8 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic detects - the use of the `net.exe` utility to disable a user account via the command line. - It leverages data from Endpoint Detection and Response (EDR) agents, focusing on - process execution logs and command-line arguments. This activity is significant - as it may indicate an adversary's attempt to disrupt user availability, potentially - as a precursor to further malicious actions. If confirmed malicious, this could - lead to denial of service for legitimate users, aiding the attacker in maintaining - control or covering their tracks. +description: The following analytic has been deprecated. + The following analytic detects the use of the `net.exe` utility to disable + a user account via the command line. It leverages data from Endpoint Detection and + Response (EDR) agents, focusing on process execution logs and command-line arguments. + This activity is significant as it may indicate an adversary's attempt to disrupt + user availability, potentially as a precursor to further malicious actions. If confirmed + malicious, this could lead to denial of service for legitimate users, aiding the + attacker in maintaining control or covering their tracks. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/domain_account_discovery_with_net_app.yml b/detections/deprecated/domain_account_discovery_with_net_app.yml index 92ad5bcfa8..a1518a4c1f 100644 --- a/detections/deprecated/domain_account_discovery_with_net_app.yml +++ b/detections/deprecated/domain_account_discovery_with_net_app.yml @@ -1,7 +1,7 @@ name: Domain Account Discovery With Net App id: 98f6a534-04c2-11ec-96b2-acde48001122 -version: 5 -date: '2025-01-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: deprecated type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/domain_group_discovery_with_net.yml b/detections/deprecated/domain_group_discovery_with_net.yml index b01c32e127..928dec10e8 100644 --- a/detections/deprecated/domain_group_discovery_with_net.yml +++ b/detections/deprecated/domain_group_discovery_with_net.yml @@ -1,7 +1,7 @@ name: Domain Group Discovery With Net id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349 -version: 6 -date: '2025-01-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: deprecated type: Hunting @@ -46,7 +46,6 @@ tags: - Cleo File Transfer Software asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/deprecated/elevated_group_discovery_with_net.yml b/detections/deprecated/elevated_group_discovery_with_net.yml index 45c777516b..a941649159 100644 --- a/detections/deprecated/elevated_group_discovery_with_net.yml +++ b/detections/deprecated/elevated_group_discovery_with_net.yml @@ -1,7 +1,7 @@ name: Elevated Group Discovery With Net id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a -version: 6 -date: '2025-01-24' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: deprecated type: TTP @@ -70,7 +70,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/deprecated/excel_spawning_powershell.yml b/detections/deprecated/excel_spawning_powershell.yml index 28ca3fa40a..764de86234 100644 --- a/detections/deprecated/excel_spawning_powershell.yml +++ b/detections/deprecated/excel_spawning_powershell.yml @@ -1,7 +1,7 @@ name: Excel Spawning PowerShell id: 42d40a22-9be3-11eb-8f08-acde48001122 -version: 7 -date: '2025-01-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -75,7 +75,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/excel_spawning_windows_script_host.yml b/detections/deprecated/excel_spawning_windows_script_host.yml index 70da2b9f10..40deb89c49 100644 --- a/detections/deprecated/excel_spawning_windows_script_host.yml +++ b/detections/deprecated/excel_spawning_windows_script_host.yml @@ -1,12 +1,12 @@ name: Excel Spawning Windows Script Host id: 57fe880a-9be3-11eb-9bf3-acde48001122 -version: 8 -date: '2025-01-13' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated in favour of a more generic approach. - The following analytic identifies instances where Microsoft Excel spawns +description: The following analytic has been deprecated in favour of a more generic + approach. The following analytic identifies instances where Microsoft Excel spawns Windows Script Host processes (`cscript.exe` or `wscript.exe`). This behavior is detected using Endpoint Detection and Response (EDR) telemetry, focusing on process creation events where the parent process is `excel.exe`. This activity is significant @@ -75,7 +75,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -84,6 +83,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/deprecated/excessive_service_stop_attempt.yml b/detections/deprecated/excessive_service_stop_attempt.yml index 9c51626bde..3e27dc456b 100644 --- a/detections/deprecated/excessive_service_stop_attempt.yml +++ b/detections/deprecated/excessive_service_stop_attempt.yml @@ -5,14 +5,15 @@ date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: Anomaly -description: The following analytic has been deprecated. The following analytic detects - multiple attempts to stop or delete services on a system using `net.exe`, `sc.exe`, - or `net1.exe`. It leverages Endpoint Detection and Response (EDR) telemetry, focusing - on process names and command-line executions within a one-minute window. This activity - is significant as it may indicate an adversary attempting to disable security or - critical services to evade detection and further their objectives. If confirmed - malicious, this could lead to the attacker gaining persistence, escalating privileges, - or disrupting essential services, thereby compromising the system's security posture. +description: The following analytic has been deprecated. + The following analytic detects multiple attempts to stop or delete services + on a system using `net.exe`, `sc.exe`, or `net1.exe`. It leverages Endpoint Detection + and Response (EDR) telemetry, focusing on process names and command-line executions + within a one-minute window. This activity is significant as it may indicate an adversary + attempting to disable security or critical services to evade detection and further + their objectives. If confirmed malicious, this could lead to the attacker gaining + persistence, escalating privileges, or disrupting essential services, thereby compromising + the system's security posture. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/excessive_usage_of_net_app.yml b/detections/deprecated/excessive_usage_of_net_app.yml index 050c4047c9..1b3556f57b 100644 --- a/detections/deprecated/excessive_usage_of_net_app.yml +++ b/detections/deprecated/excessive_usage_of_net_app.yml @@ -1,18 +1,19 @@ name: Excessive Usage Of Net App id: 45e52536-ae42-11eb-b5c6-acde48001122 -version: 6 +version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: Anomaly -description: The following analytic has been deprecated. The following analytic detects - excessive usage of `net.exe` or `net1.exe` within a one-minute interval. It leverages - data from Endpoint Detection and Response (EDR) agents, focusing on process names, - parent processes, and command-line executions. This behavior is significant as it - may indicate an adversary attempting to create, delete, or disable multiple user - accounts rapidly, a tactic observed in Monero mining incidents. If confirmed malicious, - this activity could lead to unauthorized user account manipulation, potentially - compromising system integrity and enabling further malicious actions. +description: The following analytic has been deprecated. + The following analytic detects excessive usage of `net.exe` or `net1.exe` + within a one-minute interval. It leverages data from Endpoint Detection and Response + (EDR) agents, focusing on process names, parent processes, and command-line executions. + This behavior is significant as it may indicate an adversary attempting to create, + delete, or disable multiple user accounts rapidly, a tactic observed in Monero mining + incidents. If confirmed malicious, this activity could lead to unauthorized user + account manipulation, potentially compromising system integrity and enabling further + malicious actions. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/extraction_of_registry_hives.yml b/detections/deprecated/extraction_of_registry_hives.yml index 7e1ddbc2bc..ceb5264fa6 100644 --- a/detections/deprecated/extraction_of_registry_hives.yml +++ b/detections/deprecated/extraction_of_registry_hives.yml @@ -1,7 +1,7 @@ name: Extraction of Registry Hives id: 8bbb7d58-b360-11eb-ba21-acde48001122 -version: 6 -date: '2025-01-24' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -77,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/known_services_killed_by_ransomware.yml b/detections/deprecated/known_services_killed_by_ransomware.yml similarity index 93% rename from detections/endpoint/known_services_killed_by_ransomware.yml rename to detections/deprecated/known_services_killed_by_ransomware.yml index 38760a26ef..5ca93f96d4 100644 --- a/detections/endpoint/known_services_killed_by_ransomware.yml +++ b/detections/deprecated/known_services_killed_by_ransomware.yml @@ -1,11 +1,11 @@ name: Known Services Killed by Ransomware id: 3070f8e0-c528-11eb-b2a0-acde48001122 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-07' author: Teoderick Contreras, Splunk -status: production +status: deprecated type: TTP -description: The following analytic detects the suspicious termination of known services +description: This analytic has been deprecated in favor of a new analytic - Windows Security And Backup Services Stop. The following analytic detects the suspicious termination of known services commonly targeted by ransomware before file encryption. It leverages Windows System Event Logs (EventCode 7036) to identify when critical services such as Volume Shadow Copy, backup, and antivirus services are stopped. This activity is significant because @@ -75,4 +75,4 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/known_services_killed_by_ransomware/windows-xml.log source: XmlWinEventLog:System - sourcetype: XmlWinEventLog + sourcetype: XmlWinEventLog \ No newline at end of file diff --git a/detections/deprecated/linux_auditd_find_private_keys.yml b/detections/deprecated/linux_auditd_find_private_keys.yml index 756073da56..d45b98a890 100644 --- a/detections/deprecated/linux_auditd_find_private_keys.yml +++ b/detections/deprecated/linux_auditd_find_private_keys.yml @@ -1,7 +1,7 @@ name: Linux Auditd Find Private Keys id: 80bb9988-190b-4ee0-a3c3-509545a8f678 -version: 5 -date: '2025-01-24' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/local_account_discovery_with_net.yml b/detections/deprecated/local_account_discovery_with_net.yml index 8af80acf03..69f3af6598 100644 --- a/detections/deprecated/local_account_discovery_with_net.yml +++ b/detections/deprecated/local_account_discovery_with_net.yml @@ -1,7 +1,7 @@ name: Local Account Discovery with Net id: 5d0d4830-0133-11ec-bae3-acde48001122 -version: 6 -date: '2025-01-24' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: deprecated type: Hunting @@ -41,7 +41,6 @@ tags: - Sandworm Tools asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/deprecated/mshtml_module_load_in_office_product.yml b/detections/deprecated/mshtml_module_load_in_office_product.yml index 870c4aea9d..833a24a872 100644 --- a/detections/deprecated/mshtml_module_load_in_office_product.yml +++ b/detections/deprecated/mshtml_module_load_in_office_product.yml @@ -1,7 +1,7 @@ name: MSHTML Module Load in Office Product id: 5f1c168e-118b-11ec-84ff-acde48001122 -version: 7 -date: '2025-01-24' +version: 8 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: deprecated type: TTP @@ -64,7 +64,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml index 68269b2e43..1ebadf8ebc 100644 --- a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml +++ b/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml @@ -1,7 +1,7 @@ name: Multiple Okta Users With Invalid Credentials From The Same IP id: 19cba45f-cad3-4032-8911-0c09e0444552 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Rico Valdez, Splunk status: deprecated type: TTP @@ -41,9 +41,8 @@ tags: - Suspicious Okta Activity asset_type: Okta Tenant mitre_attack_id: - - T1110.003 - - T1078 - T1078.001 + - T1110.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/net_localgroup_discovery.yml b/detections/deprecated/net_localgroup_discovery.yml index b3d15becdf..31b775f015 100644 --- a/detections/deprecated/net_localgroup_discovery.yml +++ b/detections/deprecated/net_localgroup_discovery.yml @@ -1,7 +1,7 @@ name: Net Localgroup Discovery id: 54f5201e-155b-11ec-a6e2-acde48001122 -version: 5 -date: '2025-01-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: Hunting @@ -52,7 +52,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/deprecated/network_connection_discovery_with_net.yml b/detections/deprecated/network_connection_discovery_with_net.yml index e2caea92c7..0002699f31 100644 --- a/detections/deprecated/network_connection_discovery_with_net.yml +++ b/detections/deprecated/network_connection_discovery_with_net.yml @@ -5,15 +5,15 @@ date: '2025-01-24' author: Mauricio Velazco, Splunk status: deprecated type: Hunting -description: The following analytic has been deprecated. The following analytic identifies - the execution of `net.exe` or `net1.exe` with command-line arguments used to list - network connections on a compromised system. It leverages data from Endpoint Detection - and Response (EDR) agents, focusing on process names and command-line executions. - This activity is significant as it indicates potential network reconnaissance by - adversaries or Red Teams, aiming to gather situational awareness and Active Directory - information. If confirmed malicious, this behavior could allow attackers to map - the network, identify critical assets, and plan further attacks, potentially leading - to data exfiltration or lateral movement. +description: The following analytic has been deprecated. + The following analytic identifies the execution of `net.exe` or `net1.exe` + with command-line arguments used to list network connections on a compromised system. + It leverages data from Endpoint Detection and Response (EDR) agents, focusing on + process names and command-line executions. This activity is significant as it indicates + potential network reconnaissance by adversaries or Red Teams, aiming to gather situational + awareness and Active Directory information. If confirmed malicious, this behavior + could allow attackers to map the network, identify critical assets, and plan further + attacks, potentially leading to data exfiltration or lateral movement. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml index 13dddb8c18..b706b2d0a8 100644 --- a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml +++ b/detections/deprecated/o365_suspicious_admin_email_forwarding.yml @@ -1,7 +1,7 @@ name: O365 Suspicious Admin Email Forwarding id: 7f398cfb-918d-41f4-8db8-2e2474e02c28 -version: 3 -date: '2024-11-14' +version: 4 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: Anomaly @@ -33,7 +33,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1114.003 - - T1114 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/o365_suspicious_rights_delegation.yml b/detections/deprecated/o365_suspicious_rights_delegation.yml index e9e6543750..716fd6289c 100644 --- a/detections/deprecated/o365_suspicious_rights_delegation.yml +++ b/detections/deprecated/o365_suspicious_rights_delegation.yml @@ -1,7 +1,7 @@ name: O365 Suspicious Rights Delegation id: b25d2973-303e-47c8-bacd-52b61604c6a7 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Mauricio Velazco, Splunk status: deprecated type: TTP @@ -56,10 +56,8 @@ tags: - Office 365 Collection Techniques asset_type: O365 Tenant mitre_attack_id: - - T1114.002 - - T1114 - T1098.002 - - T1098 + - T1114.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/detections/deprecated/o365_suspicious_user_email_forwarding.yml index 1a9c9c5c4c..4ea5ecc88d 100644 --- a/detections/deprecated/o365_suspicious_user_email_forwarding.yml +++ b/detections/deprecated/o365_suspicious_user_email_forwarding.yml @@ -1,7 +1,7 @@ name: O365 Suspicious User Email Forwarding id: f8dfe015-dbb3-4569-ba75-b13787e06aa4 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: deprecated type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: O365 Tenant mitre_attack_id: - T1114.003 - - T1114 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/office_application_drop_executable.yml b/detections/deprecated/office_application_drop_executable.yml index 792556a6d3..c87210ccf6 100644 --- a/detections/deprecated/office_application_drop_executable.yml +++ b/detections/deprecated/office_application_drop_executable.yml @@ -1,7 +1,7 @@ name: Office Application Drop Executable id: 73ce70c4-146d-11ec-9184-acde48001122 -version: 9 -date: '2025-01-24' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github status: deprecated type: TTP @@ -69,7 +69,6 @@ tags: - PlugX asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_application_spawn_regsvr32_process.yml b/detections/deprecated/office_application_spawn_regsvr32_process.yml index ceec84dba1..8aa07a2de3 100644 --- a/detections/deprecated/office_application_spawn_regsvr32_process.yml +++ b/detections/deprecated/office_application_spawn_regsvr32_process.yml @@ -1,7 +1,7 @@ name: Office Application Spawn Regsvr32 process id: 2d9fc90c-f11f-11eb-9300-acde48001122 -version: 8 -date: '2025-01-13' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -70,7 +70,6 @@ tags: - Qakbot asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_application_spawn_rundll32_process.yml b/detections/deprecated/office_application_spawn_rundll32_process.yml index 6d10c2b8c8..e648095cc9 100644 --- a/detections/deprecated/office_application_spawn_rundll32_process.yml +++ b/detections/deprecated/office_application_spawn_rundll32_process.yml @@ -1,7 +1,7 @@ name: Office Application Spawn rundll32 process id: 958751e4-9c5f-11eb-b103-acde48001122 -version: 8 -date: '2025-01-13' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -73,7 +73,6 @@ tags: - Trickbot asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_document_creating_schedule_task.yml b/detections/deprecated/office_document_creating_schedule_task.yml index 1275c00579..ef59131ecc 100644 --- a/detections/deprecated/office_document_creating_schedule_task.yml +++ b/detections/deprecated/office_document_creating_schedule_task.yml @@ -1,7 +1,7 @@ name: Office Document Creating Schedule Task id: cc8b7b74-9d0f-11eb-8342-acde48001122 -version: 10 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -59,7 +59,6 @@ tags: - Spearphishing Attachments asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_document_executing_macro_code.yml b/detections/deprecated/office_document_executing_macro_code.yml index 9bf6ad3357..8d74ea1aa2 100644 --- a/detections/deprecated/office_document_executing_macro_code.yml +++ b/detections/deprecated/office_document_executing_macro_code.yml @@ -1,7 +1,7 @@ name: Office Document Executing Macro Code id: b12c89bc-9d06-11eb-a592-acde48001122 -version: 9 -date: '2025-01-24' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -69,7 +69,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_document_spawned_child_process_to_download.yml b/detections/deprecated/office_document_spawned_child_process_to_download.yml index 73220f4027..2e78ed372c 100644 --- a/detections/deprecated/office_document_spawned_child_process_to_download.yml +++ b/detections/deprecated/office_document_spawned_child_process_to_download.yml @@ -1,7 +1,7 @@ name: Office Document Spawned Child Process To Download id: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3 -version: 10 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -69,7 +69,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawn_cmd_process.yml b/detections/deprecated/office_product_spawn_cmd_process.yml index 4193c23ca8..4893d60d9f 100644 --- a/detections/deprecated/office_product_spawn_cmd_process.yml +++ b/detections/deprecated/office_product_spawn_cmd_process.yml @@ -1,7 +1,7 @@ name: Office Product Spawn CMD Process id: b8b19420-e892-11eb-9244-acde48001122 -version: 8 -date: '2025-01-13' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: deprecated type: TTP @@ -85,7 +85,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_bitsadmin.yml b/detections/deprecated/office_product_spawning_bitsadmin.yml index 3bda779c35..28ee0cc811 100644 --- a/detections/deprecated/office_product_spawning_bitsadmin.yml +++ b/detections/deprecated/office_product_spawning_bitsadmin.yml @@ -1,7 +1,7 @@ name: Office Product Spawning BITSAdmin id: e8c591f4-a6d7-11eb-8cf7-acde48001122 -version: 9 -date: '2025-01-13' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -71,7 +71,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_certutil.yml b/detections/deprecated/office_product_spawning_certutil.yml index 00bc0797c9..698343c8ae 100644 --- a/detections/deprecated/office_product_spawning_certutil.yml +++ b/detections/deprecated/office_product_spawning_certutil.yml @@ -1,7 +1,7 @@ name: Office Product Spawning CertUtil id: 6925fe72-a6d5-11eb-9e17-acde48001122 -version: 9 -date: '2025-01-13' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -72,7 +72,6 @@ tags: - CVE-2023-36884 Office and Windows HTML RCE Vulnerability asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_mshta.yml b/detections/deprecated/office_product_spawning_mshta.yml index ef07f76ce2..9c8c8ae1ce 100644 --- a/detections/deprecated/office_product_spawning_mshta.yml +++ b/detections/deprecated/office_product_spawning_mshta.yml @@ -1,7 +1,7 @@ name: Office Product Spawning MSHTA id: 6078fa20-a6d2-11eb-b662-acde48001122 -version: 8 -date: '2025-01-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -71,7 +71,6 @@ tags: - CVE-2023-36884 Office and Windows HTML RCE Vulnerability asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml index a74965e373..41f3f9df66 100644 --- a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml +++ b/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml @@ -1,7 +1,7 @@ name: Office Product Spawning Rundll32 with no DLL id: c661f6be-a38c-11eb-be57-acde48001122 -version: 10 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -72,7 +72,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_windows_script_host.yml b/detections/deprecated/office_product_spawning_windows_script_host.yml index 659a4b48ed..b4da3bfa8e 100644 --- a/detections/deprecated/office_product_spawning_windows_script_host.yml +++ b/detections/deprecated/office_product_spawning_windows_script_host.yml @@ -1,7 +1,7 @@ name: Office Product Spawning Windows Script Host id: b3628a5b-8d02-42fa-a891-eebf2351cbe1 -version: 10 -date: '2025-01-13' +version: 12 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -75,7 +75,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_spawning_wmic.yml b/detections/deprecated/office_product_spawning_wmic.yml index a06d97a5d7..0e60c6e32f 100644 --- a/detections/deprecated/office_product_spawning_wmic.yml +++ b/detections/deprecated/office_product_spawning_wmic.yml @@ -1,7 +1,7 @@ name: Office Product Spawning Wmic id: ffc236d6-a6c9-11eb-95f1-acde48001122 -version: 10 -date: '2025-01-13' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -72,7 +72,6 @@ tags: - FIN7 asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_product_writing_cab_or_inf.yml b/detections/deprecated/office_product_writing_cab_or_inf.yml index 30adac14d5..9d29d2a888 100644 --- a/detections/deprecated/office_product_writing_cab_or_inf.yml +++ b/detections/deprecated/office_product_writing_cab_or_inf.yml @@ -1,7 +1,7 @@ name: Office Product Writing cab or inf id: f48cd1d4-125a-11ec-a447-acde48001122 -version: 10 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -76,7 +76,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/office_spawning_control.yml b/detections/deprecated/office_spawning_control.yml index 984e8bf0a8..f141b89519 100644 --- a/detections/deprecated/office_spawning_control.yml +++ b/detections/deprecated/office_spawning_control.yml @@ -1,7 +1,7 @@ name: Office Spawning Control id: 053e027c-10c7-11ec-8437-acde48001122 -version: 10 -date: '2025-01-24' +version: 12 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -77,7 +77,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/okta_account_lockout_events.yml b/detections/deprecated/okta_account_lockout_events.yml index 07f8d09a9d..b2ec1f14ef 100644 --- a/detections/deprecated/okta_account_lockout_events.yml +++ b/detections/deprecated/okta_account_lockout_events.yml @@ -1,7 +1,7 @@ name: Okta Account Lockout Events id: 62b70968-a0a5-4724-8ac4-67871e6f544d -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Michael Haag, Rico Valdez, Splunk status: deprecated type: Anomaly @@ -43,7 +43,6 @@ tags: - Suspicious Okta Activity asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.001 product: - Splunk Enterprise diff --git a/detections/deprecated/okta_failed_sso_attempts.yml b/detections/deprecated/okta_failed_sso_attempts.yml index 6516d32c67..3c1d92c759 100644 --- a/detections/deprecated/okta_failed_sso_attempts.yml +++ b/detections/deprecated/okta_failed_sso_attempts.yml @@ -1,7 +1,7 @@ name: Okta Failed SSO Attempts id: 371a6545-2618-4032-ad84-93386b8698c5 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Michael Haag, Rico Valdez, Splunk status: deprecated type: Anomaly @@ -32,7 +32,6 @@ tags: - Suspicious Okta Activity asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.001 product: - Splunk Enterprise diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml index 1f87cc42bf..00af9d0aa5 100644 --- a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml +++ b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml @@ -1,7 +1,7 @@ name: Okta ThreatInsight Login Failure with High Unknown users id: 632663b0-4562-4aad-abe9-9f621a049738 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Okta, Inc, Michael Haag, Splunk type: TTP status: deprecated @@ -34,7 +34,6 @@ tags: - Suspicious Okta Activity asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.001 - T1110.004 product: diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml index 478b4895a1..e68cf87729 100644 --- a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml +++ b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml @@ -1,7 +1,7 @@ name: Okta ThreatInsight Suspected PasswordSpray Attack id: 25dbad05-6682-4dd5-9ce9-8adecf0d9ae2 -version: 4 -date: '2024-11-14' +version: 5 +date: '2025-02-10' author: Okta, Inc, Michael Haag, Splunk type: TTP status: deprecated @@ -33,7 +33,6 @@ tags: - Suspicious Okta Activity asset_type: Infrastructure mitre_attack_id: - - T1078 - T1078.001 - T1110.003 product: diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/detections/deprecated/osquery_pack___coldroot_detection.yml index 3ba9866bed..369173b8fd 100644 --- a/detections/deprecated/osquery_pack___coldroot_detection.yml +++ b/detections/deprecated/osquery_pack___coldroot_detection.yml @@ -1,6 +1,6 @@ name: Osquery pack - ColdRoot detection id: a6fffe5e-05c3-4c04-badc-887607fbb8dc -version: 4 +version: 5 date: '2024-11-14' author: Rico Valdez, Splunk status: deprecated diff --git a/detections/deprecated/password_policy_discovery_with_net.yml b/detections/deprecated/password_policy_discovery_with_net.yml index 66ef237307..0656e661c8 100644 --- a/detections/deprecated/password_policy_discovery_with_net.yml +++ b/detections/deprecated/password_policy_discovery_with_net.yml @@ -5,15 +5,16 @@ date: '2025-01-24' author: Teoderick Contreras, Mauricio Velazco, Splunk status: deprecated type: Hunting -description: The following analytic has been deprecated. The following analytic identifies - the execution of `net.exe` or `net1.exe` with command line arguments aimed at obtaining - the domain password policy. It leverages data from Endpoint Detection and Response - (EDR) agents, focusing on process names and command-line executions. This activity - is significant as it indicates potential reconnaissance efforts by adversaries to - gather information about Active Directory password policies. If confirmed malicious, - this behavior could allow attackers to understand password complexity requirements, - aiding in brute-force or password-guessing attacks, ultimately compromising user - accounts and gaining unauthorized access to the network. +description: The following analytic has been deprecated. + The following analytic identifies the execution of `net.exe` or `net1.exe` + with command line arguments aimed at obtaining the domain password policy. It leverages + data from Endpoint Detection and Response (EDR) agents, focusing on process names + and command-line executions. This activity is significant as it indicates potential + reconnaissance efforts by adversaries to gather information about Active Directory + password policies. If confirmed malicious, this behavior could allow attackers to + understand password complexity requirements, aiding in brute-force or password-guessing + attacks, ultimately compromising user accounts and gaining unauthorized access to + the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/remote_desktop_network_bruteforce.yml b/detections/deprecated/remote_desktop_network_bruteforce.yml new file mode 100644 index 0000000000..400fe691cf --- /dev/null +++ b/detections/deprecated/remote_desktop_network_bruteforce.yml @@ -0,0 +1,58 @@ +name: Remote Desktop Network Bruteforce +id: a98727cc-286b-4ff2-b898-41df64695923 +version: 7 +date: '2025-01-10' +author: Jose Hernandez, Bhavin Patel, Splunk +status: deprecated +type: TTP +description: The following analytic has been deprecated in favor of "Windows Remote Desktop Network Bruteforce Attempt". The following analytic identifies potential Remote Desktop Protocol (RDP) brute force attacks by monitoring network traffic for RDP application activity. This query detects potential RDP brute force attacks by identifying source IPs that have made more than 10 successful connection attempts to the same RDP port on a host within a one-hour window. The results are presented in a table that includes the source and destination IPs, destination port, number of attempts, and the times of the first and last connection attempts, helping to prioritize IPs based on the intensity of activity. +data_source: +- Sysmon EventID 3 +search: >- + | tstats `security_content_summariesonly` count, min(_time) as firstTime, max(_time) as lastTime from datamodel=Network_Traffic where (All_Traffic.app=rdp OR All_Traffic.dest_port=3389) AND All_Traffic.action=allowed by All_Traffic.src, All_Traffic.dest, All_Traffic.dest_port All_Traffic.user All_Traffic.vendor_product + | `drop_dm_object_name("All_Traffic")` + | eval duration=lastTime-firstTime + | where count > 10 AND duration < 3600 + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `remote_desktop_network_bruteforce_filter` +how_to_implement: You must ensure that your network traffic data is populating the Network_Traffic data model. Adjust the count and duration thresholds as necessary to tune the sensitivity of your detection. +known_false_positives: RDP gateways may have unusually high amounts of traffic from all other hosts' RDP applications in the network.Any legitimate RDP traffic using wrong/expired credentials will be also detected as a false positive. +references: +- https://www.zscaler.com/blogs/security-research/ransomware-delivered-using-rdp-brute-force-attack +- https://www.reliaquest.com/blog/rdp-brute-force-attacks/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: RDP brute force attack on $dest$ + risk_objects: + - field: dest + type: system + score: 25 + threat_objects: [] +tags: + analytic_story: + - SamSam Ransomware + - Ryuk Ransomware + - Compromised User Account + asset_type: Endpoint + mitre_attack_id: + - T1110.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: network +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/rdp_brute_sysmon/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/deprecated/remote_system_discovery_with_net.yml b/detections/deprecated/remote_system_discovery_with_net.yml index 6e730569fc..2377264b52 100644 --- a/detections/deprecated/remote_system_discovery_with_net.yml +++ b/detections/deprecated/remote_system_discovery_with_net.yml @@ -5,35 +5,13 @@ date: '2025-01-13' author: Mauricio Velazco, Splunk status: deprecated type: Hunting -description: The following analytic has been deprecated in favour of two dedicated - analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" - .The following analytic identifies the execution of `net.exe` or `net1.exe` with - command-line arguments used to discover remote systems, such as `domain computers - /domain`. This detection leverages data from Endpoint Detection and Response (EDR) - agents, focusing on process names and command-line arguments. This activity is significant - as it indicates potential reconnaissance efforts by adversaries or Red Teams to - map out networked systems and Active Directory structures. If confirmed malicious, - this behavior could lead to further network exploitation, privilege escalation, - or lateral movement within the environment. +description: The following analytic has been deprecated in favour of two dedicated analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" .The following analytic identifies the execution of `net.exe` or `net1.exe` with command-line arguments used to discover remote systems, such as `domain computers /domain`. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries or Red Teams to map out networked systems and Active Directory structures. If confirmed malicious, this behavior could lead to further network exploitation, privilege escalation, or lateral movement within the environment. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*domain - computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*) - by Processes.dest Processes.user Processes.parent_process Processes.process_name - Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `remote_system_discovery_with_net_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection - and Response (EDR) agents. These agents are designed to provide security-related - telemetry from the endpoints where the agent is installed. To implement this search, - you must ingest logs that contain the process GUID, process name, and parent process. - Additionally, you must ingest complete command-line executions. These logs must - be processed using the appropriate Splunk Technology Add-ons that are specific to - the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` - data model. Use the Splunk Common Information Model (CIM) to normalize the field - names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND (Processes.process="*domain computers*" AND Processes.process=*/do*) OR (Processes.process="*view*" AND Processes.process=*/do*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `remote_system_discovery_with_net_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. known_false_positives: Administrators or power users may use this command for troubleshooting. references: - https://attack.mitre.org/techniques/T1018/ @@ -53,7 +31,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/suspicious_driver_loaded_path.yml b/detections/deprecated/suspicious_driver_loaded_path.yml similarity index 93% rename from detections/endpoint/suspicious_driver_loaded_path.yml rename to detections/deprecated/suspicious_driver_loaded_path.yml index 91196704e5..16d121b7b3 100644 --- a/detections/endpoint/suspicious_driver_loaded_path.yml +++ b/detections/deprecated/suspicious_driver_loaded_path.yml @@ -1,11 +1,11 @@ name: Suspicious Driver Loaded Path id: f880acd4-a8f1-11eb-a53b-acde48001122 -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-06' author: Teoderick Contreras, Splunk -status: production +status: deprecated type: TTP -description: The following analytic detects the loading of drivers from suspicious +description: This search has been deprecated in favour of - Windows Suspicious Driver Loaded Path. The following analytic detects the loading of drivers from suspicious paths, which is a technique often used by malicious software such as coin miners (e.g., xmrig). It leverages Sysmon EventCode 6 to identify drivers loaded from non-standard directories. This activity is significant because legitimate drivers typically reside @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.003 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/deprecated/suspicious_process_file_path.yml similarity index 95% rename from detections/endpoint/suspicious_process_file_path.yml rename to detections/deprecated/suspicious_process_file_path.yml index 1d636ec76c..d7cd62534f 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/deprecated/suspicious_process_file_path.yml @@ -1,11 +1,11 @@ name: Suspicious Process File Path id: 9be25988-ad82-11eb-a14f-acde48001122 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk -status: production +status: deprecated type: TTP -description: The following analytic identifies processes running from file paths not +description: This search has been deprecated in favour of - Windows Suspicious Process File Path. The following analytic identifies processes running from file paths not typically associated with legitimate software. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional @@ -117,4 +117,4 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog + sourcetype: XmlWinEventLog \ No newline at end of file diff --git a/detections/deprecated/suspicious_rundll32_rename.yml b/detections/deprecated/suspicious_rundll32_rename.yml index 48fdc6b2d5..eee4228129 100644 --- a/detections/deprecated/suspicious_rundll32_rename.yml +++ b/detections/deprecated/suspicious_rundll32_rename.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 Rename id: 7360137f-abad-473e-8189-acbdaa34d114 -version: 7 -date: '2024-11-14' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: Hunting @@ -40,10 +40,8 @@ tags: - Masquerading - Rename System Utilities asset_type: Endpoint mitre_attack_id: - - T1218 - - T1036 - - T1218.011 - T1036.003 + - T1218.011 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/windows_command_shell_fetch_env_variables.yml b/detections/deprecated/windows_command_shell_fetch_env_variables.yml index 8fcaf15950..90618ba3e5 100644 --- a/detections/deprecated/windows_command_shell_fetch_env_variables.yml +++ b/detections/deprecated/windows_command_shell_fetch_env_variables.yml @@ -5,14 +5,15 @@ date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic identifies - a suspicious process command line fetching environment variables with a non-shell - parent process. It leverages data from Endpoint Detection and Response (EDR) agents, - focusing on command-line executions and parent process names. This activity is significant - as it is commonly associated with malware like Qakbot, which uses this technique - to gather system information. If confirmed malicious, this behavior could indicate - that the parent process has been compromised, potentially allowing attackers to - execute arbitrary commands, escalate privileges, or persist within the environment. +description: The following analytic has been deprecated. + The following analytic identifies a suspicious process command line fetching + environment variables with a non-shell parent process. It leverages data from Endpoint + Detection and Response (EDR) agents, focusing on command-line executions and parent + process names. This activity is significant as it is commonly associated with malware + like Qakbot, which uses this technique to gather system information. If confirmed + malicious, this behavior could indicate that the parent process has been compromised, + potentially allowing attackers to execute arbitrary commands, escalate privileges, + or persist within the environment. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml index 38d777ae9a..6149fc746d 100644 --- a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml +++ b/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml @@ -1,7 +1,7 @@ name: Windows DLL Search Order Hijacking Hunt id: 79c7d0fc-60c7-41be-a616-ccda752efe89 -version: 5 -date: '2024-11-14' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: Hunting @@ -49,7 +49,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.001 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml index 0611c1c8f6..47789c6b30 100644 --- a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml +++ b/detections/deprecated/windows_lateral_tool_transfer_remcom.yml @@ -1,6 +1,6 @@ name: Windows Lateral Tool Transfer RemCom id: e373a840-5bdc-47ef-b2fd-9cc7aaf387f0 -version: 5 +version: 6 date: '2024-12-10' author: Michael Haag, Splunk type: TTP diff --git a/detections/deprecated/windows_modify_registry_reg_restore.yml b/detections/deprecated/windows_modify_registry_reg_restore.yml index e1fcad055a..f63d1b0214 100644 --- a/detections/deprecated/windows_modify_registry_reg_restore.yml +++ b/detections/deprecated/windows_modify_registry_reg_restore.yml @@ -5,15 +5,15 @@ date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: Hunting -description: The following analytic has been deprecated. The following analytic detects - the execution of reg.exe with the "restore" parameter, indicating an attempt to - restore registry backup data on a host. This detection leverages data from Endpoint - Detection and Response (EDR) agents, focusing on process execution logs and command-line - arguments. This activity is significant as it may indicate post-exploitation actions, - such as those performed by tools like winpeas, which use "reg save" and "reg restore" - to manipulate registry settings. If confirmed malicious, this could allow an attacker - to revert registry changes, potentially bypassing security controls and maintaining - persistence. +description: The following analytic has been deprecated. + The following analytic detects the execution of reg.exe with the "restore" + parameter, indicating an attempt to restore registry backup data on a host. This + detection leverages data from Endpoint Detection and Response (EDR) agents, focusing + on process execution logs and command-line arguments. This activity is significant + as it may indicate post-exploitation actions, such as those performed by tools like + winpeas, which use "reg save" and "reg restore" to manipulate registry settings. + If confirmed malicious, this could allow an attacker to revert registry changes, + potentially bypassing security controls and maintaining persistence. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/windows_msiexec_with_network_connections.yml b/detections/deprecated/windows_msiexec_with_network_connections.yml index 39ac9d4465..5c17518468 100644 --- a/detections/deprecated/windows_msiexec_with_network_connections.yml +++ b/detections/deprecated/windows_msiexec_with_network_connections.yml @@ -1,18 +1,19 @@ name: Windows MSIExec With Network Connections id: 827409a1-5393-4d8d-8da4-bbb297c262a7 -version: 6 +version: 7 date: '2025-01-24' author: Michael Haag, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic detects - MSIExec making network connections over ports 443 or 80. This behavior is identified - by correlating process creation events from Endpoint Detection and Response (EDR) - agents with network traffic logs. Typically, MSIExec does not perform network communication - to the internet, making this activity unusual and potentially indicative of malicious - behavior. If confirmed malicious, an attacker could be using MSIExec to download - or communicate with external servers, potentially leading to data exfiltration, - command and control (C2) communication, or further malware deployment. +description: The following analytic has been deprecated. + The following analytic detects MSIExec making network connections over + ports 443 or 80. This behavior is identified by correlating process creation events + from Endpoint Detection and Response (EDR) agents with network traffic logs. Typically, + MSIExec does not perform network communication to the internet, making this activity + unusual and potentially indicative of malicious behavior. If confirmed malicious, + an attacker could be using MSIExec to download or communicate with external servers, + potentially leading to data exfiltration, command and control (C2) communication, + or further malware deployment. data_source: - Sysmon EventID 1 AND Sysmon EventID 3 search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes diff --git a/detections/deprecated/windows_network_share_interaction_with_net.yml b/detections/deprecated/windows_network_share_interaction_with_net.yml index 29047d8992..fea71519c1 100644 --- a/detections/deprecated/windows_network_share_interaction_with_net.yml +++ b/detections/deprecated/windows_network_share_interaction_with_net.yml @@ -7,13 +7,13 @@ status: deprecated type: TTP data_source: - Sysmon EventID 1 -description: The following analytic has been deprecated. This analytic detects network - share discovery and collection activities performed on Windows systems using the - Net command. Attackers often use network share discovery to identify accessible - shared resources within a network, which can be a precursor to privilege escalation - or data exfiltration. By monitoring Windows Event Logs for the usage of the Net - command to list and interact with network shares, this detection helps identify - potential reconnaissance and collection activities. +description: The following analytic has been deprecated. + This analytic detects network share discovery and collection activities + performed on Windows systems using the Net command. Attackers often use network + share discovery to identify accessible shared resources within a network, which + can be a precursor to privilege escalation or data exfiltration. By monitoring Windows + Event Logs for the usage of the Net command to list and interact with network shares, + this detection helps identify potential reconnaissance and collection activities. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.user_category) as user_category values(Processes.user_bunit) as user_bunit FROM datamodel=Endpoint.Processes WHERE `process_net` BY Processes.user diff --git a/detections/deprecated/windows_office_product_spawning_msdt.yml b/detections/deprecated/windows_office_product_spawning_msdt.yml index 88be1f1298..9415352231 100644 --- a/detections/deprecated/windows_office_product_spawning_msdt.yml +++ b/detections/deprecated/windows_office_product_spawning_msdt.yml @@ -1,7 +1,7 @@ name: Windows Office Product Spawning MSDT id: 127eba64-c981-40bf-8589-1830638864a7 -version: 9 -date: '2025-01-24' +version: 11 +date: '2025-02-10' author: Michael Haag, Teoderick Contreras, Splunk status: deprecated type: TTP @@ -80,7 +80,6 @@ tags: cve: - CVE-2022-30190 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/windows_query_registry_reg_save.yml b/detections/deprecated/windows_query_registry_reg_save.yml index f44d4b8617..291c0cf7a0 100644 --- a/detections/deprecated/windows_query_registry_reg_save.yml +++ b/detections/deprecated/windows_query_registry_reg_save.yml @@ -5,14 +5,14 @@ date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: Hunting -description: The following analytic has been deprecated. The following analytic detects - the execution of the reg.exe process with the "save" parameter. This detection leverages - data from Endpoint Detection and Response (EDR) agents, focusing on process execution - logs and command-line arguments. This activity is significant because threat actors - often use the "reg save" command to dump credentials or test registry modification - capabilities on compromised hosts. If confirmed malicious, this behavior could allow - attackers to escalate privileges, persist in the environment, or access sensitive - information stored in the registry. +description: The following analytic has been deprecated. + The following analytic detects the execution of the reg.exe process with + the "save" parameter. This detection leverages data from Endpoint Detection and + Response (EDR) agents, focusing on process execution logs and command-line arguments. + This activity is significant because threat actors often use the "reg save" command + to dump credentials or test registry modification capabilities on compromised hosts. + If confirmed malicious, this behavior could allow attackers to escalate privileges, + persist in the environment, or access sensitive information stored in the registry. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/windows_valid_account_with_never_expires_password.yml b/detections/deprecated/windows_valid_account_with_never_expires_password.yml index 6bd2c46133..01b416d1d5 100644 --- a/detections/deprecated/windows_valid_account_with_never_expires_password.yml +++ b/detections/deprecated/windows_valid_account_with_never_expires_password.yml @@ -5,14 +5,15 @@ date: '2025-01-24' author: Teoderick Contreras, Splunk status: deprecated type: TTP -description: The following analytic has been deprecated. The following analytic detects - the use of net.exe to update user account policies to set passwords as non-expiring. - It leverages data from Endpoint Detection and Response (EDR) agents, focusing on - command-line executions involving "/maxpwage:unlimited". This activity is significant - as it can indicate an attempt to maintain persistence, escalate privileges, evade - defenses, or facilitate lateral movement. If confirmed malicious, this behavior - could allow an attacker to maintain long-term access to compromised accounts, potentially - leading to further exploitation and unauthorized access to sensitive information. +description: The following analytic has been deprecated. + The following analytic detects the use of net.exe to update user account + policies to set passwords as non-expiring. It leverages data from Endpoint Detection + and Response (EDR) agents, focusing on command-line executions involving "/maxpwage:unlimited". + This activity is significant as it can indicate an attempt to maintain persistence, + escalate privileges, evade defenses, or facilitate lateral movement. If confirmed + malicious, this behavior could allow an attacker to maintain long-term access to + compromised accounts, potentially leading to further exploitation and unauthorized + access to sensitive information. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/detections/deprecated/winword_spawning_cmd.yml b/detections/deprecated/winword_spawning_cmd.yml index f16575033c..2d65e01f22 100644 --- a/detections/deprecated/winword_spawning_cmd.yml +++ b/detections/deprecated/winword_spawning_cmd.yml @@ -1,7 +1,7 @@ name: Winword Spawning Cmd id: 6fcbaedc-a37b-11eb-956b-acde48001122 -version: 7 -date: '2025-01-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -73,7 +73,6 @@ tags: - DarkCrystal RAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/winword_spawning_powershell.yml b/detections/deprecated/winword_spawning_powershell.yml index 50d598f95b..4164d64cf7 100644 --- a/detections/deprecated/winword_spawning_powershell.yml +++ b/detections/deprecated/winword_spawning_powershell.yml @@ -1,7 +1,7 @@ name: Winword Spawning PowerShell id: b2c950b8-9be2-11eb-8658-acde48001122 -version: 7 -date: '2025-01-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -76,7 +76,6 @@ tags: - DarkCrystal RAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/deprecated/winword_spawning_windows_script_host.yml b/detections/deprecated/winword_spawning_windows_script_host.yml index b1d17ca5a5..47feee0635 100644 --- a/detections/deprecated/winword_spawning_windows_script_host.yml +++ b/detections/deprecated/winword_spawning_windows_script_host.yml @@ -1,7 +1,7 @@ name: Winword Spawning Windows Script Host id: 637e1b5c-9be1-11eb-9c32-acde48001122 -version: 6 -date: '2025-01-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: deprecated type: TTP @@ -70,7 +70,6 @@ tags: - CVE-2023-21716 Word RTF Heap Corruption asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/endpoint/7zip_commandline_to_smb_share_path.yml b/detections/endpoint/7zip_commandline_to_smb_share_path.yml index 01c78be576..052abeb87b 100644 --- a/detections/endpoint/7zip_commandline_to_smb_share_path.yml +++ b/detections/endpoint/7zip_commandline_to_smb_share_path.yml @@ -1,7 +1,7 @@ name: 7zip CommandLine To SMB Share Path id: 01d29b48-ff6f-11eb-b81e-acde48001123 -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/access_lsass_memory_for_dump_creation.yml b/detections/endpoint/access_lsass_memory_for_dump_creation.yml index ad6103c9b0..0f261b491b 100644 --- a/detections/endpoint/access_lsass_memory_for_dump_creation.yml +++ b/detections/endpoint/access_lsass_memory_for_dump_creation.yml @@ -1,7 +1,7 @@ name: Access LSASS Memory for Dump Creation id: fb4c31b0-13e8-4155-8aa5-24de4b8d6717 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Windows mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index 6f4e0d1d4d..6ca39da2a4 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -1,7 +1,7 @@ name: Active Setup Registry Autostart id: f64579c0-203f-11ec-abcc-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.014 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml index cd0c7eb48c..968de4b132 100644 --- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml +++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml @@ -1,7 +1,7 @@ name: Add DefaultUser And Password In Registry id: d4a3eb62-0f1e-11ec-a971-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.002 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/add_or_set_windows_defender_exclusion.yml b/detections/endpoint/add_or_set_windows_defender_exclusion.yml index cf78828ce7..ca4975ede6 100644 --- a/detections/endpoint/add_or_set_windows_defender_exclusion.yml +++ b/detections/endpoint/add_or_set_windows_defender_exclusion.yml @@ -1,7 +1,7 @@ name: Add or Set Windows Defender Exclusion id: 773b66fe-4dd9-11ec-8289-acde48001122 -version: '6' -date: '2024-12-17' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml index 65286be5b8..67241b0279 100644 --- a/detections/endpoint/adsisearcher_account_discovery.yml +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -1,7 +1,7 @@ name: AdsiSearcher Account Discovery id: de7fcadc-04f3-11ec-a241-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index 0a86ed9fd9..2e11a3aa86 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -1,7 +1,7 @@ name: Allow File And Printing Sharing In Firewall id: ce27646e-d411-11eb-8a00-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index 6b7f561f20..8aa114f36a 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -1,7 +1,7 @@ name: Allow Inbound Traffic By Firewall Rule Registry id: 0a46537c-be02-11eb-92ca-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml index 677ec6f051..bf2fda0d4b 100644 --- a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml +++ b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml @@ -1,7 +1,7 @@ name: Allow Inbound Traffic In Firewall Rule id: a5d85486-b89c-11eb-8267-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/allow_network_discovery_in_firewall.yml b/detections/endpoint/allow_network_discovery_in_firewall.yml index 1334af8f48..1163a4d168 100644 --- a/detections/endpoint/allow_network_discovery_in_firewall.yml +++ b/detections/endpoint/allow_network_discovery_in_firewall.yml @@ -1,7 +1,7 @@ name: Allow Network Discovery In Firewall id: ccd6a38c-d40b-11eb-85a5-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.007 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index 952bab98c5..32a9f2d25c 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -1,7 +1,7 @@ name: Anomalous usage of 7zip id: 9364ee8e-a39a-11eb-8f1d-acde48001122 -version: 6 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Teoderick Contreras, Splunk status: production type: Anomaly @@ -77,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml index 74049ff9cb..65a6733058 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/endpoint/any_powershell_downloadfile.yml @@ -1,7 +1,7 @@ name: Any Powershell DownloadFile id: 1a93b7ea-7af7-11eb-adb5-acde48001122 -version: 9 -date: '2025-01-27' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -87,7 +87,6 @@ tags: cve: - CVE-2021-44228 mitre_attack_id: - - T1059 - T1059.001 - T1105 product: @@ -98,6 +97,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml index 3a5fdced6f..7f516361ff 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/endpoint/any_powershell_downloadstring.yml @@ -1,7 +1,7 @@ name: Any Powershell DownloadString id: 4d015ef2-7adf-11eb-95da-acde48001122 -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -83,7 +83,6 @@ tags: - Phemedrone Stealer asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 - T1105 product: diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 13d06f14d7..a983aeb31d 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,7 +1,7 @@ name: Attacker Tools On Endpoint id: a51bfe1a-94f0-48cc-b4e4-16a110145893 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -73,9 +73,8 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1036.005 - - T1036 - T1003 + - T1036.005 - T1595 product: - Splunk Enterprise diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index e23a285c6c..360d6c472d 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -1,7 +1,7 @@ name: Attempt To Add Certificate To Untrusted Store id: 6bc5243e-ef36-45dc-9b12-f4a6be131159 -version: 11 -date: '2024-11-13' +version: 13 +date: '2025-02-10' author: Patrick Bareiss, Rico Valdez, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1553.004 - - T1553 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/auto_admin_logon_registry_entry.yml b/detections/endpoint/auto_admin_logon_registry_entry.yml index ab26897ba0..8161fcdca6 100644 --- a/detections/endpoint/auto_admin_logon_registry_entry.yml +++ b/detections/endpoint/auto_admin_logon_registry_entry.yml @@ -1,7 +1,7 @@ name: Auto Admin Logon Registry Entry id: 1379d2b8-0f18-11ec-8ca3-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.002 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index b7fa5f29ff..0d3a9702cd 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -1,7 +1,7 @@ name: Batch File Write to System32 id: 503d17cb-9eab-4cf8-a20e-01d5c6987ae3 -version: 8 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Steven Dick, Michael Haag, Rico Valdez, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1204 - T1204.002 product: - Splunk Enterprise diff --git a/detections/endpoint/bcdedit_failure_recovery_modification.yml b/detections/endpoint/bcdedit_failure_recovery_modification.yml index 29bdb7ba33..1425eee424 100644 --- a/detections/endpoint/bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/bcdedit_failure_recovery_modification.yml @@ -1,6 +1,6 @@ name: BCDEdit Failure Recovery Modification id: 809b31d2-5462-11eb-ae93-0242ac130002 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/bits_job_persistence.yml b/detections/endpoint/bits_job_persistence.yml index b115098430..eee12eeb44 100644 --- a/detections/endpoint/bits_job_persistence.yml +++ b/detections/endpoint/bits_job_persistence.yml @@ -1,6 +1,6 @@ name: BITS Job Persistence id: e97a5ffe-90bf-11eb-928a-acde48001122 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/bitsadmin_download_file.yml b/detections/endpoint/bitsadmin_download_file.yml index da8e3522bb..bdab9e207a 100644 --- a/detections/endpoint/bitsadmin_download_file.yml +++ b/detections/endpoint/bitsadmin_download_file.yml @@ -1,6 +1,6 @@ name: BITSAdmin Download File id: 80630ff4-8e4c-11eb-aab5-acde48001122 -version: 7 +version: 8 date: '2024-11-13' author: Michael Haag, Sittikorn S status: production diff --git a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml index 7e3407c516..b6d19b0b39 100644 --- a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml @@ -1,6 +1,6 @@ name: CertUtil Download With URLCache and Split Arguments id: 415b4306-8bfb-11eb-85c4-acde48001122 -version: 9 +version: 10 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml index 7c6a453b69..97a0c24ba9 100644 --- a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml @@ -1,6 +1,6 @@ name: CertUtil Download With VerifyCtl and Split Arguments id: 801ad9e4-8bfb-11eb-8b31-acde48001122 -version: 9 +version: 10 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/certutil_exe_certificate_extraction.yml b/detections/endpoint/certutil_exe_certificate_extraction.yml index 34b29335c5..6dafec9ff9 100644 --- a/detections/endpoint/certutil_exe_certificate_extraction.yml +++ b/detections/endpoint/certutil_exe_certificate_extraction.yml @@ -1,6 +1,6 @@ name: Certutil exe certificate extraction id: 337a46be-600f-11eb-ae93-0242ac130002 -version: 7 +version: 8 date: '2024-12-10' author: Rod Soto, Splunk status: production diff --git a/detections/endpoint/certutil_with_decode_argument.yml b/detections/endpoint/certutil_with_decode_argument.yml index 0fc4d9b902..f00b0f4387 100644 --- a/detections/endpoint/certutil_with_decode_argument.yml +++ b/detections/endpoint/certutil_with_decode_argument.yml @@ -1,6 +1,6 @@ name: CertUtil With Decode Argument id: bfe94226-8c10-11eb-a4b3-acde48001122 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/check_elevated_cmd_using_whoami.yml b/detections/endpoint/check_elevated_cmd_using_whoami.yml index abb19e8ac8..b5f5648875 100644 --- a/detections/endpoint/check_elevated_cmd_using_whoami.yml +++ b/detections/endpoint/check_elevated_cmd_using_whoami.yml @@ -1,6 +1,6 @@ name: Check Elevated CMD using whoami id: a9079b18-1633-11ec-859c-acde48001122 -version: 4 +version: 5 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml index ee6d5594e2..82a73a420c 100644 --- a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml +++ b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml @@ -1,7 +1,7 @@ name: Clear Unallocated Sector Using Cipher App id: cd80a6ac-c9d9-11eb-8839-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1070.004 - - T1070 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/clop_common_exec_parameter.yml b/detections/endpoint/clop_common_exec_parameter.yml index 0be756484b..3618dec57d 100644 --- a/detections/endpoint/clop_common_exec_parameter.yml +++ b/detections/endpoint/clop_common_exec_parameter.yml @@ -1,6 +1,6 @@ name: Clop Common Exec Parameter id: 5a8a2a72-8322-11eb-9ee9-acde48001122 -version: 7 +version: 8 date: '2024-12-10' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/cmd_carry_out_string_command_parameter.yml b/detections/endpoint/cmd_carry_out_string_command_parameter.yml index ead8c6acad..f2545358d1 100644 --- a/detections/endpoint/cmd_carry_out_string_command_parameter.yml +++ b/detections/endpoint/cmd_carry_out_string_command_parameter.yml @@ -1,7 +1,7 @@ name: CMD Carry Out String Command Parameter id: 54a6ed00-3256-11ec-b031-acde48001122 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Bhavin Patel, Splunk status: production type: Hunting @@ -64,7 +64,6 @@ tags: - CVE-2021-44228 mitre_attack_id: - T1059.003 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/cmd_echo_pipe___escalation.yml b/detections/endpoint/cmd_echo_pipe___escalation.yml index 618a7f1670..c1b77e4c5b 100644 --- a/detections/endpoint/cmd_echo_pipe___escalation.yml +++ b/detections/endpoint/cmd_echo_pipe___escalation.yml @@ -1,7 +1,7 @@ name: CMD Echo Pipe - Escalation id: eb277ba0-b96b-11eb-b00e-acde48001122 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -75,10 +75,8 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.003 - T1543.003 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml b/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml index d71bc60a38..deb0daab75 100644 --- a/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml +++ b/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml @@ -1,7 +1,7 @@ name: CMLUA Or CMSTPLUA UAC Bypass id: f87b5062-b405-11eb-a889-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - ValleyRAT asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.003 product: - Splunk Enterprise diff --git a/detections/endpoint/common_ransomware_extensions.yml b/detections/endpoint/common_ransomware_extensions.yml index 281a998ed1..b7dbef7eb3 100644 --- a/detections/endpoint/common_ransomware_extensions.yml +++ b/detections/endpoint/common_ransomware_extensions.yml @@ -1,6 +1,6 @@ name: Common Ransomware Extensions id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec -version: 10 +version: 11 date: '2025-01-07' author: David Dorsey, Michael Haag, Splunk, Steven Dick status: production diff --git a/detections/endpoint/conti_common_exec_parameter.yml b/detections/endpoint/conti_common_exec_parameter.yml index fe3227dd29..68ddb073f8 100644 --- a/detections/endpoint/conti_common_exec_parameter.yml +++ b/detections/endpoint/conti_common_exec_parameter.yml @@ -1,6 +1,6 @@ name: Conti Common Exec parameter id: 624919bc-c382-11eb-adcc-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/control_loading_from_world_writable_directory.yml b/detections/endpoint/control_loading_from_world_writable_directory.yml index 0b02258a47..34c0fe2491 100644 --- a/detections/endpoint/control_loading_from_world_writable_directory.yml +++ b/detections/endpoint/control_loading_from_world_writable_directory.yml @@ -1,7 +1,7 @@ name: Control Loading from World Writable Directory id: 10423ac4-10c9-11ec-8dc4-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -80,7 +80,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1218 - T1218.002 product: - Splunk Enterprise diff --git a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml index c90a12c6e9..43cc11f1f7 100644 --- a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml +++ b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml @@ -1,7 +1,7 @@ name: Create or delete windows shares using net exe id: 743a322c-9a68-4a0f-9c17-85d9cce2a27c -version: 10 -date: '2024-12-12' +version: 12 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: - DarkGate Malware asset_type: Endpoint mitre_attack_id: - - T1070 - T1070.005 product: - Splunk Enterprise diff --git a/detections/endpoint/create_remote_thread_into_lsass.yml b/detections/endpoint/create_remote_thread_into_lsass.yml index daf76493ed..fbc0310759 100644 --- a/detections/endpoint/create_remote_thread_into_lsass.yml +++ b/detections/endpoint/create_remote_thread_into_lsass.yml @@ -1,7 +1,7 @@ name: Create Remote Thread into LSASS id: 67d4dbef-9564-4699-8da8-03a151529edc -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: Windows mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml b/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml index ee0bb861f3..dcd2a4391c 100644 --- a/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml +++ b/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml @@ -1,7 +1,7 @@ name: Creation of lsass Dump with Taskmgr id: b2fbe95a-9c62-4c12-8a29-24b97e84c0cd -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: Windows mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/creation_of_shadow_copy.yml b/detections/endpoint/creation_of_shadow_copy.yml index 49b3059565..ce5b148d77 100644 --- a/detections/endpoint/creation_of_shadow_copy.yml +++ b/detections/endpoint/creation_of_shadow_copy.yml @@ -1,7 +1,7 @@ name: Creation of Shadow Copy id: eb120f5f-b879-4a63-97c1-93352b5df844 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml index 9571ea9236..78b7c0d9dd 100644 --- a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml +++ b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml @@ -1,7 +1,7 @@ name: Creation of Shadow Copy with wmic and powershell id: 2ed8b538-d284-449a-be1d-82ad1dbd186b -version: 8 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml index 69aa5fe62b..a443947f7e 100644 --- a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml @@ -1,7 +1,7 @@ name: Credential Dumping via Copy Command from Shadow Copy id: d8c406fe-23d2-45f3-a983-1abe7b83ff3b -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml index ed7082bfee..ac524c6b29 100644 --- a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml @@ -1,7 +1,7 @@ name: Credential Dumping via Symlink to Shadow Copy id: c5eac648-fae0-4263-91a6-773df1f4c903 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/csc_net_on_the_fly_compilation.yml b/detections/endpoint/csc_net_on_the_fly_compilation.yml index 523efe64be..39211a947c 100644 --- a/detections/endpoint/csc_net_on_the_fly_compilation.yml +++ b/detections/endpoint/csc_net_on_the_fly_compilation.yml @@ -1,7 +1,7 @@ name: CSC Net On The Fly Compilation id: ea73128a-43ab-11ec-9753-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -45,7 +45,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1027.004 - - T1027 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml index 43b2d363b6..89b5ebed9b 100644 --- a/detections/endpoint/deleting_shadow_copies.yml +++ b/detections/endpoint/deleting_shadow_copies.yml @@ -1,6 +1,6 @@ name: Deleting Shadow Copies id: b89919ed-ee5f-492c-b139-95dbb162039e -version: 9 +version: 10 date: '2024-12-10' author: David Dorsey, Splunk status: production diff --git a/detections/endpoint/detect_azurehound_command_line_arguments.yml b/detections/endpoint/detect_azurehound_command_line_arguments.yml index a20929459c..df661b9c10 100644 --- a/detections/endpoint/detect_azurehound_command_line_arguments.yml +++ b/detections/endpoint/detect_azurehound_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Detect AzureHound Command-Line Arguments id: 26f02e96-c300-11eb-b611-acde48001122 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -72,13 +72,11 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_azurehound_file_modifications.yml b/detections/endpoint/detect_azurehound_file_modifications.yml index 71aee3b142..af89e009cd 100644 --- a/detections/endpoint/detect_azurehound_file_modifications.yml +++ b/detections/endpoint/detect_azurehound_file_modifications.yml @@ -1,7 +1,7 @@ name: Detect AzureHound File Modifications id: 1c34549e-c31b-11eb-996b-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -62,13 +62,11 @@ tags: - Windows Discovery Techniques asset_type: Endpoint mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml b/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml index 38e25e1fcc..5b22224e3d 100644 --- a/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml +++ b/detections/endpoint/detect_certify_with_powershell_script_block_logging.yml @@ -1,7 +1,7 @@ name: Detect Certify With PowerShell Script Block Logging id: f533ca6c-9440-4686-80cb-7f294c07812a -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -62,9 +62,8 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1649 - - T1059 - T1059.001 + - T1649 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_certipy_file_modifications.yml b/detections/endpoint/detect_certipy_file_modifications.yml index 932c36dce7..48a6a3129b 100644 --- a/detections/endpoint/detect_certipy_file_modifications.yml +++ b/detections/endpoint/detect_certipy_file_modifications.yml @@ -1,6 +1,6 @@ name: Detect Certipy File Modifications id: 7e3df743-b1d8-4631-8fa8-bd5819688876 -version: 4 +version: 5 date: '2024-11-13' author: Steven Dick status: production diff --git a/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml b/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml index 9f13d8ec5e..5ba7b43a6d 100644 --- a/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml +++ b/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml @@ -1,7 +1,7 @@ name: Detect Copy of ShadowCopy with Script Block Logging id: 9251299c-ea5b-11eb-a8de-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - CVE-2021-36934 mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml index cbca225e2f..d407bbd637 100644 --- a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml +++ b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml @@ -1,7 +1,7 @@ name: Detect Credential Dumping through LSASS access id: 2c365e57-4414-4540-8dc0-73ab10729996 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Windows mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml index 7e5e09b90a..4c5e71523a 100644 --- a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml +++ b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml @@ -1,7 +1,7 @@ name: Detect Empire with PowerShell Script Block Logging id: bc1dc6b8-c954-11eb-bade-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml index c159f44c23..e81a797125 100644 --- a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml +++ b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml @@ -1,7 +1,7 @@ name: Detect Excessive Account Lockouts From Endpoint id: c026e3dd-7e18-4abb-8f41-929e836efe74 -version: 11 -date: '2024-11-13' +version: 12 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: - Active Directory Password Spraying asset_type: Windows mitre_attack_id: - - T1078 - T1078.002 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_excessive_user_account_lockouts.yml b/detections/endpoint/detect_excessive_user_account_lockouts.yml index e80d4200a3..6eab6eb5d8 100644 --- a/detections/endpoint/detect_excessive_user_account_lockouts.yml +++ b/detections/endpoint/detect_excessive_user_account_lockouts.yml @@ -1,7 +1,7 @@ name: Detect Excessive User Account Lockouts id: 95a7f9a5-6096-437e-a19e-86f42ac609bd -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: Anomaly @@ -51,7 +51,6 @@ tags: - Active Directory Password Spraying asset_type: Windows mitre_attack_id: - - T1078 - T1078.003 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml index 6301bf3efc..11b24212d0 100644 --- a/detections/endpoint/detect_exchange_web_shell.yml +++ b/detections/endpoint/detect_exchange_web_shell.yml @@ -1,7 +1,7 @@ name: Detect Exchange Web Shell id: 8c14eeee-2af1-4a4b-bda8-228da0f4862a -version: 9 -date: '2024-12-12' +version: 10 +date: '2025-02-10' author: Michael Haag, Shannon Davis, David Dorsey, Splunk status: production type: TTP @@ -16,18 +16,16 @@ description: The following analytic identifies the creation of suspicious .aspx data_source: - Sysmon EventID 1 AND Sysmon EventID 11 search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - where Processes.process_name=System by _time span=1h Processes.process_guid Processes.process_name Processes.process - Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| join process_guid, _time - [| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", - "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name - IN( "*.aspx", "*.ashx") by _time span=1h Filesystem.process_guid Filesystem.user Filesystem.dest Filesystem.file_create_time - Filesystem.file_name Filesystem.file_path - | `drop_dm_object_name(Filesystem)` ] - | dedup file_create_time - | table _time dest user file_create_time file_name file_path process_name process process_guid | `detect_exchange_web_shell_filter`' + where Processes.process_name=System by _time span=1h Processes.process_guid Processes.process_name + Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)` + | join process_guid, _time [| tstats `security_content_summariesonly` count min(_time) + as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path + IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") + Filesystem.file_name IN( "*.aspx", "*.ashx") by _time span=1h Filesystem.process_guid + Filesystem.user Filesystem.dest Filesystem.file_create_time Filesystem.file_name + Filesystem.file_path | `drop_dm_object_name(Filesystem)` ] | dedup file_create_time + | table _time dest user file_create_time file_name file_path process_name process + process_guid | `detect_exchange_web_shell_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` @@ -78,10 +76,9 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1505 - - T1505.003 - - T1190 - T1133 + - T1190 + - T1505.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_html_help_renamed.yml b/detections/endpoint/detect_html_help_renamed.yml index 5ad0885f0f..a772c50bad 100644 --- a/detections/endpoint/detect_html_help_renamed.yml +++ b/detections/endpoint/detect_html_help_renamed.yml @@ -1,7 +1,7 @@ name: Detect HTML Help Renamed id: 62fed254-513b-460e-953d-79771493a9f3 -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -44,7 +44,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_html_help_spawn_child_process.yml b/detections/endpoint/detect_html_help_spawn_child_process.yml index 05aed6328e..e4cf5469a5 100644 --- a/detections/endpoint/detect_html_help_spawn_child_process.yml +++ b/detections/endpoint/detect_html_help_spawn_child_process.yml @@ -1,7 +1,7 @@ name: Detect HTML Help Spawn Child Process id: 723716de-ee55-4cd4-9759-c44e7e55ba4b -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -78,7 +78,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml index d72c7f64a1..4e07b994f9 100644 --- a/detections/endpoint/detect_html_help_url_in_command_line.yml +++ b/detections/endpoint/detect_html_help_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Detect HTML Help URL in Command Line id: 8c5835b9-39d9-438b-817c-95f14c69a31e -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml index 335817cd7b..3ab1a666ab 100644 --- a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml +++ b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml @@ -1,7 +1,7 @@ name: Detect HTML Help Using InfoTech Storage Handlers id: 0b2eefa5-5508-450d-b970-3dd2fb761aec -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml b/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml index 0960910cc8..d3616fae42 100644 --- a/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml +++ b/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml @@ -1,6 +1,6 @@ name: Detect Mimikatz With PowerShell Script Block Logging id: 8148c29c-c952-11eb-9255-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/detect_mshta_inline_hta_execution.yml b/detections/endpoint/detect_mshta_inline_hta_execution.yml index 09c4f17867..cc64c91a1d 100644 --- a/detections/endpoint/detect_mshta_inline_hta_execution.yml +++ b/detections/endpoint/detect_mshta_inline_hta_execution.yml @@ -1,7 +1,7 @@ name: Detect mshta inline hta execution id: a0873b32-5b68-11eb-ae93-0242ac130002 -version: 12 -date: '2024-12-10' +version: 14 +date: '2025-02-10' author: Bhavin Patel, Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_mshta_renamed.yml b/detections/endpoint/detect_mshta_renamed.yml index 229050f266..8edd8c5256 100644 --- a/detections/endpoint/detect_mshta_renamed.yml +++ b/detections/endpoint/detect_mshta_renamed.yml @@ -1,7 +1,7 @@ name: Detect mshta renamed id: 8f45fcf0-5b68-11eb-ae93-0242ac130002 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index 7a9bc24261..c33a2bd047 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Detect MSHTA Url in Command Line id: 9b3af1e6-5b68-11eb-ae93-0242ac130002 -version: 8 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_new_local_admin_account.yml b/detections/endpoint/detect_new_local_admin_account.yml index f70320bd1c..e17eed841e 100644 --- a/detections/endpoint/detect_new_local_admin_account.yml +++ b/detections/endpoint/detect_new_local_admin_account.yml @@ -1,7 +1,7 @@ name: Detect New Local Admin account id: b25f6f62-0712-43c1-b203-083231ffd97d -version: 6 -date: '2024-12-12' +version: 7 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Windows mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml b/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml index 4e6934e5fc..95d80c9749 100644 --- a/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml +++ b/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml @@ -1,7 +1,7 @@ name: Detect Outlook exe writing a zip file id: a51bfe1a-94f0-4822-b1e4-16ae10145893 -version: 9 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Bhavin Patel, Splunk status: experimental type: TTP @@ -55,7 +55,6 @@ tags: - Meduza Stealer asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml b/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml index a3a18311fa..474fcdd7d7 100644 --- a/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml +++ b/detections/endpoint/detect_password_spray_attack_behavior_from_source.yml @@ -1,7 +1,7 @@ name: Detect Password Spray Attack Behavior From Source id: b6391b15-e913-4c2c-8949-9eecc06efacc -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -68,7 +68,6 @@ tags: asset_type: Account mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml b/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml index bd82127859..c584c6dae0 100644 --- a/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml +++ b/detections/endpoint/detect_password_spray_attack_behavior_on_user.yml @@ -1,7 +1,7 @@ name: Detect Password Spray Attack Behavior On User id: a7539705-7183-4a12-9b6a-b6eef645a6d7 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Account mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml index f6f07579ae..7996dfb15e 100644 --- a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml +++ b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml @@ -1,7 +1,7 @@ name: Detect Path Interception By Creation Of program exe id: cbef820c-e1ff-407f-887f-0a9240a2d477 -version: 9 -date: '2024-11-13' +version: 11 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.009 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml index 08ebbb0515..1b9df60d0d 100644 --- a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml +++ b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml @@ -1,7 +1,7 @@ name: Detect Prohibited Applications Spawning cmd exe id: dcfd6b40-42f9-469d-a433-2e53f7486664 -version: 10 -date: '2024-11-13' +version: 11 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Hunting @@ -44,7 +44,6 @@ tags: - NOBELIUM Group asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.003 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index 6004101254..f1974ad052 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -1,7 +1,7 @@ name: Detect PsExec With accepteula Flag id: 27c3a83d-cada-47c6-9042-67baf19d2574 -version: 8 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -83,7 +83,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.002 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml index 31e5bc6329..a36e49cace 100644 --- a/detections/endpoint/detect_rclone_command_line_usage.yml +++ b/detections/endpoint/detect_rclone_command_line_usage.yml @@ -1,6 +1,6 @@ name: Detect RClone Command-Line Usage id: 32e0baea-b3f1-11eb-a2ce-acde48001122 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml index edd0e0652f..adc6c5a181 100644 --- a/detections/endpoint/detect_regasm_spawning_a_process.yml +++ b/detections/endpoint/detect_regasm_spawning_a_process.yml @@ -1,7 +1,7 @@ name: Detect Regasm Spawning a Process id: 72170ec5-f7d2-42f5-aefb-2b8be6aad15f -version: 8 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -81,7 +81,6 @@ tags: - Snake Keylogger asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regasm_with_network_connection.yml b/detections/endpoint/detect_regasm_with_network_connection.yml index 9b010fad35..803e1d2cc8 100644 --- a/detections/endpoint/detect_regasm_with_network_connection.yml +++ b/detections/endpoint/detect_regasm_with_network_connection.yml @@ -1,7 +1,7 @@ name: Detect Regasm with Network Connection id: 07921114-6db4-4e2e-ae58-3ea8a52ae93f -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - Handala Wiper asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml index 3431b74b40..a04e5c72a0 100644 --- a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Detect Regasm with no Command Line Arguments id: c3bc1430-04e7-4178-835f-047d8e6e97df -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: - Handala Wiper asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regsvcs_spawning_a_process.yml b/detections/endpoint/detect_regsvcs_spawning_a_process.yml index 369fa49db9..72541a45bc 100644 --- a/detections/endpoint/detect_regsvcs_spawning_a_process.yml +++ b/detections/endpoint/detect_regsvcs_spawning_a_process.yml @@ -1,7 +1,7 @@ name: Detect Regsvcs Spawning a Process id: bc477b57-5c21-4ab6-9c33-668772e7f114 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regsvcs_with_network_connection.yml b/detections/endpoint/detect_regsvcs_with_network_connection.yml index 43d8cd8f6f..160e0aad1e 100644 --- a/detections/endpoint/detect_regsvcs_with_network_connection.yml +++ b/detections/endpoint/detect_regsvcs_with_network_connection.yml @@ -1,7 +1,7 @@ name: Detect Regsvcs with Network Connection id: e3e7a1c0-f2b9-445c-8493-f30a63522d1a -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml index c8dfa3767d..79f0ca5b7e 100644 --- a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Detect Regsvcs with No Command Line Arguments id: 6b74d578-a02e-4e94-a0d1-39440d0bf254 -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.009 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml index e2130893c1..a3df354b36 100644 --- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml +++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml @@ -1,7 +1,7 @@ name: Detect Regsvr32 Application Control Bypass id: 070e9b80-6252-11eb-ae93-0242ac130002 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -79,7 +79,6 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.010 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_remote_access_software_usage_file.yml b/detections/endpoint/detect_remote_access_software_usage_file.yml index a9d1005364..25292e24c2 100644 --- a/detections/endpoint/detect_remote_access_software_usage_file.yml +++ b/detections/endpoint/detect_remote_access_software_usage_file.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage File id: 3bf5541a-6a45-4fdc-b01d-59b899fff961 -version: 5 +version: 6 date: '2024-11-13' author: Steven Dick status: production @@ -54,6 +54,10 @@ drilldown_searches: by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate files on $dest$ + search: '| from datamodel:Endpoint.Filesystem | search dest=$dest$ file_name=$file_name$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: A file for known a remote access software [$file_name$] was created on $dest$ by $user$. @@ -67,6 +71,8 @@ rba: threat_objects: - field: file_name type: file_name + - field: signature + type: signature tags: analytic_story: - Insider Threat @@ -74,6 +80,7 @@ tags: - Ransomware - Gozi Malware - CISA AA24-241A + - Remote Monitoring and Management Software asset_type: Endpoint mitre_attack_id: - T1219 diff --git a/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml b/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml index 8286572d72..b1a9ef4f84 100644 --- a/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml +++ b/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage FileInfo id: ccad96d7-a48c-4f13-8b9c-9f6a31cba454 -version: 5 +version: 6 date: '2024-11-13' author: Steven Dick status: production @@ -47,6 +47,10 @@ drilldown_searches: | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate processes on $dest$ + search: '| from datamodel:Endpoint.Processes| search dest=$dest$ process_name=$process_name$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: A file attributes for known a remote access software [$process_name$] was detected on $dest$ @@ -54,15 +58,21 @@ rba: - field: dest type: system score: 25 + - field: user + type: user + score: 25 threat_objects: - field: process_name type: process_name + - field: signature + type: signature tags: analytic_story: - Insider Threat - Command And Control - Ransomware - Gozi Malware + - Remote Monitoring and Management Software asset_type: Endpoint mitre_attack_id: - T1219 diff --git a/detections/endpoint/detect_remote_access_software_usage_process.yml b/detections/endpoint/detect_remote_access_software_usage_process.yml index 8a5dfd6d64..e0417a4071 100644 --- a/detections/endpoint/detect_remote_access_software_usage_process.yml +++ b/detections/endpoint/detect_remote_access_software_usage_process.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage Process id: ffd5e001-2e34-48f4-97a2-26dc4bb08178 -version: 5 +version: 6 date: '2024-11-13' author: Steven Dick status: production @@ -59,6 +59,10 @@ drilldown_searches: by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate processes on $dest$ + search: '| from datamodel:Endpoint.Processes| search dest=$dest$ process_name=$process_name$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: A process for a known remote access software $process_name$ was identified on $dest$. @@ -72,6 +76,8 @@ rba: threat_objects: - field: process_name type: process_name + - field: signature + type: signature tags: analytic_story: - Insider Threat @@ -79,6 +85,7 @@ tags: - Ransomware - Gozi Malware - CISA AA24-241A + - Remote Monitoring and Management Software asset_type: Endpoint mitre_attack_id: - T1219 diff --git a/detections/endpoint/detect_remote_access_software_usage_registry.yml b/detections/endpoint/detect_remote_access_software_usage_registry.yml index 93e927f108..a757b157c9 100644 --- a/detections/endpoint/detect_remote_access_software_usage_registry.yml +++ b/detections/endpoint/detect_remote_access_software_usage_registry.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage Registry id: 33804986-25dd-43cf-bb6b-dc14956c7cbc -version: 2 +version: 3 date: '2025-01-10' author: Steven Dick status: production @@ -60,6 +60,7 @@ tags: - Ransomware - Gozi Malware - CISA AA24-241A + - Remote Monitoring and Management Software asset_type: Endpoint mitre_attack_id: - T1219 diff --git a/detections/endpoint/detect_renamed_7_zip.yml b/detections/endpoint/detect_renamed_7_zip.yml index e2a994e020..62309db2ab 100644 --- a/detections/endpoint/detect_renamed_7_zip.yml +++ b/detections/endpoint/detect_renamed_7_zip.yml @@ -1,7 +1,7 @@ name: Detect Renamed 7-Zip id: 4057291a-b8cf-11eb-95fe-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_renamed_psexec.yml b/detections/endpoint/detect_renamed_psexec.yml index 3b2380accc..27479f9d15 100644 --- a/detections/endpoint/detect_renamed_psexec.yml +++ b/detections/endpoint/detect_renamed_psexec.yml @@ -1,7 +1,7 @@ name: Detect Renamed PSExec id: 683e6196-b8e8-11eb-9a79-acde48001122 -version: 10 -date: '2025-01-27' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk, Alex Oberkircher, Github Community status: production type: Hunting @@ -53,7 +53,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise @@ -63,6 +62,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/detect_renamed_winrar.yml b/detections/endpoint/detect_renamed_winrar.yml index 43af74579c..5c146b775f 100644 --- a/detections/endpoint/detect_renamed_winrar.yml +++ b/detections/endpoint/detect_renamed_winrar.yml @@ -1,7 +1,7 @@ name: Detect Renamed WinRAR id: 1b7bfb2c-b8e6-11eb-99ac-acde48001122 -version: 8 -date: '2025-01-27' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -45,7 +45,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security @@ -54,6 +53,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/detect_rtlo_in_file_name.yml b/detections/endpoint/detect_rtlo_in_file_name.yml index 0754140915..5e65a0dda2 100644 --- a/detections/endpoint/detect_rtlo_in_file_name.yml +++ b/detections/endpoint/detect_rtlo_in_file_name.yml @@ -1,7 +1,7 @@ name: Detect RTLO In File Name id: 468b7e11-d362-43b8-b6ec-7a2d3b246678 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1036.002 - - T1036 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_rtlo_in_process.yml b/detections/endpoint/detect_rtlo_in_process.yml index f9af08e747..c9ee16ee83 100644 --- a/detections/endpoint/detect_rtlo_in_process.yml +++ b/detections/endpoint/detect_rtlo_in_process.yml @@ -1,7 +1,7 @@ name: Detect RTLO In Process id: 22ac27b4-7189-4a4f-9375-b9017c9620d7 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1036.002 - - T1036 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml index 8774c0b8e9..710a02181c 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml @@ -1,7 +1,7 @@ name: Detect Rundll32 Application Control Bypass - advpack id: 4aefadfe-9abd-4bf8-b3fd-867e9ef95bf8 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml index 5870f0e87b..2ee5451c0e 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml @@ -1,7 +1,7 @@ name: Detect Rundll32 Application Control Bypass - setupapi id: 61e7b44a-6088-4f26-b788-9a96ba13b37a -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml index cab866b351..86662d958f 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml @@ -1,7 +1,7 @@ name: Detect Rundll32 Application Control Bypass - syssetup id: 71b9bf37-cde1-45fb-b899-1b0aa6fa1183 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_rundll32_inline_hta_execution.yml b/detections/endpoint/detect_rundll32_inline_hta_execution.yml index 310dee62f4..3a1a84e20a 100644 --- a/detections/endpoint/detect_rundll32_inline_hta_execution.yml +++ b/detections/endpoint/detect_rundll32_inline_hta_execution.yml @@ -1,7 +1,7 @@ name: Detect Rundll32 Inline HTA Execution id: 91c79f14-5b41-11eb-ae93-0242ac130002 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_sharphound_command_line_arguments.yml b/detections/endpoint/detect_sharphound_command_line_arguments.yml index 25d0f48916..f1763e793c 100644 --- a/detections/endpoint/detect_sharphound_command_line_arguments.yml +++ b/detections/endpoint/detect_sharphound_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Detect SharpHound Command-Line Arguments id: a0bdd2f6-c2ff-11eb-b918-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,13 +67,11 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_sharphound_file_modifications.yml b/detections/endpoint/detect_sharphound_file_modifications.yml index 6d6d2d57ee..9054f588ce 100644 --- a/detections/endpoint/detect_sharphound_file_modifications.yml +++ b/detections/endpoint/detect_sharphound_file_modifications.yml @@ -1,7 +1,7 @@ name: Detect SharpHound File Modifications id: 42b4b438-beed-11eb-ba1d-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -64,13 +64,11 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_sharphound_usage.yml b/detections/endpoint/detect_sharphound_usage.yml index 8f75b08dfe..ce759de968 100644 --- a/detections/endpoint/detect_sharphound_usage.yml +++ b/detections/endpoint/detect_sharphound_usage.yml @@ -1,7 +1,7 @@ name: Detect SharpHound Usage id: dd04b29a-beed-11eb-87bc-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,13 +67,11 @@ tags: - Ransomware asset_type: Endpoint mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml b/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml index 6fa1b4cdd0..93af7b9881 100644 --- a/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml +++ b/detections/endpoint/detect_suspicious_processnames_using_pretrained_model_in_dsdl.yml @@ -1,6 +1,6 @@ name: Detect suspicious processnames using pretrained model in DSDL id: a15f8977-ad7d-4669-92ef-b59b97219bf5 -version: 4 +version: 5 date: '2024-11-13' author: Abhinav Mishra, Kumar Sharad and Namratha Sreekanta, Splunk type: Anomaly diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index eb1159dade..307509b731 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -1,7 +1,7 @@ name: Detect Use of cmd exe to Launch Script Interpreters id: b89919ed-fe5f-492c-b139-95dbb162039e -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Bhavin Patel, Mauricio Velazco, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Azorult asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.003 product: - Splunk Enterprise diff --git a/detections/endpoint/detect_wmi_event_subscription_persistence.yml b/detections/endpoint/detect_wmi_event_subscription_persistence.yml index 4ed7920815..5aff76c6d1 100644 --- a/detections/endpoint/detect_wmi_event_subscription_persistence.yml +++ b/detections/endpoint/detect_wmi_event_subscription_persistence.yml @@ -1,7 +1,7 @@ name: Detect WMI Event Subscription Persistence id: 01d9a0c2-cece-11eb-ab46-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.003 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_amsi_through_registry.yml b/detections/endpoint/disable_amsi_through_registry.yml index 4f526be68b..a0ee63d1be 100644 --- a/detections/endpoint/disable_amsi_through_registry.yml +++ b/detections/endpoint/disable_amsi_through_registry.yml @@ -1,7 +1,7 @@ name: Disable AMSI Through Registry id: 9c27ec42-d338-11eb-9044-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_antivirus_registry.yml b/detections/endpoint/disable_defender_antivirus_registry.yml index b73157c4ce..fdd91cef44 100644 --- a/detections/endpoint/disable_defender_antivirus_registry.yml +++ b/detections/endpoint/disable_defender_antivirus_registry.yml @@ -1,7 +1,7 @@ name: Disable Defender AntiVirus Registry id: aa4f695a-3024-11ec-9987-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml index d092f50138..f1289e60a2 100644 --- a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml +++ b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml @@ -1,7 +1,7 @@ name: Disable Defender BlockAtFirstSeen Feature id: 2dd719ac-3021-11ec-97b4-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_enhanced_notification.yml b/detections/endpoint/disable_defender_enhanced_notification.yml index 55022f84b4..6475fe086a 100644 --- a/detections/endpoint/disable_defender_enhanced_notification.yml +++ b/detections/endpoint/disable_defender_enhanced_notification.yml @@ -1,7 +1,7 @@ name: Disable Defender Enhanced Notification id: dc65678c-301f-11ec-8e30-acde48001122 -version: 7 -date: '2025-01-21' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -75,7 +75,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_mpengine_registry.yml b/detections/endpoint/disable_defender_mpengine_registry.yml index e7472c30b0..ce5b547c15 100644 --- a/detections/endpoint/disable_defender_mpengine_registry.yml +++ b/detections/endpoint/disable_defender_mpengine_registry.yml @@ -1,7 +1,7 @@ name: Disable Defender MpEngine Registry id: cc391750-3024-11ec-955a-acde48001122 -version: 9 -date: '2024-12-16' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_spynet_reporting.yml b/detections/endpoint/disable_defender_spynet_reporting.yml index 4c5bffe004..f670dce6cc 100644 --- a/detections/endpoint/disable_defender_spynet_reporting.yml +++ b/detections/endpoint/disable_defender_spynet_reporting.yml @@ -1,7 +1,7 @@ name: Disable Defender Spynet Reporting id: 898debf4-3021-11ec-ba7c-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml index e7286d3d79..3ee864c99c 100644 --- a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml +++ b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml @@ -1,7 +1,7 @@ name: Disable Defender Submit Samples Consent Feature id: 73922ff8-3022-11ec-bf5e-acde48001122 -version: 8 -date: '2024-12-16' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_etw_through_registry.yml b/detections/endpoint/disable_etw_through_registry.yml index cae93c999b..6aeb854d3b 100644 --- a/detections/endpoint/disable_etw_through_registry.yml +++ b/detections/endpoint/disable_etw_through_registry.yml @@ -1,7 +1,7 @@ name: Disable ETW Through Registry id: f0eacfa4-d33f-11eb-8f9d-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_logs_using_wevtutil.yml b/detections/endpoint/disable_logs_using_wevtutil.yml index 33e17afd7d..434b6452ec 100644 --- a/detections/endpoint/disable_logs_using_wevtutil.yml +++ b/detections/endpoint/disable_logs_using_wevtutil.yml @@ -1,7 +1,7 @@ name: Disable Logs Using WevtUtil id: 236e7c8e-c9d9-11eb-a824-acde48001122 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1070 - T1070.001 product: - Splunk Enterprise diff --git a/detections/endpoint/disable_registry_tool.yml b/detections/endpoint/disable_registry_tool.yml index b75eca4b3c..ce3b191378 100644 --- a/detections/endpoint/disable_registry_tool.yml +++ b/detections/endpoint/disable_registry_tool.yml @@ -1,7 +1,7 @@ name: Disable Registry Tool id: cd2cf33c-9201-11eb-a10a-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -58,9 +58,8 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1562.001 - - T1562 - T1112 + - T1562.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_schedule_task.yml b/detections/endpoint/disable_schedule_task.yml index 4474a3fc1d..43abf6fe4d 100644 --- a/detections/endpoint/disable_schedule_task.yml +++ b/detections/endpoint/disable_schedule_task.yml @@ -1,7 +1,7 @@ name: Disable Schedule Task id: db596056-3019-11ec-a9ff-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_show_hidden_files.yml b/detections/endpoint/disable_show_hidden_files.yml index 8cf133efe2..f2851fcdf0 100644 --- a/detections/endpoint/disable_show_hidden_files.yml +++ b/detections/endpoint/disable_show_hidden_files.yml @@ -1,7 +1,7 @@ name: Disable Show Hidden Files id: 6f3ccfa2-91fe-11eb-8f9b-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: Anomaly @@ -58,11 +58,9 @@ tags: - Azorult asset_type: Endpoint mitre_attack_id: - - T1564.001 - - T1562.001 - - T1564 - - T1562 - T1112 + - T1562.001 + - T1564.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_uac_remote_restriction.yml b/detections/endpoint/disable_uac_remote_restriction.yml index 9ca80568c7..5f4ae2f4db 100644 --- a/detections/endpoint/disable_uac_remote_restriction.yml +++ b/detections/endpoint/disable_uac_remote_restriction.yml @@ -1,7 +1,7 @@ name: Disable UAC Remote Restriction id: 9928b732-210e-11ec-b65e-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_windows_app_hotkeys.yml b/detections/endpoint/disable_windows_app_hotkeys.yml index 0edb9bc907..61d89307c0 100644 --- a/detections/endpoint/disable_windows_app_hotkeys.yml +++ b/detections/endpoint/disable_windows_app_hotkeys.yml @@ -1,7 +1,7 @@ name: Disable Windows App Hotkeys id: 1490f224-ad8b-11eb-8c4f-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -57,9 +57,8 @@ tags: - Windows Registry Abuse asset_type: Endpoint mitre_attack_id: - - T1562.001 - - T1562 - T1112 + - T1562.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index 07d891b9b9..ff1af8433e 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -1,7 +1,7 @@ name: Disable Windows Behavior Monitoring id: 79439cae-9200-11eb-a4d3-acde48001122 -version: 10 -date: '2024-12-08' +version: 11 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_windows_smartscreen_protection.yml b/detections/endpoint/disable_windows_smartscreen_protection.yml index 88d052f10e..d804b2c8d0 100644 --- a/detections/endpoint/disable_windows_smartscreen_protection.yml +++ b/detections/endpoint/disable_windows_smartscreen_protection.yml @@ -1,7 +1,7 @@ name: Disable Windows SmartScreen Protection id: 664f0fd0-91ff-11eb-a56f-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml index 1606e574da..2aeb701771 100644 --- a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml +++ b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml @@ -1,7 +1,7 @@ name: Disabled Kerberos Pre-Authentication Discovery With Get-ADUser id: 114c6bfe-9406-11ec-bcce-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.004 product: - Splunk Enterprise diff --git a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml index e5ac20f37f..b5464753fe 100644 --- a/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml +++ b/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml @@ -1,7 +1,7 @@ name: Disabled Kerberos Pre-Authentication Discovery With PowerView id: b0b34e2c-90de-11ec-baeb-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -53,7 +53,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.004 product: - Splunk Enterprise diff --git a/detections/endpoint/disabling_cmd_application.yml b/detections/endpoint/disabling_cmd_application.yml index d35acced16..2a96b3b449 100644 --- a/detections/endpoint/disabling_cmd_application.yml +++ b/detections/endpoint/disabling_cmd_application.yml @@ -1,7 +1,7 @@ name: Disabling CMD Application id: ff86077c-9212-11eb-a1e6-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -60,9 +60,8 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1562.001 - - T1562 - T1112 + - T1562.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_controlpanel.yml b/detections/endpoint/disabling_controlpanel.yml index c6428e5197..7225cef46f 100644 --- a/detections/endpoint/disabling_controlpanel.yml +++ b/detections/endpoint/disabling_controlpanel.yml @@ -1,7 +1,7 @@ name: Disabling ControlPanel id: 6ae0148e-9215-11eb-a94a-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -60,9 +60,8 @@ tags: - Windows Registry Abuse asset_type: Endpoint mitre_attack_id: - - T1562.001 - - T1562 - T1112 + - T1562.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_defender_services.yml b/detections/endpoint/disabling_defender_services.yml index d9432952f5..c8fc943b34 100644 --- a/detections/endpoint/disabling_defender_services.yml +++ b/detections/endpoint/disabling_defender_services.yml @@ -1,7 +1,7 @@ name: Disabling Defender Services id: 911eacdc-317f-11ec-ad30-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_firewall_with_netsh.yml b/detections/endpoint/disabling_firewall_with_netsh.yml index d2cf8713d8..c5d95d266a 100644 --- a/detections/endpoint/disabling_firewall_with_netsh.yml +++ b/detections/endpoint/disabling_firewall_with_netsh.yml @@ -1,7 +1,7 @@ name: Disabling Firewall with Netsh id: 6860a62c-9203-11eb-9e05-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_folderoptions_windows_feature.yml b/detections/endpoint/disabling_folderoptions_windows_feature.yml index 1025506d70..572e1550d2 100644 --- a/detections/endpoint/disabling_folderoptions_windows_feature.yml +++ b/detections/endpoint/disabling_folderoptions_windows_feature.yml @@ -1,7 +1,7 @@ name: Disabling FolderOptions Windows Feature id: 83776de4-921a-11eb-868a-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_norun_windows_app.yml b/detections/endpoint/disabling_norun_windows_app.yml index 793a6f7540..28ad2e6afa 100644 --- a/detections/endpoint/disabling_norun_windows_app.yml +++ b/detections/endpoint/disabling_norun_windows_app.yml @@ -1,7 +1,7 @@ name: Disabling NoRun Windows App id: de81bc46-9213-11eb-adc9-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -60,9 +60,8 @@ tags: - Windows Registry Abuse asset_type: Endpoint mitre_attack_id: - - T1562.001 - - T1562 - T1112 + - T1562.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_remote_user_account_control.yml b/detections/endpoint/disabling_remote_user_account_control.yml index cac14cea20..e1729e4fee 100644 --- a/detections/endpoint/disabling_remote_user_account_control.yml +++ b/detections/endpoint/disabling_remote_user_account_control.yml @@ -1,7 +1,7 @@ name: Disabling Remote User Account Control id: bbc644bc-37df-4e1a-9c88-ec9a53e2038c -version: 8 -date: '2024-12-16' +version: 9 +date: '2025-02-10' author: David Dorsey, Patrick Bareiss, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disabling_task_manager.yml b/detections/endpoint/disabling_task_manager.yml index 218bab32c0..0cd9db8bc1 100644 --- a/detections/endpoint/disabling_task_manager.yml +++ b/detections/endpoint/disabling_task_manager.yml @@ -1,7 +1,7 @@ name: Disabling Task Manager id: dac279bc-9202-11eb-b7fb-acde48001122 -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml index a244b2a733..9e42a31685 100644 --- a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml +++ b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml @@ -1,6 +1,6 @@ name: DNS Exfiltration Using Nslookup App id: 2452e632-9e0d-11eb-bacd-acde48001122 -version: 7 +version: 8 date: '2024-12-10' author: Teoderick Contreras, Splunk, Wouter Jansen status: production diff --git a/detections/endpoint/domain_account_discovery_with_dsquery.yml b/detections/endpoint/domain_account_discovery_with_dsquery.yml index cde94f4d78..73c4f00bf2 100644 --- a/detections/endpoint/domain_account_discovery_with_dsquery.yml +++ b/detections/endpoint/domain_account_discovery_with_dsquery.yml @@ -1,7 +1,7 @@ name: Domain Account Discovery with Dsquery id: b1a8ce04-04c2-11ec-bea7-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index d374d2851a..5997c315cc 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -1,7 +1,7 @@ name: Domain Account Discovery with Wmic id: 383572e0-04c5-11ec-bdcc-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/domain_group_discovery_with_adsisearcher.yml b/detections/endpoint/domain_group_discovery_with_adsisearcher.yml index e1abeaa0b5..7e402f9632 100644 --- a/detections/endpoint/domain_group_discovery_with_adsisearcher.yml +++ b/detections/endpoint/domain_group_discovery_with_adsisearcher.yml @@ -1,7 +1,7 @@ name: Domain Group Discovery with Adsisearcher id: 089c862f-5f83-49b5-b1c8-7e4ff66560c7 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -53,7 +53,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/domain_group_discovery_with_dsquery.yml b/detections/endpoint/domain_group_discovery_with_dsquery.yml index 1ab2a63c77..3c80940d89 100644 --- a/detections/endpoint/domain_group_discovery_with_dsquery.yml +++ b/detections/endpoint/domain_group_discovery_with_dsquery.yml @@ -1,7 +1,7 @@ name: Domain Group Discovery With Dsquery id: f0c9d62f-a232-4edd-b17e-bc409fb133d4 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -40,7 +40,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/domain_group_discovery_with_wmic.yml b/detections/endpoint/domain_group_discovery_with_wmic.yml index 77e3b1886c..0ea13c9e66 100644 --- a/detections/endpoint/domain_group_discovery_with_wmic.yml +++ b/detections/endpoint/domain_group_discovery_with_wmic.yml @@ -1,7 +1,7 @@ name: Domain Group Discovery With Wmic id: a87736a6-95cd-4728-8689-3c64d5026b3e -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -40,7 +40,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/drop_icedid_license_dat.yml b/detections/endpoint/drop_icedid_license_dat.yml index 12460ee148..c5232b8655 100644 --- a/detections/endpoint/drop_icedid_license_dat.yml +++ b/detections/endpoint/drop_icedid_license_dat.yml @@ -1,7 +1,7 @@ name: Drop IcedID License dat id: b7a045fc-f14a-11eb-8e79-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -31,7 +31,6 @@ tags: - IcedID asset_type: Endpoint mitre_attack_id: - - T1204 - T1204.002 product: - Splunk Enterprise diff --git a/detections/endpoint/dsquery_domain_discovery.yml b/detections/endpoint/dsquery_domain_discovery.yml index 3ee0399230..72e21dfb8e 100644 --- a/detections/endpoint/dsquery_domain_discovery.yml +++ b/detections/endpoint/dsquery_domain_discovery.yml @@ -1,6 +1,6 @@ name: DSQuery Domain Discovery id: cc316032-924a-11eb-91a2-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml index ea6d606030..7199fc7352 100644 --- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml +++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml @@ -1,7 +1,7 @@ name: Dump LSASS via comsvcs DLL id: 8943b567-f14d-4ee8-a0bb-2121d4ce3184 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -84,7 +84,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/dump_lsass_via_procdump.yml b/detections/endpoint/dump_lsass_via_procdump.yml index 56b38267ec..18d9cc1aa4 100644 --- a/detections/endpoint/dump_lsass_via_procdump.yml +++ b/detections/endpoint/dump_lsass_via_procdump.yml @@ -1,7 +1,7 @@ name: Dump LSASS via procdump id: 3742ebfe-64c2-11eb-ae93-0242ac130002 -version: 8 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/elevated_group_discovery_with_powerview.yml b/detections/endpoint/elevated_group_discovery_with_powerview.yml index 1493676285..6b8427834e 100644 --- a/detections/endpoint/elevated_group_discovery_with_powerview.yml +++ b/detections/endpoint/elevated_group_discovery_with_powerview.yml @@ -1,7 +1,7 @@ name: Elevated Group Discovery with PowerView id: 10d62950-0de5-4199-a710-cff9ea79b413 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -35,7 +35,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/elevated_group_discovery_with_wmic.yml b/detections/endpoint/elevated_group_discovery_with_wmic.yml index 3c74c3e9ca..d06e82db3f 100644 --- a/detections/endpoint/elevated_group_discovery_with_wmic.yml +++ b/detections/endpoint/elevated_group_discovery_with_wmic.yml @@ -1,7 +1,7 @@ name: Elevated Group Discovery With Wmic id: 3f6bbf22-093e-4cb4-9641-83f47b8444b6 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/esentutl_sam_copy.yml b/detections/endpoint/esentutl_sam_copy.yml index cf7ea2b703..b4f247be75 100644 --- a/detections/endpoint/esentutl_sam_copy.yml +++ b/detections/endpoint/esentutl_sam_copy.yml @@ -1,7 +1,7 @@ name: Esentutl SAM Copy id: d372f928-ce4f-11eb-a762-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/etw_registry_disabled.yml b/detections/endpoint/etw_registry_disabled.yml index e001bbdc5b..c2be3b0a81 100644 --- a/detections/endpoint/etw_registry_disabled.yml +++ b/detections/endpoint/etw_registry_disabled.yml @@ -1,7 +1,7 @@ name: ETW Registry Disabled id: 8ed523ac-276b-11ec-ac39-acde48001122 -version: 9 -date: '2024-12-16' +version: 11 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -64,9 +64,8 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1562.006 - T1127 - - T1562 + - T1562.006 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/eventvwr_uac_bypass.yml b/detections/endpoint/eventvwr_uac_bypass.yml index d86cc12b72..87c438a3b5 100644 --- a/detections/endpoint/eventvwr_uac_bypass.yml +++ b/detections/endpoint/eventvwr_uac_bypass.yml @@ -1,7 +1,7 @@ name: Eventvwr UAC Bypass id: 9cf8fe08-7ad8-11eb-9819-acde48001122 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Steven Dick, Michael Haag, Splunk status: production type: TTP @@ -78,7 +78,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml index 87384b30be..8e55318d13 100644 --- a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml +++ b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml @@ -1,7 +1,7 @@ name: Excessive number of service control start as disabled id: 77592bec-d5cc-11eb-9e60-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Hart, Splunk status: production type: Anomaly @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excessive_usage_of_sc_service_utility.yml b/detections/endpoint/excessive_usage_of_sc_service_utility.yml index bf447f6818..a7cbd28e9d 100644 --- a/detections/endpoint/excessive_usage_of_sc_service_utility.yml +++ b/detections/endpoint/excessive_usage_of_sc_service_utility.yml @@ -1,7 +1,7 @@ name: Excessive Usage Of SC Service Utility id: cb6b339e-d4c6-11eb-a026-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise diff --git a/detections/endpoint/excessive_usage_of_taskkill.yml b/detections/endpoint/excessive_usage_of_taskkill.yml index 14669e1cab..58c6c1d2c6 100644 --- a/detections/endpoint/excessive_usage_of_taskkill.yml +++ b/detections/endpoint/excessive_usage_of_taskkill.yml @@ -1,7 +1,7 @@ name: Excessive Usage Of Taskkill id: fe5bca48-accb-11eb-a67c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/exchange_powershell_module_usage.yml b/detections/endpoint/exchange_powershell_module_usage.yml index 0f67e57eea..a4a976b447 100644 --- a/detections/endpoint/exchange_powershell_module_usage.yml +++ b/detections/endpoint/exchange_powershell_module_usage.yml @@ -1,7 +1,7 @@ name: Exchange PowerShell Module Usage id: 2d10095e-05ae-11ec-8fdf-acde48001122 -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: - CISA AA22-264A asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml index b86556c3ad..17986ee585 100644 --- a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml +++ b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml @@ -1,7 +1,7 @@ name: Executable File Written in Administrative SMB Share id: f63c34fe-a435-11eb-935a-acde48001122 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: - Trickbot asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.002 product: - Splunk Enterprise diff --git a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml index d389a1626f..7099216131 100644 --- a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml +++ b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml @@ -1,7 +1,7 @@ name: Execute Javascript With Jscript COM CLSID id: dc64d064-d346-11eb-8588-acde48001122 -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: - Ransomware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.005 product: - Splunk Enterprise diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index 306a367e2b..c7c46d2a00 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -1,7 +1,7 @@ name: Execution of File with Multiple Extensions id: b06a555e-dce0-417d-a2eb-28a5d8d66ef7 -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Rico Valdez, Teoderick Contreras, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: - DarkGate Malware asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.003 product: - Splunk Enterprise diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml index 0d86b46dcd..f09d658da1 100644 --- a/detections/endpoint/file_with_samsam_extension.yml +++ b/detections/endpoint/file_with_samsam_extension.yml @@ -1,6 +1,6 @@ name: File with Samsam Extension id: 02c6cfc2-ae66-4735-bfc7-6291da834cbf -version: 5 +version: 6 date: '2024-11-13' author: Rico Valdez, Splunk status: production diff --git a/detections/endpoint/firewall_allowed_program_enable.yml b/detections/endpoint/firewall_allowed_program_enable.yml index 39966aac74..11f599d75e 100644 --- a/detections/endpoint/firewall_allowed_program_enable.yml +++ b/detections/endpoint/firewall_allowed_program_enable.yml @@ -1,7 +1,7 @@ name: Firewall Allowed Program Enable id: 9a8f63a8-43ac-11ec-904c-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/first_time_seen_running_windows_service.yml b/detections/endpoint/first_time_seen_running_windows_service.yml index 8576de1a20..70ca621bf7 100644 --- a/detections/endpoint/first_time_seen_running_windows_service.yml +++ b/detections/endpoint/first_time_seen_running_windows_service.yml @@ -1,7 +1,7 @@ name: First Time Seen Running Windows Service id: 823136f2-d755-4b6d-ae04-372b486a5808 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -46,7 +46,6 @@ tags: - NOBELIUM Group asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise diff --git a/detections/endpoint/fodhelper_uac_bypass.yml b/detections/endpoint/fodhelper_uac_bypass.yml index b1be122909..643bf866c4 100644 --- a/detections/endpoint/fodhelper_uac_bypass.yml +++ b/detections/endpoint/fodhelper_uac_bypass.yml @@ -1,7 +1,7 @@ name: FodHelper UAC Bypass id: 909f8fd8-7ac8-11eb-a1f3-acde48001122 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: mitre_attack_id: - T1112 - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_aduser_with_powershell.yml b/detections/endpoint/get_aduser_with_powershell.yml index 1c21e48521..19c5c4c847 100644 --- a/detections/endpoint/get_aduser_with_powershell.yml +++ b/detections/endpoint/get_aduser_with_powershell.yml @@ -1,7 +1,7 @@ name: Get ADUser with PowerShell id: 0b6ee3f4-04e3-11ec-a87d-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Hunting @@ -45,7 +45,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_aduser_with_powershell_script_block.yml b/detections/endpoint/get_aduser_with_powershell_script_block.yml index ecdc645ace..4ea837065c 100644 --- a/detections/endpoint/get_aduser_with_powershell_script_block.yml +++ b/detections/endpoint/get_aduser_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: Get ADUser with PowerShell Script Block id: 21432e40-04f4-11ec-b7e6-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Hunting @@ -34,7 +34,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml index f6f9362eb3..b7844e4976 100644 --- a/detections/endpoint/get_domainuser_with_powershell.yml +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -1,7 +1,7 @@ name: Get DomainUser with PowerShell id: 9a5a41d6-04e7-11ec-923c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_domainuser_with_powershell_script_block.yml b/detections/endpoint/get_domainuser_with_powershell_script_block.yml index 8b3e401a5a..9fb765be7e 100644 --- a/detections/endpoint/get_domainuser_with_powershell_script_block.yml +++ b/detections/endpoint/get_domainuser_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: Get DomainUser with PowerShell Script Block id: 61994268-04f4-11ec-865c-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/get_wmiobject_group_discovery.yml b/detections/endpoint/get_wmiobject_group_discovery.yml index ca6601298b..eb0c67807c 100644 --- a/detections/endpoint/get_wmiobject_group_discovery.yml +++ b/detections/endpoint/get_wmiobject_group_discovery.yml @@ -1,7 +1,7 @@ name: Get WMIObject Group Discovery id: 5434f670-155d-11ec-8cca-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml b/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml index 04fa251a96..b6b6ec3604 100644 --- a/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml +++ b/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml @@ -1,7 +1,7 @@ name: Get WMIObject Group Discovery with Script Block Logging id: 69df7f7c-155d-11ec-a055-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -34,7 +34,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/endpoint/getadgroup_with_powershell.yml b/detections/endpoint/getadgroup_with_powershell.yml index d381b71e36..8f87c04925 100644 --- a/detections/endpoint/getadgroup_with_powershell.yml +++ b/detections/endpoint/getadgroup_with_powershell.yml @@ -1,7 +1,7 @@ name: GetAdGroup with PowerShell id: 872e3063-0fc4-4e68-b2f3-f2b99184a708 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getadgroup_with_powershell_script_block.yml b/detections/endpoint/getadgroup_with_powershell_script_block.yml index 0e2b7f09ef..5f765ba70b 100644 --- a/detections/endpoint/getadgroup_with_powershell_script_block.yml +++ b/detections/endpoint/getadgroup_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetAdGroup with PowerShell Script Block id: e4c73d68-794b-468d-b4d0-dac1772bbae7 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -31,7 +31,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getdomaingroup_with_powershell.yml b/detections/endpoint/getdomaingroup_with_powershell.yml index 85f7f11b3e..8c01054c4b 100644 --- a/detections/endpoint/getdomaingroup_with_powershell.yml +++ b/detections/endpoint/getdomaingroup_with_powershell.yml @@ -1,7 +1,7 @@ name: GetDomainGroup with PowerShell id: 93c94be3-bead-4a60-860f-77ca3fe59903 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getdomaingroup_with_powershell_script_block.yml b/detections/endpoint/getdomaingroup_with_powershell_script_block.yml index 913dbacb5e..bad857a4c9 100644 --- a/detections/endpoint/getdomaingroup_with_powershell_script_block.yml +++ b/detections/endpoint/getdomaingroup_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetDomainGroup with PowerShell Script Block id: 09725404-a44f-4ed3-9efa-8ed5d69e4c53 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -52,7 +52,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getlocaluser_with_powershell.yml b/detections/endpoint/getlocaluser_with_powershell.yml index 690b834301..7819e2520b 100644 --- a/detections/endpoint/getlocaluser_with_powershell.yml +++ b/detections/endpoint/getlocaluser_with_powershell.yml @@ -1,7 +1,7 @@ name: GetLocalUser with PowerShell id: 85fae8fa-0427-11ec-8b78-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/endpoint/getlocaluser_with_powershell_script_block.yml b/detections/endpoint/getlocaluser_with_powershell_script_block.yml index 754d2cadae..5e8423446f 100644 --- a/detections/endpoint/getlocaluser_with_powershell_script_block.yml +++ b/detections/endpoint/getlocaluser_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetLocalUser with PowerShell Script Block id: 2e891cbe-0426-11ec-9c9c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -33,9 +33,8 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1087 - - T1087.001 - T1059.001 + - T1087.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml index 11b144c48c..f0dc6262b2 100644 --- a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml @@ -1,7 +1,7 @@ name: GetWmiObject Ds Group with PowerShell id: df275a44-4527-443b-b884-7600e066e3eb -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml index 5dcd4326a6..36a64083ac 100644 --- a/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetWmiObject Ds Group with PowerShell Script Block id: 67740bd3-1506-469c-b91d-effc322cc6e5 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -53,7 +53,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml index 5cd432dcaa..eeb6e39b17 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -1,7 +1,7 @@ name: GetWmiObject DS User with PowerShell id: 22d3b118-04df-11ec-8fa3-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml index ac5f12c52e..ab9fdb89c4 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetWmiObject DS User with PowerShell Script Block id: fabd364e-04f3-11ec-b34b-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/getwmiobject_user_account_with_powershell.yml b/detections/endpoint/getwmiobject_user_account_with_powershell.yml index 0c6134ae47..8733ba54ea 100644 --- a/detections/endpoint/getwmiobject_user_account_with_powershell.yml +++ b/detections/endpoint/getwmiobject_user_account_with_powershell.yml @@ -1,7 +1,7 @@ name: GetWmiObject User Account with PowerShell id: b44f6ac6-0429-11ec-87e9-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml index 1a5ed182ed..8677fb28ab 100644 --- a/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml @@ -1,7 +1,7 @@ name: GetWmiObject User Account with PowerShell Script Block id: 640b0eda-0429-11ec-accd-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -32,9 +32,8 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1087 - - T1087.001 - T1059.001 + - T1087.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml index c60512b788..46ab4b2a2e 100644 --- a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml @@ -1,6 +1,6 @@ name: GPUpdate with no Command Line Arguments with Network id: 2c853856-a140-11eb-a5b5-acde48001122 -version: 7 +version: 8 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml b/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml index a5a0e59b2d..6d6557e0ab 100644 --- a/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml +++ b/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml @@ -1,6 +1,6 @@ name: Headless Browser Mockbin or Mocky Request id: 94fc85a1-e55b-4265-95e1-4b66730e05c0 -version: 4 +version: 5 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/hide_user_account_from_sign_in_screen.yml b/detections/endpoint/hide_user_account_from_sign_in_screen.yml index 8d27a673ad..1a4035b651 100644 --- a/detections/endpoint/hide_user_account_from_sign_in_screen.yml +++ b/detections/endpoint/hide_user_account_from_sign_in_screen.yml @@ -1,7 +1,7 @@ name: Hide User Account From Sign-In Screen id: 834ba832-ad89-11eb-937d-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index c95af49a98..9e314746a6 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -1,7 +1,7 @@ name: Hiding Files And Directories With Attrib exe id: 6e5a3ae4-90a3-462d-9aa6-0119f638c0f1 -version: 9 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1222 - T1222.001 product: - Splunk Enterprise diff --git a/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml b/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml index d0965e6ffb..2a4a093612 100644 --- a/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml +++ b/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml @@ -1,7 +1,7 @@ name: IcedID Exfiltrated Archived File Creation id: 0db4da70-f14b-11eb-8043-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -34,7 +34,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml index 67d36cf818..7325419b34 100644 --- a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Impacket Lateral Movement Commandline Parameters id: 8ce07472-496f-11ec-ab3b-3e22fbd008af -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -82,7 +82,6 @@ tags: - CISA AA22-277A asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.002 - T1021.003 - T1047 diff --git a/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml index b48dcbbc37..5bc432054e 100644 --- a/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Impacket Lateral Movement smbexec CommandLine Parameters id: bb3c1bac-6bdf-4aa0-8dc9-068b8b712a76 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -83,7 +83,6 @@ tags: asset_type: Endpoint atomic_guid: [] mitre_attack_id: - - T1021 - T1021.002 - T1021.003 - T1047 diff --git a/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml index 7965e0f409..9e48d7ea19 100644 --- a/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Impacket Lateral Movement WMIExec Commandline Parameters id: d6e464e4-5c6a-474e-82d2-aed616a3a492 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -83,7 +83,6 @@ tags: asset_type: Endpoint atomic_guid: [] mitre_attack_id: - - T1021 - T1021.002 - T1021.003 - T1047 diff --git a/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml b/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml index a096091412..4e56391427 100644 --- a/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml +++ b/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml @@ -1,7 +1,7 @@ name: Interactive Session on Remote Endpoint with PowerShell id: a4e8f3a4-48b2-11ec-bcfc-3e22fbd008af -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.006 product: - Splunk Enterprise diff --git a/detections/endpoint/jscript_execution_using_cscript_app.yml b/detections/endpoint/jscript_execution_using_cscript_app.yml index a88bd5debd..94f26c5e5f 100644 --- a/detections/endpoint/jscript_execution_using_cscript_app.yml +++ b/detections/endpoint/jscript_execution_using_cscript_app.yml @@ -1,7 +1,7 @@ name: Jscript Execution Using Cscript App id: 002f1e24-146e-11ec-a470-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: - Remcos asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.007 product: - Splunk Enterprise diff --git a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml index 948d171659..57f2076b4c 100644 --- a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml +++ b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml @@ -1,7 +1,7 @@ name: Kerberoasting spn request with RC4 encryption id: 5cc67381-44fa-4111-8a37-7a230943f027 -version: 9 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Jose Hernandez, Patrick Bareiss, Mauricio Velazco, Dean Luxton, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Hermetic Wiper asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.003 product: - Splunk Enterprise diff --git a/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml b/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml index f5d8ed8cf8..748fef94bf 100644 --- a/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml +++ b/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml @@ -1,7 +1,7 @@ name: Kerberos Pre-Authentication Flag Disabled in UserAccountControl id: 0cb847ee-9423-11ec-b2df-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -16,7 +16,8 @@ description: The following analytic detects when the Kerberos Pre-Authentication data_source: - Windows Event Log Security 4738 search: > - `wineventlog_security` EventCode=4738 MSADChangedAttributes="*\'Don\'t Require Preauth\' - Enabled*" |rename Account_Name as user | table EventCode, user, dest, Security_ID, + `wineventlog_security` EventCode=4738 MSADChangedAttributes="*\'Don\'t Require Preauth\' + - Enabled*" |rename Account_Name as user | table EventCode, user, dest, Security_ID, MSADChangedAttributes | `kerberos_pre_authentication_flag_disabled_in_useraccountcontrol_filter` how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller events. The Advanced Security Audit policy setting `User Account @@ -53,7 +54,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.004 product: - Splunk Enterprise diff --git a/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml b/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml index bc3d94ee68..67814fc234 100644 --- a/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml +++ b/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml @@ -1,7 +1,7 @@ name: Kerberos Pre-Authentication Flag Disabled with PowerShell id: 59b51620-94c9-11ec-b3d5-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.004 product: - Splunk Enterprise diff --git a/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml b/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml index d667d529f4..768d5fe2e6 100644 --- a/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml +++ b/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml @@ -1,7 +1,7 @@ name: Kerberos Service Ticket Request Using RC4 Encryption id: 7d90f334-a482-11ec-908c-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: - Active Directory Privilege Escalation asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.001 product: - Splunk Enterprise diff --git a/detections/endpoint/kerberos_user_enumeration.yml b/detections/endpoint/kerberos_user_enumeration.yml index 570a014a73..e5b80a4cea 100644 --- a/detections/endpoint/kerberos_user_enumeration.yml +++ b/detections/endpoint/kerberos_user_enumeration.yml @@ -1,7 +1,7 @@ name: Kerberos User Enumeration id: d82d4af4-a0bd-11ec-9445-3e22fbd008af -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Anomaly @@ -55,7 +55,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1589 - T1589.002 product: - Splunk Enterprise diff --git a/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml b/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml index 70069801ef..8728599618 100644 --- a/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml +++ b/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml @@ -1,7 +1,7 @@ name: Linux Account Manipulation Of SSH Config and Keys id: 73a56508-1cf5-4df7-b8d9-5737fbdc27d2 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -55,9 +55,8 @@ tags: - AcidRain asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_add_files_in_known_crontab_directories.yml b/detections/endpoint/linux_add_files_in_known_crontab_directories.yml index 5ac49389a5..7c5f666cd9 100644 --- a/detections/endpoint/linux_add_files_in_known_crontab_directories.yml +++ b/detections/endpoint/linux_add_files_in_known_crontab_directories.yml @@ -1,7 +1,7 @@ name: Linux Add Files In Known Crontab Directories id: 023f3452-5f27-11ec-bf00-acde48001122 -version: 5 -date: '2024-12-19' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_add_user_account.yml b/detections/endpoint/linux_add_user_account.yml index 3685c49b94..3c798ae4cb 100644 --- a/detections/endpoint/linux_add_user_account.yml +++ b/detections/endpoint/linux_add_user_account.yml @@ -1,7 +1,7 @@ name: Linux Add User Account id: 51fbcaf2-6259-11ec-b0f3-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -40,7 +40,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_adding_crontab_using_list_parameter.yml b/detections/endpoint/linux_adding_crontab_using_list_parameter.yml index 8bdc8a8822..7f05ba1ab8 100644 --- a/detections/endpoint/linux_adding_crontab_using_list_parameter.yml +++ b/detections/endpoint/linux_adding_crontab_using_list_parameter.yml @@ -1,7 +1,7 @@ name: Linux Adding Crontab Using List Parameter id: 52f6d751-1fd4-4c74-a4c9-777ecfeb5c58 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -47,7 +47,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_apt_get_privilege_escalation.yml b/detections/endpoint/linux_apt_get_privilege_escalation.yml index 7924c146e3..0dd8a1971a 100644 --- a/detections/endpoint/linux_apt_get_privilege_escalation.yml +++ b/detections/endpoint/linux_apt_get_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux apt-get Privilege Escalation id: d870ce3b-e796-402f-b2af-cab4da1223f2 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_apt_privilege_escalation.yml b/detections/endpoint/linux_apt_privilege_escalation.yml index 7f6804cbfb..b663f74c24 100644 --- a/detections/endpoint/linux_apt_privilege_escalation.yml +++ b/detections/endpoint/linux_apt_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux APT Privilege Escalation id: 4d5a05fa-77d9-4fd0-af9c-05704f9f9a88 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_at_allow_config_file_creation.yml b/detections/endpoint/linux_at_allow_config_file_creation.yml index 732c20f5b7..ae556ae740 100644 --- a/detections/endpoint/linux_at_allow_config_file_creation.yml +++ b/detections/endpoint/linux_at_allow_config_file_creation.yml @@ -1,7 +1,7 @@ name: Linux At Allow Config File Creation id: 977b3082-5f3d-11ec-b954-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_at_application_execution.yml b/detections/endpoint/linux_at_application_execution.yml index 3cd126c6ca..6666181369 100644 --- a/detections/endpoint/linux_at_application_execution.yml +++ b/detections/endpoint/linux_at_application_execution.yml @@ -1,7 +1,7 @@ name: Linux At Application Execution id: bf0a378e-5f3c-11ec-a6de-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.002 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_add_user_account.yml b/detections/endpoint/linux_auditd_add_user_account.yml index 900f4b6a4e..c29d67571e 100644 --- a/detections/endpoint/linux_auditd_add_user_account.yml +++ b/detections/endpoint/linux_auditd_add_user_account.yml @@ -1,7 +1,7 @@ name: Linux Auditd Add User Account id: aae66dc0-74b4-4807-b480-b35f8027abb4 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_add_user_account_type.yml b/detections/endpoint/linux_auditd_add_user_account_type.yml index 929dd08741..7bf00799da 100644 --- a/detections/endpoint/linux_auditd_add_user_account_type.yml +++ b/detections/endpoint/linux_auditd_add_user_account_type.yml @@ -1,7 +1,7 @@ name: Linux Auditd Add User Account Type id: f8c325ea-506e-4105-8ccf-da1492e90115 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: - Compromised Linux Host asset_type: Endpoint mitre_attack_id: - - T1136 - T1136.001 product: - Splunk Enterprise diff --git a/detections/endpoint/linux_auditd_at_application_execution.yml b/detections/endpoint/linux_auditd_at_application_execution.yml index da29fe7c02..e9c76689ff 100644 --- a/detections/endpoint/linux_auditd_at_application_execution.yml +++ b/detections/endpoint/linux_auditd_at_application_execution.yml @@ -1,7 +1,7 @@ name: Linux Auditd At Application Execution id: 9f306e0a-1c36-469e-8892-968ca12470dd -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.002 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_change_file_owner_to_root.yml b/detections/endpoint/linux_auditd_change_file_owner_to_root.yml index a45a65d0f8..b4733004c9 100644 --- a/detections/endpoint/linux_auditd_change_file_owner_to_root.yml +++ b/detections/endpoint/linux_auditd_change_file_owner_to_root.yml @@ -1,16 +1,35 @@ name: Linux Auditd Change File Owner To Root id: 7b87c556-0ca4-47e0-b84c-6cd62a0a3e90 -version: 4 -date: '2025-01-20' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects the use of the 'chown' command to change a file owner to 'root' on a Linux system. It leverages Linux Auditd telemetry, specifically monitoring command-line executions and process details. This activity is significant as it may indicate an attempt to escalate privileges by adversaries, malware, or red teamers. If confirmed malicious, this action could allow an attacker to gain root-level access, leading to full control over the compromised host and potential persistence within the environment. +description: The following analytic detects the use of the 'chown' command to change + a file owner to 'root' on a Linux system. It leverages Linux Auditd telemetry, specifically + monitoring command-line executions and process details. This activity is significant + as it may indicate an attempt to escalate privileges by adversaries, malware, or + red teamers. If confirmed malicious, this action could allow an attacker to gain + root-level access, leading to full control over the compromised host and potential + persistence within the environment. data_source: - Linux Auditd Proctitle -search: '`linux_auditd` `linux_auditd_normalized_proctitle_process`| rename host as dest | where LIKE (process_exec, "%chown %root%") | stats count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_change_file_owner_to_root_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_proctitle_process`| rename host as + dest | where LIKE (process_exec, "%chown %root%") | stats count min(_time) as firstTime + max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter + dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| + `linux_auditd_change_file_owner_to_root_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. references: - https://unix.stackexchange.com/questions/101073/how-to-change-permissions-from-root-user-to-all-users - https://askubuntu.com/questions/617850/changing-from-user-to-superuser @@ -20,7 +39,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -40,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1222.002 - - T1222 product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/linux_auditd_chown_root/linux_auditd_chown_root.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/linux_auditd_chown_root/linux_auditd_chown_root.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml b/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml index 5dfd17febc..a825c4c9fe 100644 --- a/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml +++ b/detections/endpoint/linux_auditd_disable_or_modify_system_firewall.yml @@ -1,7 +1,7 @@ name: Linux Auditd Disable Or Modify System Firewall id: 07052556-d4b5-4bae-89aa-cbdc1bb11250 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_doas_conf_file_creation.yml b/detections/endpoint/linux_auditd_doas_conf_file_creation.yml index 6eea3f2bdf..ce27362871 100644 --- a/detections/endpoint/linux_auditd_doas_conf_file_creation.yml +++ b/detections/endpoint/linux_auditd_doas_conf_file_creation.yml @@ -1,7 +1,7 @@ name: Linux Auditd Doas Conf File Creation id: 61059783-574b-40d2-ac2f-69b898afd6b4 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_doas_tool_execution.yml b/detections/endpoint/linux_auditd_doas_tool_execution.yml index 14483461ca..d955c86264 100644 --- a/detections/endpoint/linux_auditd_doas_tool_execution.yml +++ b/detections/endpoint/linux_auditd_doas_tool_execution.yml @@ -1,7 +1,7 @@ name: Linux Auditd Doas Tool Execution id: 91b8ca78-f205-4826-a3ef-cd8d6b24e97b -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml b/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml index abcf36a2c5..e3a2452cda 100644 --- a/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml +++ b/detections/endpoint/linux_auditd_edit_cron_table_parameter.yml @@ -1,7 +1,7 @@ name: Linux Auditd Edit Cron Table Parameter id: f4bb7321-7e64-4d1e-b1aa-21f8b019a91f -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml b/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml index f33b95fed5..7ce6b582fc 100644 --- a/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml +++ b/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml @@ -1,8 +1,8 @@ name: Linux Auditd File Permission Modification Via Chmod id: 5f1d2ea7-eec0-4790-8b24-6875312ad492 -version: 6 -date: '2025-01-27' -author: "Teoderick Contreras, Splunk, Ivar Nyg\xE5rd" +version: 7 +date: '2025-02-10' +author: Teoderick Contreras, Splunk, Ivar Nygård status: production type: Anomaly description: The following analytic detects suspicious file permission modifications @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1222.002 - - T1222 product: - Splunk Enterprise - Splunk Enterprise Security @@ -77,6 +76,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/linux_auditd_chmod_exec_attrib.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/linux_auditd_chmod_exec_attrib.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml b/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml index 84bb8beef4..de8a0c8bc8 100644 --- a/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml +++ b/detections/endpoint/linux_auditd_file_permissions_modification_via_chattr.yml @@ -1,16 +1,30 @@ name: Linux Auditd File Permissions Modification Via Chattr id: f2d1110d-b01c-4a58-9975-90a9edeb083a -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-03' author: Teoderick Contreras, Splunk status: production -type: TTP +type: Anomaly description: The following analytic detects suspicious file permissions modifications using the chattr command, which may indicate an attacker attempting to manipulate file attributes to evade detection or prevent alteration. The chattr command can be used to make files immutable or restrict deletion, which can be leveraged to protect malicious files or disrupt system operations. By monitoring for unusual or unauthorized chattr usage, this analytic helps identify potential tampering with critical files, enabling security teams to quickly respond to and mitigate threats associated with unauthorized file attribute changes. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host as dest | rename comm as process_name | rename exe as process | where LIKE(process_exec, "%chattr %") AND LIKE(process_exec, "% -i%") | stats count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_file_permissions_modification_via_chattr_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host + as dest | rename comm as process_name | rename exe as process | where LIKE(process_exec, + "%chattr %") AND LIKE(process_exec, "% -i%") | stats count min(_time) as firstTime + max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter + dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| + `linux_auditd_file_permissions_modification_via_chattr_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can use this application + for automation purposes. Please update the filter macros to remove false positives. references: - https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html drilldown_searches: @@ -19,7 +33,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -28,7 +47,7 @@ rba: risk_objects: - field: dest type: system - score: 49 + score: 30 threat_objects: [] tags: analytic_story: @@ -39,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1222.002 - - T1222 product: - Splunk Enterprise - Splunk Enterprise Security @@ -48,6 +66,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chattr_i/linux_auditd_chattr_i.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chattr_i/linux_auditd_chattr_i.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml b/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml index f42a173862..91a4468484 100644 --- a/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml +++ b/detections/endpoint/linux_auditd_find_credentials_from_password_managers.yml @@ -1,14 +1,21 @@ name: Linux Auditd Find Credentials From Password Managers id: 784241aa-85a5-4782-a503-d071bd3446f9 -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-03' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects suspicious attempts to find credentials stored in password managers, which may indicate an attacker's effort to retrieve sensitive login information. Password managers are often targeted by adversaries seeking to access stored passwords for further compromise or lateral movement within a network. By monitoring for unusual or unauthorized access to password manager files or processes, this analytic helps identify potential credential theft attempts, enabling security teams to respond quickly to protect critical accounts and prevent further unauthorized access. +description: The following analytic detects suspicious attempts to find credentials + stored in password managers, which may indicate an attacker's effort to retrieve + sensitive login information. Password managers are often targeted by adversaries + seeking to access stored passwords for further compromise or lateral movement within + a network. By monitoring for unusual or unauthorized access to password manager + files or processes, this analytic helps identify potential credential theft attempts, + enabling security teams to respond quickly to protect critical accounts and prevent + further unauthorized access. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.kdbx%") OR LIKE (process_exec, "%KeePass%") OR LIKE (process_exec, "%KeePass\.enforced%") OR LIKE (process_exec, "%.lpdb%")OR LIKE (process_exec, "%.opvault%")OR LIKE (process_exec, "%.agilekeychain%")OR LIKE (process_exec, "%.dashlane%")OR LIKE (process_exec, "%.rfx%")OR LIKE (process_exec, "%passbolt%")OR LIKE (process_exec, "%.spdb%")OR LIKE (process_exec, "%StickyPassword%")OR LIKE (process_exec, "%.walletx%")OR LIKE (process_exec, "%enpass%")OR LIKE (process_exec, "%vault%")OR LIKE (process_exec, "%.kdb%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_credentials_from_password_managers_filter`' +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.kdbx%") OR LIKE (process_exec, "%KeePass%") OR LIKE (process_exec, "%.enforced%") OR LIKE (process_exec, "%.lpdb%")OR LIKE (process_exec, "%.opvault%")OR LIKE (process_exec, "%.agilekeychain%")OR LIKE (process_exec, "%.dashlane%")OR LIKE (process_exec, "%.rfx%")OR LIKE (process_exec, "%passbolt%")OR LIKE (process_exec, "%.spdb%")OR LIKE (process_exec, "%StickyPassword%")OR LIKE (process_exec, "%.walletx%")OR LIKE (process_exec, "%enpass%")OR LIKE (process_exec, "%vault%")OR LIKE (process_exec, "%.kdb%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_credentials_from_password_managers_filter`' how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. references: @@ -20,7 +27,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -40,7 +52,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1555.005 - - T1555 product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,6 +60,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_password_db/linux_auditd_find_password_db.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_password_db/linux_auditd_find_password_db.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml b/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml index 6332592a94..9ae67754ae 100644 --- a/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml +++ b/detections/endpoint/linux_auditd_find_credentials_from_password_stores.yml @@ -1,16 +1,38 @@ name: Linux Auditd Find Credentials From Password Stores id: 4de73044-9a1d-4a51-a1c2-85267d8dcab3 -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects suspicious attempts to find credentials stored in password stores, indicating a potential attacker's effort to access sensitive login information. Password stores are critical repositories that contain valuable credentials, and unauthorized access to them can lead to significant security breaches. By monitoring for unusual or unauthorized activities related to password store access, this analytic helps identify potential credential theft attempts, allowing security teams to respond promptly and prevent unauthorized access to critical systems and data. +description: The following analytic detects suspicious attempts to find credentials + stored in password stores, indicating a potential attacker's effort to access sensitive + login information. Password stores are critical repositories that contain valuable + credentials, and unauthorized access to them can lead to significant security breaches. + By monitoring for unusual or unauthorized activities related to password store access, + this analytic helps identify potential credential theft attempts, allowing security + teams to respond promptly and prevent unauthorized access to critical systems and + data. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%password%") OR LIKE (process_exec, "%pass %") OR LIKE (process_exec, "%credential%")OR LIKE (process_exec, "%creds%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_credentials_from_password_stores_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as + dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, + "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%password%") + OR LIKE (process_exec, "%pass %") OR LIKE (process_exec, "%credential%")OR LIKE + (process_exec, "%creds%")) | stats count min(_time) as firstTime max(_time) as lastTime + by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| + `linux_auditd_find_credentials_from_password_stores_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can use this application + for automation purposes. Please update the filter macros to remove false positives. references: - https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html - https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS @@ -20,7 +42,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -40,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1555.005 - - T1555 product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_credentials/linux_auditd_find_credentials.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555.005/linux_auditd_find_credentials/linux_auditd_find_credentials.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_find_ssh_private_keys.yml b/detections/endpoint/linux_auditd_find_ssh_private_keys.yml index 8788828cc2..96e7d7d952 100644 --- a/detections/endpoint/linux_auditd_find_ssh_private_keys.yml +++ b/detections/endpoint/linux_auditd_find_ssh_private_keys.yml @@ -1,16 +1,38 @@ name: Linux Auditd Find Ssh Private Keys id: e2d2bd10-dcd1-4b2f-8a76-0198eab32ba5 -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic detects suspicious attempts to find SSH private keys, which may indicate an attacker's effort to compromise secure access to systems. SSH private keys are essential for secure authentication, and unauthorized access to these keys can enable attackers to gain unauthorized access to servers and other critical infrastructure. By monitoring for unusual or unauthorized searches for SSH private keys, this analytic helps identify potential threats to network security, allowing security teams to quickly respond and safeguard against unauthorized access and potential breaches. +description: The following analytic detects suspicious attempts to find SSH private + keys, which may indicate an attacker's effort to compromise secure access to systems. + SSH private keys are essential for secure authentication, and unauthorized access + to these keys can enable attackers to gain unauthorized access to servers and other + critical infrastructure. By monitoring for unusual or unauthorized searches for + SSH private keys, this analytic helps identify potential threats to network security, + allowing security teams to quickly respond and safeguard against unauthorized access + and potential breaches. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%id_rsa%") OR LIKE (process_exec, "%id_dsa%")OR LIKE (process_exec, "%.key%") OR LIKE (process_exec, "%ssh_key%")OR LIKE (process_exec, "%authorized_keys%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_find_ssh_private_keys_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as + dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, + "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%id_rsa%") + OR LIKE (process_exec, "%id_dsa%")OR LIKE (process_exec, "%.key%") OR LIKE (process_exec, + "%ssh_key%")OR LIKE (process_exec, "%authorized_keys%")) | stats count min(_time) + as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`| `linux_auditd_find_ssh_private_keys_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can use this application + for automation purposes. Please update the filter macros to remove false positives. references: - https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html - https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS @@ -20,7 +42,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -40,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_ssh_files/linux_auditd_find_ssh_files.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_ssh_files/linux_auditd_find_ssh_files.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml b/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml index f888933bba..483150c621 100644 --- a/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml +++ b/detections/endpoint/linux_auditd_hidden_files_and_directories_creation.yml @@ -1,10 +1,10 @@ name: Linux Auditd Hidden Files And Directories Creation id: 555cc358-bf16-4e05-9b3a-0f89c73b7261 -version: 4 -date: '2025-01-16' +version: 5 +date: '2025-02-03' author: Teoderick Contreras, Splunk status: production -type: TTP +type: Anomaly description: The following analytic detects suspicious creation of hidden files and directories, which may indicate an attacker's attempt to conceal malicious activities or unauthorized data. Hidden files and directories are often used to evade detection by security tools and administrators, providing a stealthy means for storing malware, logs, or sensitive information. By monitoring for unusual or unauthorized creation of hidden files and directories, this analytic helps identify potential attempts to hide or unauthorized creation of hidden files and directories, this analytic helps identify potential attempts to hide malicious operations, enabling security teams to uncover and address hidden threats effectively. data_source: - Linux Auditd Execve @@ -28,7 +28,7 @@ rba: risk_objects: - field: dest type: system - score: 64 + score: 30 threat_objects: [] tags: analytic_story: diff --git a/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml b/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml index 10a1cc21ad..0b168373bc 100644 --- a/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml +++ b/detections/endpoint/linux_auditd_insert_kernel_module_using_insmod_utility.yml @@ -1,7 +1,7 @@ name: Linux Auditd Insert Kernel Module Using Insmod Utility id: bc0ca53f-dea6-4906-9b12-09c396fdf1d3 -version: 4 -date: '2024-12-19' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -19,9 +19,9 @@ search: '`linux_auditd` type=SYSCALL comm=insmod | rename host as dest | stats c success dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_insert_kernel_module_using_insmod_utility_filter`' how_to_implement: To implement this detection, the process begins by ingesting auditd - data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line - executions and process details on Unix/Linux systems. These logs should be ingested - and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml b/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml index 29a1db8488..a57cd34a93 100644 --- a/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml +++ b/detections/endpoint/linux_auditd_install_kernel_module_using_modprobe_utility.yml @@ -1,16 +1,34 @@ name: Linux Auditd Install Kernel Module Using Modprobe Utility id: 95165985-ace5-4d42-9c42-93a89a5af901 -version: 3 -date: '2025-01-20' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic detects the installation of a Linux kernel module using the modprobe utility. It leverages data from Linux Auditd, focusing on process names and command-line executions. This activity is significant because installing a kernel module can indicate an attempt to deploy a rootkit or other malicious kernel-level code, potentially leading to elevated privileges and bypassing security detections. If confirmed malicious, this could allow an attacker to gain persistent, high-level access to the system, compromising its integrity and security. +description: The following analytic detects the installation of a Linux kernel module + using the modprobe utility. It leverages data from Linux Auditd, focusing on process + names and command-line executions. This activity is significant because installing + a kernel module can indicate an attempt to deploy a rootkit or other malicious kernel-level + code, potentially leading to elevated privileges and bypassing security detections. + If confirmed malicious, this could allow an attacker to gain persistent, high-level + access to the system, compromising its integrity and security. data_source: - Linux Auditd Syscall -search: '`linux_auditd` type=SYSCALL comm=modprobe | rename host as dest | stats count min(_time) as firstTime max(_time) as lastTime by comm exe SYSCALL UID ppid pid success dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `linux_auditd_install_kernel_module_using_modprobe_utility_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives. +search: '`linux_auditd` type=SYSCALL comm=modprobe | rename host as dest | stats count + min(_time) as firstTime max(_time) as lastTime by comm exe SYSCALL UID ppid pid + success dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| + `linux_auditd_install_kernel_module_using_modprobe_utility_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. references: - https://docs.fedoraproject.org/en-US/fedora/rawhide/system-administrators-guide/kernel-module-driver-configuration/Working_with_Kernel_Modules/ - https://security.stackexchange.com/questions/175953/how-to-load-a-malicious-lkm-at-startup @@ -21,7 +39,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -41,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security @@ -50,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe/linux_auditd_modprobe.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe/linux_auditd_modprobe.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml b/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml index 85736a7952..0d437219d2 100644 --- a/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml +++ b/detections/endpoint/linux_auditd_kernel_module_using_rmmod_utility.yml @@ -1,7 +1,7 @@ name: Linux Auditd Kernel Module Using Rmmod Utility id: 31810b7a-0abe-42be-a210-0dec8106afee -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml b/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml index b0d9f8aa6c..2470ddfe8f 100644 --- a/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml +++ b/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Nopasswd Entry In Sudoers File id: 651df959-ad17-4b73-a323-90cb96d5fa1b -version: 4 -date: '2025-01-27' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -74,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml b/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml index 965112d606..a9323c6d19 100644 --- a/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml +++ b/detections/endpoint/linux_auditd_possible_access_or_modification_of_sshd_config_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Possible Access Or Modification Of Sshd Config File id: acb3ea33-70f7-47aa-b335-643b3aebcb2f -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1098.004 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml b/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml index 499e0a23bb..62158c07f3 100644 --- a/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml +++ b/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml @@ -1,7 +1,7 @@ name: Linux Auditd Possible Access To Credential Files id: 0419cb7a-57ea-467b-974f-77c303dfe2a3 -version: 4 -date: '2025-01-27' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.008 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -76,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/linux_auditd_access_credential.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/linux_auditd_access_credential.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml b/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml index 8dda7e5e89..ce58e5dae8 100644 --- a/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml +++ b/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Possible Access To Sudoers File id: 8be88f46-f7e8-4ae6-b15e-cf1b13392834 -version: 4 -date: '2025-01-27' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -73,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml b/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml index d80e3059c5..7fac278e2a 100644 --- a/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml +++ b/detections/endpoint/linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File id: fea71cf0-fa10-4ef6-9202-9682b2e0c477 -version: 4 -date: '2025-01-20' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -19,9 +19,9 @@ search: '`linux_auditd` type=PATH name IN("*/etc/cron*", "*/var/spool/cron/*", " by name nametype OGID dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `linux_auditd_possible_append_cronjob_entry_on_existing_cronjob_file_filter`' how_to_implement: To implement this detection, the process begins by ingesting auditd - data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line - executions and process details on Unix/Linux systems. These logs should be ingested - and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources @@ -45,7 +45,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml b/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml index fdfa38e184..8eb1a95ce2 100644 --- a/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml +++ b/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml @@ -1,7 +1,7 @@ name: Linux Auditd Preload Hijack Library Calls id: 35c50572-a70b-452f-afa9-bebdf3c3ce36 -version: 4 -date: '2025-01-27' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.006 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security @@ -74,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/linux_auditd_ldpreload.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/linux_auditd_ldpreload.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml b/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml index 2d5b8c3d5e..d850271d2d 100644 --- a/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml +++ b/detections/endpoint/linux_auditd_preload_hijack_via_preload_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Preload Hijack Via Preload File id: c1b7abca-55cb-4a39-bdfb-e28c1c12745f -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -47,7 +47,8 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: A [$type$] event has occurred on host - [$dest$] to modify the preload file. + message: A [$type$] event has occurred on host - [$dest$] to modify the preload + file. risk_objects: - field: dest type: system @@ -62,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.006 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml b/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml index 29d3189d49..3734df8760 100644 --- a/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml +++ b/detections/endpoint/linux_auditd_private_keys_and_certificate_enumeration.yml @@ -1,16 +1,40 @@ name: Linux Auditd Private Keys and Certificate Enumeration id: 892eb674-3344-4143-8e52-4775b1daf3f1 -version: 1 -date: '2025-01-15' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic detects suspicious attempts to find private keys, which may indicate an attacker's effort to access sensitive cryptographic information. Private keys are crucial for securing encrypted communications and data, and unauthorized access to them can lead to severe security breaches, including data decryption and identity theft. By monitoring for unusual or unauthorized searches for private keys, this analytic helps identify potential threats to cryptographic security, enabling security teams to take swift action to protect the integrity and confidentiality of encrypted information. +description: The following analytic detects suspicious attempts to find private keys, + which may indicate an attacker's effort to access sensitive cryptographic information. + Private keys are crucial for securing encrypted communications and data, and unauthorized + access to them can lead to severe security breaches, including data decryption and + identity theft. By monitoring for unusual or unauthorized searches for private keys, + this analytic helps identify potential threats to cryptographic security, enabling + security teams to take swift action to protect the integrity and confidentiality + of encrypted information. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.pem%") OR LIKE (process_exec, "%.cer%") OR LIKE (process_exec, "%.crt%") OR LIKE (process_exec, "%.pgp%") OR LIKE (process_exec, "%.key%") OR LIKE (process_exec, "%.gpg%")OR LIKE (process_exec, "%.ppk%") OR LIKE (process_exec, "%.p12%") OR LIKE (process_exec, "%.pfx%")OR LIKE (process_exec, "%.p7b%")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_private_keys_and_certificate_enumeration_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as + dest | rename comm as process_name | rename exe as process | where (LIKE (process_exec, + "%find%") OR LIKE (process_exec, "%grep%")) AND (LIKE (process_exec, "%.pem%") OR + LIKE (process_exec, "%.cer%") OR LIKE (process_exec, "%.crt%") OR LIKE (process_exec, + "%.pgp%") OR LIKE (process_exec, "%.key%") OR LIKE (process_exec, "%.gpg%")OR LIKE + (process_exec, "%.ppk%") OR LIKE (process_exec, "%.p12%") OR LIKE (process_exec, + "%.pfx%")OR LIKE (process_exec, "%.p7b%")) | stats count min(_time) as firstTime + max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`| `linux_auditd_private_keys_and_certificate_enumeration_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can use this application + for automation purposes. Please update the filter macros to remove false positives. references: - https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html - https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS @@ -20,7 +44,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -39,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security @@ -48,6 +76,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_gpg/linux_auditd_find_gpg.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.004/linux_auditd_find_gpg/linux_auditd_find_gpg.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_service_restarted.yml b/detections/endpoint/linux_auditd_service_restarted.yml index a619b94f79..63fbdd633c 100644 --- a/detections/endpoint/linux_auditd_service_restarted.yml +++ b/detections/endpoint/linux_auditd_service_restarted.yml @@ -1,7 +1,7 @@ name: Linux Auditd Service Restarted id: 8eb3e858-18d3-44a4-a514-52cfa39f154a -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.006 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_service_started.yml b/detections/endpoint/linux_auditd_service_started.yml index 2e878c1779..d157eebc41 100644 --- a/detections/endpoint/linux_auditd_service_started.yml +++ b/detections/endpoint/linux_auditd_service_started.yml @@ -1,10 +1,10 @@ name: Linux Auditd Service Started id: b5eed06d-5c97-4092-a3a1-fa4b7e77c71a -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-03' author: Teoderick Contreras, Splunk status: production -type: TTP +type: Anomaly description: The following analytic detects the suspicious service started. This behavior is critical for a SOC to monitor because it may indicate attempts to gain unauthorized access or maintain control over a system. Such actions could be signs of malicious @@ -53,7 +53,7 @@ rba: risk_objects: - field: dest type: system - score: 64 + score: 40 threat_objects: [] tags: analytic_story: @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1569.002 - - T1569 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml b/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml index 7c32e22160..db1157d54e 100644 --- a/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml +++ b/detections/endpoint/linux_auditd_setuid_using_chmod_utility.yml @@ -1,7 +1,7 @@ name: Linux Auditd Setuid Using Chmod Utility id: 8230c407-1b47-4d95-ac2e-718bd6381386 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.001 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml b/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml index df8cc3f4ae..08a69f6ca0 100644 --- a/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml +++ b/detections/endpoint/linux_auditd_setuid_using_setcap_utility.yml @@ -1,16 +1,38 @@ name: Linux Auditd Setuid Using Setcap Utility id: 1474459a-302b-4255-8add-d82f96d14cd9 -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects the execution of the 'setcap' utility to enable the SUID bit on Linux systems. It leverages Linux Auditd data, focusing on process names and command-line arguments that indicate the use of 'setcap' with specific capabilities. This activity is significant because setting the SUID bit allows a user to temporarily gain root access, posing a substantial security risk. If confirmed malicious, an attacker could escalate privileges, execute arbitrary commands with elevated permissions, and potentially compromise the entire system. +description: The following analytic detects the execution of the 'setcap' utility + to enable the SUID bit on Linux systems. It leverages Linux Auditd data, focusing + on process names and command-line arguments that indicate the use of 'setcap' with + specific capabilities. This activity is significant because setting the SUID bit + allows a user to temporarily gain root access, posing a substantial security risk. + If confirmed malicious, an attacker could escalate privileges, execute arbitrary + commands with elevated permissions, and potentially compromise the entire system. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where LIKE (process_exec, "%setcap %") AND (LIKE (process_exec, "% cap_setuid+ep %") OR LIKE (process_exec, "% cap_setuid=ep %") OR LIKE (process_exec, "% cap_net_bind_service+p %") OR LIKE (process_exec, "% cap_net_raw+ep %") OR LIKE (process_exec, "% cap_dac_read_search+ep %")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `linux_auditd_setuid_using_setcap_utility_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as + dest | rename comm as process_name | rename exe as process | where LIKE (process_exec, + "%setcap %") AND (LIKE (process_exec, "% cap_setuid+ep %") OR LIKE (process_exec, + "% cap_setuid=ep %") OR LIKE (process_exec, "% cap_net_bind_service+p %") OR LIKE + (process_exec, "% cap_net_raw+ep %") OR LIKE (process_exec, "% cap_dac_read_search+ep + %")) | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec + dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| + `linux_auditd_setuid_using_setcap_utility_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. references: - https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/ drilldown_searches: @@ -19,7 +41,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -38,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.001 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -47,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/linux_auditd_setuid/linux_auditd_setcap_priv.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/linux_auditd_setuid/linux_auditd_setcap_priv.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_sudo_or_su_execution.yml b/detections/endpoint/linux_auditd_sudo_or_su_execution.yml index b53ed7ef6c..ebf46c26c5 100644 --- a/detections/endpoint/linux_auditd_sudo_or_su_execution.yml +++ b/detections/endpoint/linux_auditd_sudo_or_su_execution.yml @@ -1,16 +1,35 @@ name: Linux Auditd Sudo Or Su Execution id: 817a5c89-5b92-4818-a22d-aa35e1361afe -version: 3 -date: '2025-01-20' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic detects the execution of the "sudo" or "su" command on a Linux operating system. It leverages data from Linux Auditd, focusing on process names and parent process names. This activity is significant because "sudo" and "su" commands are commonly used by adversaries to elevate privileges, potentially leading to unauthorized access or control over the system. If confirmed malicious, this activity could allow attackers to execute commands with root privileges, leading to severe security breaches, data exfiltration, or further system compromise. +description: The following analytic detects the execution of the "sudo" or "su" command + on a Linux operating system. It leverages data from Linux Auditd, focusing on process + names and parent process names. This activity is significant because "sudo" and + "su" commands are commonly used by adversaries to elevate privileges, potentially + leading to unauthorized access or control over the system. If confirmed malicious, + this activity could allow attackers to execute commands with root privileges, leading + to severe security breaches, data exfiltration, or further system compromise. data_source: - Linux Auditd Proctitle -search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host as dest | where LIKE(process_exec, "%sudo %") OR LIKE(process_exec, "%su %") | stats count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `linux_auditd_sudo_or_su_execution_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can execute this command. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_proctitle_process` | rename host + as dest | where LIKE(process_exec, "%sudo %") OR LIKE(process_exec, "%su %") | stats + count min(_time) as firstTime max(_time) as lastTime by process_exec proctitle normalized_proctitle_delimiter + dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| + `linux_auditd_sudo_or_su_execution_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. references: - https://attack.mitre.org/techniques/T1548/003/ drilldown_searches: @@ -19,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -38,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -47,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudo_su/linux_auditd_sudo_su.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudo_su/linux_auditd_sudo_su.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml b/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml index 50d90725bc..664416e29d 100644 --- a/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml +++ b/detections/endpoint/linux_auditd_unix_shell_configuration_modification.yml @@ -1,7 +1,7 @@ name: Linux Auditd Unix Shell Configuration Modification id: 66f737c6-3f7f-46ed-8e9b-cc0e5bf01f04 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.004 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml b/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml index d3f5d76e2e..cdd0c0c95c 100644 --- a/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml +++ b/detections/endpoint/linux_auditd_unload_module_via_modprobe.yml @@ -1,16 +1,36 @@ name: Linux Auditd Unload Module Via Modprobe id: 90964d6a-4b5f-409a-85bd-95e261e03fe9 -version: 3 -date: '2025-01-16' +version: 4 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects suspicious use of the `modprobe` command to unload kernel modules, which may indicate an attempt to disable critical system components or evade detection. The `modprobe` utility manages kernel modules, and unauthorized unloading of modules can disrupt system security features, remove logging capabilities, or conceal malicious activities. By monitoring for unusual or unauthorized `modprobe` operations involving module unloading, this analytic helps identify potential tampering with kernel functionality, enabling security teams to investigate and address possible threats to system integrity. +description: The following analytic detects suspicious use of the `modprobe` command + to unload kernel modules, which may indicate an attempt to disable critical system + components or evade detection. The `modprobe` utility manages kernel modules, and + unauthorized unloading of modules can disrupt system security features, remove logging + capabilities, or conceal malicious activities. By monitoring for unusual or unauthorized + `modprobe` operations involving module unloading, this analytic helps identify potential + tampering with kernel functionality, enabling security teams to investigate and + address possible threats to system integrity. data_source: - Linux Auditd Execve -search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as dest | rename comm as process_name | rename exe as process | where LIKE (process_exec, "%modprobe%") AND LIKE (process_exec, "%-r %") | stats count min(_time) as firstTime max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `linux_auditd_unload_module_via_modprobe_filter`' -how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), which is essential for correctly parsing and categorizing the data. The next step involves normalizing the field names to match the field names set by the Splunk Common Information Model (CIM) to ensure consistency across different data sources and enhance the efficiency of data modeling. This approach enables effective monitoring and detection of linux endpoints where auditd is deployed -known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. +search: '`linux_auditd` `linux_auditd_normalized_execve_process` | rename host as + dest | rename comm as process_name | rename exe as process | where LIKE (process_exec, + "%modprobe%") AND LIKE (process_exec, "%-r %") | stats count min(_time) as firstTime + max(_time) as lastTime by argc process_exec dest | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)`| `linux_auditd_unload_module_via_modprobe_filter`' +how_to_implement: To implement this detection, the process begins by ingesting auditd + data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures + command-line executions and process details on Unix/Linux systems. These logs should + be ingested and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833), + which is essential for correctly parsing and categorizing the data. The next step + involves normalizing the field names to match the field names set by the Splunk + Common Information Model (CIM) to ensure consistency across different data sources + and enhance the efficiency of data modeling. This approach enables effective monitoring + and detection of linux endpoints where auditd is deployed +known_false_positives: Administrator or network operator can use this application + for automation purposes. Please update the filter macros to remove false positives. references: - https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html drilldown_searches: @@ -19,7 +39,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -39,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security @@ -48,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe_unload_module/linux_auditd_modprobe_unload_module.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.006/linux_auditd_modprobe_unload_module/linux_auditd_modprobe_unload_module.log source: /var/log/audit/audit.log sourcetype: linux:audit diff --git a/detections/endpoint/linux_awk_privilege_escalation.yml b/detections/endpoint/linux_awk_privilege_escalation.yml index 1036c94106..412b476eef 100644 --- a/detections/endpoint/linux_awk_privilege_escalation.yml +++ b/detections/endpoint/linux_awk_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux AWK Privilege Escalation id: 4510cae0-96a2-4840-9919-91d262db210a -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_busybox_privilege_escalation.yml b/detections/endpoint/linux_busybox_privilege_escalation.yml index f6bbd0bde7..74ea49e117 100644 --- a/detections/endpoint/linux_busybox_privilege_escalation.yml +++ b/detections/endpoint/linux_busybox_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Busybox Privilege Escalation id: 387c4e78-f4a4-413d-ad44-e9f7bc4642c9 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_c89_privilege_escalation.yml b/detections/endpoint/linux_c89_privilege_escalation.yml index 3919b610e8..229db8dfc8 100644 --- a/detections/endpoint/linux_c89_privilege_escalation.yml +++ b/detections/endpoint/linux_c89_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux c89 Privilege Escalation id: 54c95f4d-3e5d-44be-9521-ea19ba62f7a8 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_c99_privilege_escalation.yml b/detections/endpoint/linux_c99_privilege_escalation.yml index 9e76c91bfe..6456f1654a 100644 --- a/detections/endpoint/linux_c99_privilege_escalation.yml +++ b/detections/endpoint/linux_c99_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux c99 Privilege Escalation id: e1c6dec5-2249-442d-a1f9-99a4bd228183 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_change_file_owner_to_root.yml b/detections/endpoint/linux_change_file_owner_to_root.yml index 89b8695a26..0135aa468d 100644 --- a/detections/endpoint/linux_change_file_owner_to_root.yml +++ b/detections/endpoint/linux_change_file_owner_to_root.yml @@ -1,7 +1,7 @@ name: Linux Change File Owner To Root id: c1400ea2-6257-11ec-ad49-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1222.002 - - T1222 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_common_process_for_elevation_control.yml b/detections/endpoint/linux_common_process_for_elevation_control.yml index 9bcb78b36d..221f4c30c6 100644 --- a/detections/endpoint/linux_common_process_for_elevation_control.yml +++ b/detections/endpoint/linux_common_process_for_elevation_control.yml @@ -1,7 +1,7 @@ name: Linux Common Process For Elevation Control id: 66ab15c0-63d0-11ec-9e70-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -52,7 +52,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.001 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -61,6 +60,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.001/chmod_uid/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_composer_privilege_escalation.yml b/detections/endpoint/linux_composer_privilege_escalation.yml index 4128c46843..d3303e4046 100644 --- a/detections/endpoint/linux_composer_privilege_escalation.yml +++ b/detections/endpoint/linux_composer_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Composer Privilege Escalation id: a3bddf71-6ba3-42ab-a6b2-396929b16d92 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_cpulimit_privilege_escalation.yml b/detections/endpoint/linux_cpulimit_privilege_escalation.yml index 2d565e6a8b..42c898b210 100644 --- a/detections/endpoint/linux_cpulimit_privilege_escalation.yml +++ b/detections/endpoint/linux_cpulimit_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Cpulimit Privilege Escalation id: d4e40b7e-aad3-4a7d-aac8-550ea5222be5 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_csvtool_privilege_escalation.yml b/detections/endpoint/linux_csvtool_privilege_escalation.yml index 0b4a4ed4b6..4c17cce459 100644 --- a/detections/endpoint/linux_csvtool_privilege_escalation.yml +++ b/detections/endpoint/linux_csvtool_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Csvtool Privilege Escalation id: f8384f9e-1a5c-4c3a-96d6-8a7e5a38a8b8 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_data_destruction_command.yml b/detections/endpoint/linux_data_destruction_command.yml index 0ed0562b5d..d995933ae4 100644 --- a/detections/endpoint/linux_data_destruction_command.yml +++ b/detections/endpoint/linux_data_destruction_command.yml @@ -1,6 +1,6 @@ name: Linux Data Destruction Command id: b11d3979-b2f7-411b-bb1a-bd00e642173b -version: 4 +version: 5 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/linux_decode_base64_to_shell.yml b/detections/endpoint/linux_decode_base64_to_shell.yml index a60cd9db88..a332d7535a 100644 --- a/detections/endpoint/linux_decode_base64_to_shell.yml +++ b/detections/endpoint/linux_decode_base64_to_shell.yml @@ -1,6 +1,6 @@ name: Linux Decode Base64 to Shell id: 637b603e-1799-40fd-bf87-47ecbd551b66 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_deletion_of_cron_jobs.yml b/detections/endpoint/linux_deletion_of_cron_jobs.yml index 6c57aa65d9..0e75efa4a7 100644 --- a/detections/endpoint/linux_deletion_of_cron_jobs.yml +++ b/detections/endpoint/linux_deletion_of_cron_jobs.yml @@ -1,7 +1,7 @@ name: Linux Deletion Of Cron Jobs id: 3b132a71-9335-4f33-9932-00bb4f6ac7e8 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -57,9 +57,8 @@ tags: - AcidPour asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_deletion_of_init_daemon_script.yml b/detections/endpoint/linux_deletion_of_init_daemon_script.yml index 98d166fbbf..339d58c50b 100644 --- a/detections/endpoint/linux_deletion_of_init_daemon_script.yml +++ b/detections/endpoint/linux_deletion_of_init_daemon_script.yml @@ -1,7 +1,7 @@ name: Linux Deletion Of Init Daemon Script id: 729aab57-d26f-4156-b97f-ab8dda8f44b1 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,9 +57,8 @@ tags: - AcidPour asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_deletion_of_services.yml b/detections/endpoint/linux_deletion_of_services.yml index 0105dcf5c9..2d27e43f5b 100644 --- a/detections/endpoint/linux_deletion_of_services.yml +++ b/detections/endpoint/linux_deletion_of_services.yml @@ -1,7 +1,7 @@ name: Linux Deletion Of Services id: b509bbd3-0331-4aaa-8e4a-d2affe100af6 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -62,9 +62,8 @@ tags: - AcidPour asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_deletion_of_ssl_certificate.yml b/detections/endpoint/linux_deletion_of_ssl_certificate.yml index 3742f9eeed..94765cb179 100644 --- a/detections/endpoint/linux_deletion_of_ssl_certificate.yml +++ b/detections/endpoint/linux_deletion_of_ssl_certificate.yml @@ -1,7 +1,7 @@ name: Linux Deletion of SSL Certificate id: 839ab790-a60a-4f81-bfb3-02567063f615 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,9 +58,8 @@ tags: - AcidPour asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_doas_conf_file_creation.yml b/detections/endpoint/linux_doas_conf_file_creation.yml index 5acb1dff95..8dfac80ecc 100644 --- a/detections/endpoint/linux_doas_conf_file_creation.yml +++ b/detections/endpoint/linux_doas_conf_file_creation.yml @@ -1,7 +1,7 @@ name: Linux Doas Conf File Creation id: f6343e86-6e09-11ec-9376-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_doas_tool_execution.yml b/detections/endpoint/linux_doas_tool_execution.yml index 3c242194f3..24876440f0 100644 --- a/detections/endpoint/linux_doas_tool_execution.yml +++ b/detections/endpoint/linux_doas_tool_execution.yml @@ -1,7 +1,7 @@ name: Linux Doas Tool Execution id: d5a62490-6e09-11ec-884e-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_docker_privilege_escalation.yml b/detections/endpoint/linux_docker_privilege_escalation.yml index a6c8d07606..6a3293283f 100644 --- a/detections/endpoint/linux_docker_privilege_escalation.yml +++ b/detections/endpoint/linux_docker_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Docker Privilege Escalation id: 2e7bfb78-85f6-47b5-bc2f-15813a4ef2b3 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_edit_cron_table_parameter.yml b/detections/endpoint/linux_edit_cron_table_parameter.yml index 9283c0bbfb..6da604bda5 100644 --- a/detections/endpoint/linux_edit_cron_table_parameter.yml +++ b/detections/endpoint/linux_edit_cron_table_parameter.yml @@ -1,7 +1,7 @@ name: Linux Edit Cron Table Parameter id: 0d370304-5f26-11ec-a4bb-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_emacs_privilege_escalation.yml b/detections/endpoint/linux_emacs_privilege_escalation.yml index 2e3b916845..3e44cdc17f 100644 --- a/detections/endpoint/linux_emacs_privilege_escalation.yml +++ b/detections/endpoint/linux_emacs_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Emacs Privilege Escalation id: 92033cab-1871-483d-a03b-a7ce98665cfc -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml b/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml index 2b4da8e0f3..1335c47856 100644 --- a/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml +++ b/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml @@ -1,7 +1,7 @@ name: Linux File Created In Kernel Driver Directory id: b85bbeec-6326-11ec-9311-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_file_creation_in_init_boot_directory.yml b/detections/endpoint/linux_file_creation_in_init_boot_directory.yml index 810914e4f3..05900fd9fa 100644 --- a/detections/endpoint/linux_file_creation_in_init_boot_directory.yml +++ b/detections/endpoint/linux_file_creation_in_init_boot_directory.yml @@ -1,7 +1,7 @@ name: Linux File Creation In Init Boot Directory id: 97d9cfb2-61ad-11ec-bb2d-acde48001122 -version: 6 -date: '2025-01-27' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1037.004 - - T1037 product: - Splunk Enterprise - Splunk Enterprise Security @@ -66,6 +65,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_init_profile/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_file_creation_in_profile_directory.yml b/detections/endpoint/linux_file_creation_in_profile_directory.yml index c35c743ea6..d42712cf76 100644 --- a/detections/endpoint/linux_file_creation_in_profile_directory.yml +++ b/detections/endpoint/linux_file_creation_in_profile_directory.yml @@ -1,7 +1,7 @@ name: Linux File Creation In Profile Directory id: 46ba0082-61af-11ec-9826-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.004 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_find_privilege_escalation.yml b/detections/endpoint/linux_find_privilege_escalation.yml index faeeb076e0..6f3280fbc7 100644 --- a/detections/endpoint/linux_find_privilege_escalation.yml +++ b/detections/endpoint/linux_find_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Find Privilege Escalation id: 2ff4e0c2-8256-4143-9c07-1e39c7231111 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_gdb_privilege_escalation.yml b/detections/endpoint/linux_gdb_privilege_escalation.yml index fd91250e3a..ac12b85551 100644 --- a/detections/endpoint/linux_gdb_privilege_escalation.yml +++ b/detections/endpoint/linux_gdb_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux GDB Privilege Escalation id: 310b7da2-ab52-437f-b1bf-0bd458674308 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_gem_privilege_escalation.yml b/detections/endpoint/linux_gem_privilege_escalation.yml index 7976f81781..ad933d3de7 100644 --- a/detections/endpoint/linux_gem_privilege_escalation.yml +++ b/detections/endpoint/linux_gem_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Gem Privilege Escalation id: 0115482a-5dcb-4bb0-bcca-5d095d224236 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_gnu_awk_privilege_escalation.yml b/detections/endpoint/linux_gnu_awk_privilege_escalation.yml index 818ca801e4..2b34220074 100644 --- a/detections/endpoint/linux_gnu_awk_privilege_escalation.yml +++ b/detections/endpoint/linux_gnu_awk_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux GNU Awk Privilege Escalation id: 0dcf43b9-50d8-42a6-acd9-d1c9201fe6ae -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml b/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml index 49948ef473..cdde6977e4 100644 --- a/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml +++ b/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml @@ -1,7 +1,7 @@ name: Linux High Frequency Of File Deletion In Boot Folder id: e27fbc5d-0445-4c4a-bc39-87f060d5c602 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -58,9 +58,8 @@ tags: - AcidPour asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml b/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml index c783597e9c..ae5aa85d0d 100644 --- a/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml +++ b/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml @@ -1,7 +1,7 @@ name: Linux High Frequency Of File Deletion In Etc Folder id: 9d867448-2aff-4d07-876c-89409a752ff8 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,9 +56,8 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_impair_defenses_process_kill.yml b/detections/endpoint/linux_impair_defenses_process_kill.yml index 095729c786..6662f54760 100644 --- a/detections/endpoint/linux_impair_defenses_process_kill.yml +++ b/detections/endpoint/linux_impair_defenses_process_kill.yml @@ -1,7 +1,7 @@ name: Linux Impair Defenses Process Kill id: 435c6b33-adf9-47fe-be87-8e29fd6654f5 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_indicator_removal_service_file_deletion.yml b/detections/endpoint/linux_indicator_removal_service_file_deletion.yml index 917a6f8fb6..de2d2e6acb 100644 --- a/detections/endpoint/linux_indicator_removal_service_file_deletion.yml +++ b/detections/endpoint/linux_indicator_removal_service_file_deletion.yml @@ -1,7 +1,7 @@ name: Linux Indicator Removal Service File Deletion id: 6c077f81-2a83-4537-afbc-0e62e3215d55 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1070.004 - - T1070 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml b/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml index cb4fd7b694..fc543070b2 100644 --- a/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml +++ b/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml @@ -1,7 +1,7 @@ name: Linux Insert Kernel Module Using Insmod Utility id: 18b5a1a0-6326-11ec-943a-acde48001122 -version: 5 -date: '2024-12-17' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml b/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml index 7668cca286..32b16133a8 100644 --- a/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml +++ b/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml @@ -1,7 +1,7 @@ name: Linux Install Kernel Module Using Modprobe Utility id: 387b278a-6326-11ec-aa2c-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.006 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_iptables_firewall_modification.yml b/detections/endpoint/linux_iptables_firewall_modification.yml index 3107d907e2..395f7c7c45 100644 --- a/detections/endpoint/linux_iptables_firewall_modification.yml +++ b/detections/endpoint/linux_iptables_firewall_modification.yml @@ -1,7 +1,7 @@ name: Linux Iptables Firewall Modification id: 309d59dc-1e1b-49b2-9800-7cf18d12f7b7 -version: 7 -date: '2025-01-27' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -82,6 +81,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/cyclopsblink/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_java_spawning_shell.yml b/detections/endpoint/linux_java_spawning_shell.yml index 4625c20fb7..a13f0d306e 100644 --- a/detections/endpoint/linux_java_spawning_shell.yml +++ b/detections/endpoint/linux_java_spawning_shell.yml @@ -1,6 +1,6 @@ name: Linux Java Spawning Shell id: 7b09db8a-5c20-11ec-9945-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_kernel_module_enumeration.yml b/detections/endpoint/linux_kernel_module_enumeration.yml index 9939c3de7c..157f255449 100644 --- a/detections/endpoint/linux_kernel_module_enumeration.yml +++ b/detections/endpoint/linux_kernel_module_enumeration.yml @@ -1,6 +1,6 @@ name: Linux Kernel Module Enumeration id: 6df99886-0e04-4c11-8b88-325747419278 -version: 6 +version: 7 date: '2024-11-17' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_kworker_process_in_writable_process_path.yml b/detections/endpoint/linux_kworker_process_in_writable_process_path.yml index 0672ad7b93..6f189c9c75 100644 --- a/detections/endpoint/linux_kworker_process_in_writable_process_path.yml +++ b/detections/endpoint/linux_kworker_process_in_writable_process_path.yml @@ -1,7 +1,7 @@ name: Linux Kworker Process In Writable Process Path id: 1cefb270-74a5-4e27-aa0c-2b6fa7c5b4ed -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1036.004 - - T1036 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_make_privilege_escalation.yml b/detections/endpoint/linux_make_privilege_escalation.yml index a8e87a9bf6..8167787558 100644 --- a/detections/endpoint/linux_make_privilege_escalation.yml +++ b/detections/endpoint/linux_make_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Make Privilege Escalation id: 80b22836-5091-4944-80ee-f733ac443f4f -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_mysql_privilege_escalation.yml b/detections/endpoint/linux_mysql_privilege_escalation.yml index 370c6cc5e1..4fc1ec1c2a 100644 --- a/detections/endpoint/linux_mysql_privilege_escalation.yml +++ b/detections/endpoint/linux_mysql_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux MySQL Privilege Escalation id: c0d810f4-230c-44ea-b703-989da02ff145 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml b/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml index eeaf7de9e4..ace58aa7ad 100644 --- a/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml +++ b/detections/endpoint/linux_ngrok_reverse_proxy_usage.yml @@ -1,6 +1,6 @@ name: Linux Ngrok Reverse Proxy Usage id: bc84d574-708c-467d-b78a-4c1e20171f97 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_node_privilege_escalation.yml b/detections/endpoint/linux_node_privilege_escalation.yml index 5e26a21d55..de6c9fa5c1 100644 --- a/detections/endpoint/linux_node_privilege_escalation.yml +++ b/detections/endpoint/linux_node_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Node Privilege Escalation id: 2e58a4ff-398f-42f4-8fd0-e01ebfe2a8ce -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml index 15ca07070f..42d8d99f84 100644 --- a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml +++ b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml @@ -1,7 +1,7 @@ name: Linux NOPASSWD Entry In Sudoers File id: ab1e0d52-624a-11ec-8e0b-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -74,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/nopasswd_sudoers/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/nopasswd_sudoers/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml b/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml index 033284562b..eeb2fe21ba 100644 --- a/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml +++ b/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml @@ -1,6 +1,6 @@ name: Linux Obfuscated Files or Information Base64 Decode id: 303b38b2-c03f-44e2-8f41-4594606fcfc7 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_octave_privilege_escalation.yml b/detections/endpoint/linux_octave_privilege_escalation.yml index 37839dd3cb..ac9ee41409 100644 --- a/detections/endpoint/linux_octave_privilege_escalation.yml +++ b/detections/endpoint/linux_octave_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Octave Privilege Escalation id: 78f7487d-42ce-4f7f-8685-2159b25fb477 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_openvpn_privilege_escalation.yml b/detections/endpoint/linux_openvpn_privilege_escalation.yml index 452799d717..721061b734 100644 --- a/detections/endpoint/linux_openvpn_privilege_escalation.yml +++ b/detections/endpoint/linux_openvpn_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux OpenVPN Privilege Escalation id: d25feebe-fa1c-4754-8a1e-afb03bedc0f2 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_php_privilege_escalation.yml b/detections/endpoint/linux_php_privilege_escalation.yml index 521ece7f21..d65dc8062b 100644 --- a/detections/endpoint/linux_php_privilege_escalation.yml +++ b/detections/endpoint/linux_php_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux PHP Privilege Escalation id: 4fc4c031-e5be-4cc0-8cf9-49f9f507bcb5 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_pkexec_privilege_escalation.yml b/detections/endpoint/linux_pkexec_privilege_escalation.yml index e4fa7129d7..81844e155e 100644 --- a/detections/endpoint/linux_pkexec_privilege_escalation.yml +++ b/detections/endpoint/linux_pkexec_privilege_escalation.yml @@ -1,6 +1,6 @@ name: Linux pkexec Privilege Escalation id: 03e22c1c-8086-11ec-ac2e-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml b/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml index a7f1ec3741..99ccd2b813 100644 --- a/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml +++ b/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml @@ -1,7 +1,7 @@ name: Linux Possible Access Or Modification Of sshd Config File id: 7a85eb24-72da-11ec-ac76-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1098.004 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_possible_access_to_credential_files.yml b/detections/endpoint/linux_possible_access_to_credential_files.yml index e5f2c33dce..9bbbe61f67 100644 --- a/detections/endpoint/linux_possible_access_to_credential_files.yml +++ b/detections/endpoint/linux_possible_access_to_credential_files.yml @@ -1,7 +1,7 @@ name: Linux Possible Access To Credential Files id: 16107e0e-71fc-11ec-b862-acde48001122 -version: 6 -date: '2025-01-27' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.008 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -74,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_possible_access_to_sudoers_file.yml b/detections/endpoint/linux_possible_access_to_sudoers_file.yml index 2be5685254..92ff1b6f97 100644 --- a/detections/endpoint/linux_possible_access_to_sudoers_file.yml +++ b/detections/endpoint/linux_possible_access_to_sudoers_file.yml @@ -1,7 +1,7 @@ name: Linux Possible Access To Sudoers File id: 4479539c-71fc-11ec-b2e2-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -73,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/copy_file_stdoutpipe/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml b/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml index 928b9536fa..484cd366c6 100644 --- a/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml +++ b/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml @@ -1,7 +1,7 @@ name: Linux Possible Append Command To At Allow Config File id: 7bc20606-5f40-11ec-a586-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.002 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml b/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml index bf67c01e6a..d003d753b3 100644 --- a/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml +++ b/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml @@ -1,7 +1,7 @@ name: Linux Possible Append Command To Profile Config File id: 9c94732a-61af-11ec-91e3-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.004 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml b/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml index 5dc3a73b3b..419ae58634 100644 --- a/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml +++ b/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml @@ -1,7 +1,7 @@ name: Linux Possible Append Cronjob Entry on Existing Cronjob File id: b5b91200-5f27-11ec-bb4e-acde48001122 -version: 5 -date: '2024-12-19' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -47,7 +47,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml b/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml index 859463e22c..2b2ebb78dc 100644 --- a/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml +++ b/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml @@ -1,7 +1,7 @@ name: Linux Possible Cronjob Modification With Editor id: dcc89bde-5f24-11ec-87ca-acde48001122 -version: 5 -date: '2024-12-19' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -44,7 +44,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.003 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_possible_ssh_key_file_creation.yml b/detections/endpoint/linux_possible_ssh_key_file_creation.yml index a67d49a356..63df17e210 100644 --- a/detections/endpoint/linux_possible_ssh_key_file_creation.yml +++ b/detections/endpoint/linux_possible_ssh_key_file_creation.yml @@ -1,7 +1,7 @@ name: Linux Possible Ssh Key File Creation id: c04ef40c-72da-11ec-8eac-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1098.004 - - T1098 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_preload_hijack_library_calls.yml b/detections/endpoint/linux_preload_hijack_library_calls.yml index 9ad2401c00..051c3c042d 100644 --- a/detections/endpoint/linux_preload_hijack_library_calls.yml +++ b/detections/endpoint/linux_preload_hijack_library_calls.yml @@ -1,7 +1,7 @@ name: Linux Preload Hijack Library Calls id: cbe2ca30-631e-11ec-8670-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.006 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security @@ -73,6 +72,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/lib_hijack/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/lib_hijack/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_proxy_socks_curl.yml b/detections/endpoint/linux_proxy_socks_curl.yml index 1093bc6413..2501295d79 100644 --- a/detections/endpoint/linux_proxy_socks_curl.yml +++ b/detections/endpoint/linux_proxy_socks_curl.yml @@ -1,6 +1,6 @@ name: Linux Proxy Socks Curl id: bd596c22-ad1e-44fc-b242-817253ce8b08 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_puppet_privilege_escalation.yml b/detections/endpoint/linux_puppet_privilege_escalation.yml index 05c7c3d735..b6a4422129 100644 --- a/detections/endpoint/linux_puppet_privilege_escalation.yml +++ b/detections/endpoint/linux_puppet_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Puppet Privilege Escalation id: 1d19037f-466e-4d56-8d87-36fafd9aa3ce -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_rpm_privilege_escalation.yml b/detections/endpoint/linux_rpm_privilege_escalation.yml index 612f08ab5f..8f3021760f 100644 --- a/detections/endpoint/linux_rpm_privilege_escalation.yml +++ b/detections/endpoint/linux_rpm_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux RPM Privilege Escalation id: f8e58a23-cecd-495f-9c65-6c76b4cb9774 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ruby_privilege_escalation.yml b/detections/endpoint/linux_ruby_privilege_escalation.yml index b004b42783..42301ecd19 100644 --- a/detections/endpoint/linux_ruby_privilege_escalation.yml +++ b/detections/endpoint/linux_ruby_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Ruby Privilege Escalation id: 097b28b5-7004-4d40-a715-7e390501788b -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_service_file_created_in_systemd_directory.yml b/detections/endpoint/linux_service_file_created_in_systemd_directory.yml index 5d09d54a8e..84f9f74176 100644 --- a/detections/endpoint/linux_service_file_created_in_systemd_directory.yml +++ b/detections/endpoint/linux_service_file_created_in_systemd_directory.yml @@ -1,7 +1,7 @@ name: Linux Service File Created In Systemd Directory id: c7495048-61b6-11ec-9a37-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.006 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_service_restarted.yml b/detections/endpoint/linux_service_restarted.yml index b51395a490..e38b12f9c0 100644 --- a/detections/endpoint/linux_service_restarted.yml +++ b/detections/endpoint/linux_service_restarted.yml @@ -1,7 +1,7 @@ name: Linux Service Restarted id: 084275ba-61b8-11ec-8d64-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.006 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_service_started_or_enabled.yml b/detections/endpoint/linux_service_started_or_enabled.yml index ca91f33339..c5ee30eed0 100644 --- a/detections/endpoint/linux_service_started_or_enabled.yml +++ b/detections/endpoint/linux_service_started_or_enabled.yml @@ -1,7 +1,7 @@ name: Linux Service Started Or Enabled id: e0428212-61b7-11ec-88a3-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.006 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_setuid_using_chmod_utility.yml b/detections/endpoint/linux_setuid_using_chmod_utility.yml index 4355cf7209..91fc08356f 100644 --- a/detections/endpoint/linux_setuid_using_chmod_utility.yml +++ b/detections/endpoint/linux_setuid_using_chmod_utility.yml @@ -1,7 +1,7 @@ name: Linux Setuid Using Chmod Utility id: bf0304b6-6250-11ec-9d7c-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.001 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_setuid_using_setcap_utility.yml b/detections/endpoint/linux_setuid_using_setcap_utility.yml index 7092cc2521..55265c8fdf 100644 --- a/detections/endpoint/linux_setuid_using_setcap_utility.yml +++ b/detections/endpoint/linux_setuid_using_setcap_utility.yml @@ -1,7 +1,7 @@ name: Linux Setuid Using Setcap Utility id: 9d96022e-6250-11ec-9a19-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.001 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_sqlite3_privilege_escalation.yml b/detections/endpoint/linux_sqlite3_privilege_escalation.yml index 60c9288b4e..276443066d 100644 --- a/detections/endpoint/linux_sqlite3_privilege_escalation.yml +++ b/detections/endpoint/linux_sqlite3_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Linux Sqlite3 Privilege Escalation id: ab75dbb7-c3ba-4689-9c1b-8d2717bdcba1 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_ssh_authorized_keys_modification.yml b/detections/endpoint/linux_ssh_authorized_keys_modification.yml index a2a4c09110..d513ccb7c5 100644 --- a/detections/endpoint/linux_ssh_authorized_keys_modification.yml +++ b/detections/endpoint/linux_ssh_authorized_keys_modification.yml @@ -1,6 +1,6 @@ name: Linux SSH Authorized Keys Modification id: f5ab595e-28e5-4327-8077-5008ba97c850 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_ssh_remote_services_script_execute.yml b/detections/endpoint/linux_ssh_remote_services_script_execute.yml index 6fcbed4dcd..cddd81fa59 100644 --- a/detections/endpoint/linux_ssh_remote_services_script_execute.yml +++ b/detections/endpoint/linux_ssh_remote_services_script_execute.yml @@ -1,6 +1,6 @@ name: Linux SSH Remote Services Script Execute id: aa1748dd-4a5c-457a-9cf6-ca7b4eb711b3 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml b/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml index ce2ed01432..07665db54f 100644 --- a/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml +++ b/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml @@ -1,7 +1,7 @@ name: Linux Stdout Redirection To Dev Null File id: de62b809-a04d-46b5-9a15-8298d330f0c8 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: experimental type: Anomaly @@ -49,7 +49,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_sudo_or_su_execution.yml b/detections/endpoint/linux_sudo_or_su_execution.yml index 4d09a93bfb..da149584d5 100644 --- a/detections/endpoint/linux_sudo_or_su_execution.yml +++ b/detections/endpoint/linux_sudo_or_su_execution.yml @@ -1,7 +1,7 @@ name: Linux Sudo OR Su Execution id: 4b00f134-6d6a-11ec-a90c-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_sudoers_tmp_file_creation.yml b/detections/endpoint/linux_sudoers_tmp_file_creation.yml index 838f432cab..cd67ed8058 100644 --- a/detections/endpoint/linux_sudoers_tmp_file_creation.yml +++ b/detections/endpoint/linux_sudoers_tmp_file_creation.yml @@ -1,7 +1,7 @@ name: Linux Sudoers Tmp File Creation id: be254a5c-63e7-11ec-89da-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security @@ -67,6 +66,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/sudoers_temp/sysmon_linux.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/sudoers_temp/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux diff --git a/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml b/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml index e6fab0a962..d183c538ae 100644 --- a/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml +++ b/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml @@ -1,7 +1,7 @@ name: Linux Unix Shell Enable All SysRq Functions id: e7a96937-3b58-4962-8dce-538e4763cf15 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.004 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/linux_visudo_utility_execution.yml b/detections/endpoint/linux_visudo_utility_execution.yml index 93adeaf905..596d9a84c3 100644 --- a/detections/endpoint/linux_visudo_utility_execution.yml +++ b/detections/endpoint/linux_visudo_utility_execution.yml @@ -1,7 +1,7 @@ name: Linux Visudo Utility Execution id: 08c41040-624c-11ec-a71f-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.003 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/loading_of_dynwrapx_module.yml b/detections/endpoint/loading_of_dynwrapx_module.yml index 4b57f8a939..b84f0b040e 100644 --- a/detections/endpoint/loading_of_dynwrapx_module.yml +++ b/detections/endpoint/loading_of_dynwrapx_module.yml @@ -1,7 +1,7 @@ name: Loading Of Dynwrapx Module id: eac5e8ba-4857-11ec-9371-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - AsyncRAT asset_type: Endpoint mitre_attack_id: - - T1055 - T1055.001 product: - Splunk Enterprise diff --git a/detections/endpoint/local_account_discovery_with_wmic.yml b/detections/endpoint/local_account_discovery_with_wmic.yml index 7a5da713bb..85b07244d2 100644 --- a/detections/endpoint/local_account_discovery_with_wmic.yml +++ b/detections/endpoint/local_account_discovery_with_wmic.yml @@ -1,7 +1,7 @@ name: Local Account Discovery With Wmic id: 4902d7aa-0134-11ec-9d65-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -39,7 +39,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/endpoint/logon_script_event_trigger_execution.yml b/detections/endpoint/logon_script_event_trigger_execution.yml index 78ab8e9852..b27836b375 100644 --- a/detections/endpoint/logon_script_event_trigger_execution.yml +++ b/detections/endpoint/logon_script_event_trigger_execution.yml @@ -1,7 +1,7 @@ name: Logon Script Event Trigger Execution id: 4c38c264-1f74-11ec-b5fa-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Windows Persistence Techniques asset_type: Endpoint mitre_attack_id: - - T1037 - T1037.001 product: - Splunk Enterprise diff --git a/detections/endpoint/macos_lolbin.yml b/detections/endpoint/macos_lolbin.yml index 57a2ca77ce..364826a00d 100644 --- a/detections/endpoint/macos_lolbin.yml +++ b/detections/endpoint/macos_lolbin.yml @@ -1,7 +1,7 @@ name: MacOS LOLbin id: 58d270fb-5b39-418e-a855-4b8ac046805e -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Patrick Bareiss, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.004 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/mailsniper_invoke_functions.yml b/detections/endpoint/mailsniper_invoke_functions.yml index c61b356b5d..63412c881e 100644 --- a/detections/endpoint/mailsniper_invoke_functions.yml +++ b/detections/endpoint/mailsniper_invoke_functions.yml @@ -1,7 +1,7 @@ name: Mailsniper Invoke functions id: a36972c8-b894-11eb-9f78-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - Data Exfiltration asset_type: Endpoint mitre_attack_id: - - T1114 - T1114.001 product: - Splunk Enterprise diff --git a/detections/endpoint/malicious_powershell_executed_as_a_service.yml b/detections/endpoint/malicious_powershell_executed_as_a_service.yml index a846b2b6d5..9ce1a87d91 100644 --- a/detections/endpoint/malicious_powershell_executed_as_a_service.yml +++ b/detections/endpoint/malicious_powershell_executed_as_a_service.yml @@ -1,7 +1,7 @@ name: Malicious Powershell Executed As A Service id: 8e204dfd-cae0-4ea8-a61d-e972a1ff2ff8 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Ryan Becwar status: production type: TTP @@ -62,7 +62,6 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml index 228765bed3..ecc670ddcd 100644 --- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml +++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml @@ -1,7 +1,7 @@ name: Malicious PowerShell Process - Execution Policy Bypass id: 9be56c82-b1cc-4318-87eb-d138afaaca39 -version: 9 -date: '2025-01-27' +version: 10 +date: '2025-02-10' author: Rico Valdez, Mauricio Velazco, Splunk status: production type: Anomaly @@ -69,7 +69,6 @@ tags: - Volt Typhoon asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise @@ -79,6 +78,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/encoded_powershell/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml index 4e23a604b3..eb1e0f4e3a 100644 --- a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml +++ b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml @@ -1,7 +1,7 @@ name: Malicious PowerShell Process With Obfuscation Techniques id: cde75cf6-3c7a-4dd6-af01-27cdb4511fd4 -version: 9 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/microsoft_defender_atp_alerts.yml b/detections/endpoint/microsoft_defender_atp_alerts.yml index e18398545b..eba3aaecd3 100644 --- a/detections/endpoint/microsoft_defender_atp_alerts.yml +++ b/detections/endpoint/microsoft_defender_atp_alerts.yml @@ -1,6 +1,6 @@ name: Microsoft Defender ATP Alerts id: 38f034ed-1598-46c8-95e8-14edf05fdf5d -version: 2 +version: 3 date: '2025-01-20' author: Bryan Pluta, Bhavin Patel, Splunk status: production diff --git a/detections/endpoint/microsoft_defender_incident_alerts.yml b/detections/endpoint/microsoft_defender_incident_alerts.yml index 2133ecae98..4cae1ede0f 100644 --- a/detections/endpoint/microsoft_defender_incident_alerts.yml +++ b/detections/endpoint/microsoft_defender_incident_alerts.yml @@ -1,6 +1,6 @@ name: Microsoft Defender Incident Alerts id: 13435b55-afd8-46d4-9045-7d5457f430a5 -version: 2 +version: 3 date: '2025-01-20' author: Bryan Pluta, Bhavin Patel, Splunk status: production diff --git a/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml b/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml index 5a6def368f..5757d7a98d 100644 --- a/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml +++ b/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Mimikatz PassTheTicket CommandLine Parameters id: 13bbd574-83ac-11ec-99d4-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1550 - T1550.003 product: - Splunk Enterprise diff --git a/detections/endpoint/mmc_lolbas_execution_process_spawn.yml b/detections/endpoint/mmc_lolbas_execution_process_spawn.yml index a3e11e7507..a2db5e0210 100644 --- a/detections/endpoint/mmc_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/mmc_lolbas_execution_process_spawn.yml @@ -1,7 +1,7 @@ name: Mmc LOLBAS Execution Process Spawn id: f6601940-4c74-11ec-b9b7-3e22fbd008af -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.003 - T1218.014 product: diff --git a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml index d40890a563..51119f9f76 100644 --- a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml +++ b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml @@ -1,7 +1,7 @@ name: Monitor Registry Keys for Print Monitors id: f5f6af30-7ba7-4295-bfe9-07de87c01bbc -version: 9 -date: '2024-12-08' +version: 10 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick, Bhavin Patel status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.010 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml b/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml index df154acdcd..dff28e7dd0 100644 --- a/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml +++ b/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml @@ -1,7 +1,7 @@ name: MS Exchange Mailbox Replication service writing Active Server Pages id: 985f322c-57a5-11ec-b9ac-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: experimental type: TTP @@ -56,10 +56,9 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1505 - - T1505.003 - - T1190 - T1133 + - T1190 + - T1505.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/ms_scripting_process_loading_ldap_module.yml b/detections/endpoint/ms_scripting_process_loading_ldap_module.yml index f6c51367ef..eb406c8ba5 100644 --- a/detections/endpoint/ms_scripting_process_loading_ldap_module.yml +++ b/detections/endpoint/ms_scripting_process_loading_ldap_module.yml @@ -1,7 +1,7 @@ name: MS Scripting Process Loading Ldap Module id: 0b0c40dc-14a6-11ec-b267-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -54,7 +54,6 @@ tags: - FIN7 asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.007 product: - Splunk Enterprise diff --git a/detections/endpoint/ms_scripting_process_loading_wmi_module.yml b/detections/endpoint/ms_scripting_process_loading_wmi_module.yml index 58ecca447c..bfe6fe971f 100644 --- a/detections/endpoint/ms_scripting_process_loading_wmi_module.yml +++ b/detections/endpoint/ms_scripting_process_loading_wmi_module.yml @@ -1,7 +1,7 @@ name: MS Scripting Process Loading WMI Module id: 2eba3d36-14a6-11ec-a682-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: - FIN7 asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.007 product: - Splunk Enterprise diff --git a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml index 05fa46f331..2163163ec3 100644 --- a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml +++ b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml @@ -1,7 +1,7 @@ name: MSBuild Suspicious Spawned By Script Process id: 213b3148-24ea-11ec-93a2-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1127.001 - - T1127 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml index 904d7c0ff7..15849b0340 100644 --- a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml +++ b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml @@ -1,7 +1,7 @@ name: Mshta spawning Rundll32 OR Regsvr32 Process id: 4aa5d062-e893-11eb-9eb2-acde48001122 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/msi_module_loaded_by_non_system_binary.yml b/detections/endpoint/msi_module_loaded_by_non_system_binary.yml index 22fa5c3e01..2c944989d3 100644 --- a/detections/endpoint/msi_module_loaded_by_non_system_binary.yml +++ b/detections/endpoint/msi_module_loaded_by_non_system_binary.yml @@ -1,7 +1,7 @@ name: MSI Module Loaded by Non-System Binary id: ccb98a66-5851-11ec-b91c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -37,7 +37,6 @@ tags: - CVE-2021-41379 mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/msmpeng_application_dll_side_loading.yml b/detections/endpoint/msmpeng_application_dll_side_loading.yml index c6a910d2c8..70f151f1ee 100644 --- a/detections/endpoint/msmpeng_application_dll_side_loading.yml +++ b/detections/endpoint/msmpeng_application_dll_side_loading.yml @@ -1,7 +1,7 @@ name: Msmpeng Application DLL Side Loading id: 8bb3f280-dd9b-11eb-84d5-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Sanjay Govind status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/net_profiler_uac_bypass.yml b/detections/endpoint/net_profiler_uac_bypass.yml index 4a11fbd77f..66a59db29f 100644 --- a/detections/endpoint/net_profiler_uac_bypass.yml +++ b/detections/endpoint/net_profiler_uac_bypass.yml @@ -1,7 +1,7 @@ name: NET Profiler UAC bypass id: 0252ca80-e30d-11eb-8aa3-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/network_discovery_using_route_windows_app.yml b/detections/endpoint/network_discovery_using_route_windows_app.yml index cf9e62d47b..acea9bdc52 100644 --- a/detections/endpoint/network_discovery_using_route_windows_app.yml +++ b/detections/endpoint/network_discovery_using_route_windows_app.yml @@ -1,7 +1,7 @@ name: Network Discovery Using Route Windows App id: dd83407e-439f-11ec-ab8e-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -45,7 +45,6 @@ tags: - Prestige Ransomware asset_type: Endpoint mitre_attack_id: - - T1016 - T1016.001 product: - Splunk Enterprise diff --git a/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml b/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml index 5a05f52cd4..96fc75806e 100644 --- a/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml +++ b/detections/endpoint/network_traffic_to_active_directory_web_services_protocol.yml @@ -1,7 +1,7 @@ name: Network Traffic to Active Directory Web Services Protocol id: 68a0056c-34cb-455f-b03d-df935ea62c4f -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -37,13 +37,11 @@ tags: asset_type: Network atomic_guid: [] mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/nishang_powershelltcponeline.yml b/detections/endpoint/nishang_powershelltcponeline.yml index 3bca3b340a..676364635a 100644 --- a/detections/endpoint/nishang_powershelltcponeline.yml +++ b/detections/endpoint/nishang_powershelltcponeline.yml @@ -1,7 +1,7 @@ name: Nishang PowershellTCPOneLine id: 1a382c6c-7c2e-11eb-ac69-acde48001122 -version: 6 -date: '2024-12-16' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Cleo File Transfer Software asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml index fa4c8d036a..3a3b1fe2b8 100644 --- a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml +++ b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml @@ -1,7 +1,7 @@ name: Non Chrome Process Accessing Chrome Default Dir id: 81263de4-160a-11ec-944f-acde48001122 -version: 6 -date: '2025-01-27' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: - RedLine Stealer asset_type: Endpoint mitre_attack_id: - - T1555 - T1555.003 product: - Splunk Enterprise @@ -74,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/non_chrome_process_accessing_chrome_default_dir/windows-xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/non_chrome_process_accessing_chrome_default_dir/windows-xml.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog diff --git a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml index abc2b0fc09..8ba8350c73 100644 --- a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml +++ b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml @@ -1,7 +1,7 @@ name: Non Firefox Process Access Firefox Profile Dir id: e6fc13b0-1609-11ec-b533-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: - Snake Keylogger asset_type: Endpoint mitre_attack_id: - - T1555 - T1555.003 product: - Splunk Enterprise diff --git a/detections/endpoint/notepad_with_no_command_line_arguments.yml b/detections/endpoint/notepad_with_no_command_line_arguments.yml index 1b8e50b748..9598488359 100644 --- a/detections/endpoint/notepad_with_no_command_line_arguments.yml +++ b/detections/endpoint/notepad_with_no_command_line_arguments.yml @@ -1,6 +1,6 @@ name: Notepad with no Command Line Arguments id: 5adbc5f1-9a2f-41c1-a810-f37e015f8179 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk type: TTP diff --git a/detections/endpoint/ntdsutil_export_ntds.yml b/detections/endpoint/ntdsutil_export_ntds.yml index fee86a72ef..6272375790 100644 --- a/detections/endpoint/ntdsutil_export_ntds.yml +++ b/detections/endpoint/ntdsutil_export_ntds.yml @@ -1,7 +1,7 @@ name: Ntdsutil Export NTDS id: da63bc76-61ae-11eb-ae93-0242ac130002 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Patrick Bareiss, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index cf10053592..a81a27d1ef 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -1,7 +1,7 @@ name: Overwriting Accessibility Binaries id: 13c2f6c3-10c5-4deb-9ba1-7c4460ebe4ae -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Flax Typhoon asset_type: Endpoint mitre_attack_id: - - T1546 - T1546.008 product: - Splunk Enterprise diff --git a/detections/endpoint/permission_modification_using_takeown_app.yml b/detections/endpoint/permission_modification_using_takeown_app.yml index 8beee2753c..cb60ecf027 100644 --- a/detections/endpoint/permission_modification_using_takeown_app.yml +++ b/detections/endpoint/permission_modification_using_takeown_app.yml @@ -1,10 +1,10 @@ name: Permission Modification using Takeown App id: fa7ca5c6-c9d8-11eb-bce9-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-01-27' author: Teoderick Contreras, Splunk status: production -type: TTP +type: Anomaly description: The following analytic detects the modification of file or directory permissions using the takeown.exe Windows application. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs that include @@ -56,7 +56,7 @@ rba: risk_objects: - field: dest type: system - score: 56 + score: 30 threat_objects: - field: process_name type: process_name diff --git a/detections/endpoint/ping_sleep_batch_command.yml b/detections/endpoint/ping_sleep_batch_command.yml index 0b164dcc22..3123e4654a 100644 --- a/detections/endpoint/ping_sleep_batch_command.yml +++ b/detections/endpoint/ping_sleep_batch_command.yml @@ -1,7 +1,7 @@ name: Ping Sleep Batch Command id: ce058d6c-79f2-11ec-b476-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -71,7 +71,6 @@ tags: - Meduza Stealer asset_type: Endpoint mitre_attack_id: - - T1497 - T1497.003 product: - Splunk Enterprise diff --git a/detections/endpoint/possible_browser_pass_view_parameter.yml b/detections/endpoint/possible_browser_pass_view_parameter.yml index 5a2fdbcd71..65339f563a 100644 --- a/detections/endpoint/possible_browser_pass_view_parameter.yml +++ b/detections/endpoint/possible_browser_pass_view_parameter.yml @@ -1,7 +1,7 @@ name: Possible Browser Pass View Parameter id: 8ba484e8-4b97-11ec-b19a-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -46,7 +46,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1555.003 - - T1555 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml index a5e4e662a0..0829ca7479 100644 --- a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml +++ b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml @@ -1,7 +1,7 @@ name: Possible Lateral Movement PowerShell Spawn id: cb909b3e-512b-11ec-aa31-3e22fbd008af -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -76,14 +76,13 @@ tags: - CISA AA24-241A asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.003 - T1021.006 - T1047 - T1053.005 - - T1543.003 - T1059.001 - T1218.014 + - T1543.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/potential_system_network_configuration_discovery_activity.yml b/detections/endpoint/potential_system_network_configuration_discovery_activity.yml index 593947e09e..7939bcde78 100644 --- a/detections/endpoint/potential_system_network_configuration_discovery_activity.yml +++ b/detections/endpoint/potential_system_network_configuration_discovery_activity.yml @@ -1,6 +1,6 @@ name: Potential System Network Configuration Discovery Activity id: 3f0b95e3-3195-46ac-bea3-84fb59e7fac5 -version: 1 +version: 2 date: '2025-01-20' author: Bhavin Patel, Splunk status: production diff --git a/detections/endpoint/powershell_4104_hunting.yml b/detections/endpoint/powershell_4104_hunting.yml index bdf4328edc..e4c1ddafe7 100644 --- a/detections/endpoint/powershell_4104_hunting.yml +++ b/detections/endpoint/powershell_4104_hunting.yml @@ -1,7 +1,7 @@ name: PowerShell 4104 Hunting id: d6f2b006-0041-11ec-8885-acde48001122 -version: 10 -date: '2025-01-27' +version: 11 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -74,7 +74,6 @@ tags: - CISA AA24-241A asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise @@ -84,6 +83,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml b/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml index 4448706801..d69d9be400 100644 --- a/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml +++ b/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml @@ -1,7 +1,7 @@ name: PowerShell - Connect To Internet With Hidden Window id: ee18ed37-0802-4268-9435-b3b91aaa18db -version: 11 -date: '2024-11-13' +version: 12 +date: '2025-02-10' author: David Dorsey, Michael Haag Splunk status: production type: Hunting @@ -55,7 +55,6 @@ tags: - CVE-2021-44228 mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml b/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml index 568bb5677c..2999af89df 100644 --- a/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml +++ b/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml @@ -1,7 +1,7 @@ name: Powershell COM Hijacking InprocServer32 Modification id: ea61e291-af05-4716-932a-67faddb6ae6f -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -56,9 +56,8 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1546.015 - - T1059 - T1059.001 + - T1546.015 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_creating_thread_mutex.yml b/detections/endpoint/powershell_creating_thread_mutex.yml index 636784f5f6..17dc9e26a6 100644 --- a/detections/endpoint/powershell_creating_thread_mutex.yml +++ b/detections/endpoint/powershell_creating_thread_mutex.yml @@ -1,7 +1,7 @@ name: Powershell Creating Thread Mutex id: 637557ec-ca08-11eb-bd0a-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: - Malicious PowerShell asset_type: Endpoint mitre_attack_id: - - T1027 - T1027.005 - T1059.001 product: diff --git a/detections/endpoint/powershell_disable_security_monitoring.yml b/detections/endpoint/powershell_disable_security_monitoring.yml index acf1715048..1564ed0507 100644 --- a/detections/endpoint/powershell_disable_security_monitoring.yml +++ b/detections/endpoint/powershell_disable_security_monitoring.yml @@ -1,7 +1,7 @@ name: Powershell Disable Security Monitoring id: c148a894-dd93-11eb-bf2a-acde48001122 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_domain_enumeration.yml b/detections/endpoint/powershell_domain_enumeration.yml index f0d3a6b92e..b5d57545c4 100644 --- a/detections/endpoint/powershell_domain_enumeration.yml +++ b/detections/endpoint/powershell_domain_enumeration.yml @@ -1,7 +1,7 @@ name: PowerShell Domain Enumeration id: e1866ce2-ca22-11eb-8e44-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_enable_powershell_remoting.yml b/detections/endpoint/powershell_enable_powershell_remoting.yml index 8cfdb6a12c..412a67fcd6 100644 --- a/detections/endpoint/powershell_enable_powershell_remoting.yml +++ b/detections/endpoint/powershell_enable_powershell_remoting.yml @@ -1,7 +1,7 @@ name: PowerShell Enable PowerShell Remoting id: 40e3b299-19a5-4460-96e9-e1467f714f8e -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk type: Anomaly status: production @@ -53,7 +53,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_enable_smb1protocol_feature.yml b/detections/endpoint/powershell_enable_smb1protocol_feature.yml index 5778e667c4..4027bd9cbf 100644 --- a/detections/endpoint/powershell_enable_smb1protocol_feature.yml +++ b/detections/endpoint/powershell_enable_smb1protocol_feature.yml @@ -1,7 +1,7 @@ name: Powershell Enable SMB1Protocol Feature id: afed80b2-d34b-11eb-a952-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1027 - T1027.005 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_execute_com_object.yml b/detections/endpoint/powershell_execute_com_object.yml index afa898ec22..0829d8c7a5 100644 --- a/detections/endpoint/powershell_execute_com_object.yml +++ b/detections/endpoint/powershell_execute_com_object.yml @@ -1,7 +1,7 @@ name: Powershell Execute COM Object id: 65711630-f9bf-11eb-8d72-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -55,9 +55,8 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1546.015 - - T1546 - T1059.001 + - T1546.015 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml b/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml index d57deb4a84..be8d0a5b04 100644 --- a/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml +++ b/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml @@ -1,7 +1,7 @@ name: Powershell Fileless Process Injection via GetProcAddress id: a26d9db4-c883-11eb-9d75-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1059 - T1055 - T1059.001 product: diff --git a/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml b/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml index 220cb14ad7..c6cf407c05 100644 --- a/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml +++ b/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml @@ -1,7 +1,7 @@ name: Powershell Fileless Script Contains Base64 Encoded Content id: 8acbc04c-c882-11eb-b060-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: - IcedID - NjRAT mitre_attack_id: - - T1059 - T1027 - T1059.001 product: diff --git a/detections/endpoint/powershell_get_localgroup_discovery.yml b/detections/endpoint/powershell_get_localgroup_discovery.yml index cf5e6ada50..95170cb2f8 100644 --- a/detections/endpoint/powershell_get_localgroup_discovery.yml +++ b/detections/endpoint/powershell_get_localgroup_discovery.yml @@ -1,7 +1,7 @@ name: PowerShell Get LocalGroup Discovery id: b71adfcc-155b-11ec-9413-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml b/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml index 09e77be336..633fbc71a1 100644 --- a/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml +++ b/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml @@ -1,7 +1,7 @@ name: Powershell Get LocalGroup Discovery with Script Block Logging id: d7c6ad22-155c-11ec-bb64-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -35,7 +35,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_load_module_in_meterpreter.yml b/detections/endpoint/powershell_load_module_in_meterpreter.yml index de6090bb3f..48f13d3839 100644 --- a/detections/endpoint/powershell_load_module_in_meterpreter.yml +++ b/detections/endpoint/powershell_load_module_in_meterpreter.yml @@ -1,7 +1,7 @@ name: Powershell Load Module in Meterpreter id: d5905da5-d050-48db-9259-018d8f034fcf -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - MetaSploit asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml b/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml index d848c784db..d7d526e11e 100644 --- a/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml +++ b/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml @@ -1,16 +1,31 @@ name: PowerShell Loading DotNET into Memory via Reflection id: 85bc3f30-ca28-11eb-bd21-acde48001122 -version: 6 -date: '2025-01-16' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly data_source: - Powershell Script Block Logging 4104 -description: The following analytic detects the use of PowerShell scripts to load .NET assemblies into memory via reflection, a technique often used in malicious activities such as those by Empire and Cobalt Strike. It leverages PowerShell Script Block Logging (EventCode=4104) to capture and analyze the full command executed. This behavior is significant as it can indicate advanced attack techniques aiming to execute code in memory, bypassing traditional defenses. If confirmed malicious, this activity could lead to unauthorized code execution, privilege escalation, and persistent access within the environment. -search: '`powershell` EventCode=4104 ScriptBlockText IN ("*Reflection.Assembly]::Load*", "*Reflection.Assembly.Load*", "*UnsafeLoadFrom*", "*.LoadFrom(*", "*.LoadModule(*", "*.LoadWithPartialName*", "*ReflectionOnlyLoad*") | stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText | rename Computer as dest, UserID as user| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `powershell_loading_dotnet_into_memory_via_reflection_filter`' -how_to_implement: To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. -known_false_positives: False positives should be limited as day to day scripts do not use this method. +description: The following analytic detects the use of PowerShell scripts to load + .NET assemblies into memory via reflection, a technique often used in malicious + activities such as those by Empire and Cobalt Strike. It leverages PowerShell Script + Block Logging (EventCode=4104) to capture and analyze the full command executed. + This behavior is significant as it can indicate advanced attack techniques aiming + to execute code in memory, bypassing traditional defenses. If confirmed malicious, + this activity could lead to unauthorized code execution, privilege escalation, and + persistent access within the environment. +search: '`powershell` EventCode=4104 ScriptBlockText IN ("*Reflection.Assembly]::Load*", + "*Reflection.Assembly.Load*", "*UnsafeLoadFrom*", "*.LoadFrom(*", "*.LoadModule(*", + "*.LoadWithPartialName*", "*ReflectionOnlyLoad*") | stats count min(_time) as firstTime + max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText | rename + Computer as dest, UserID as user| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `powershell_loading_dotnet_into_memory_via_reflection_filter`' +how_to_implement: To successfully implement this analytic, you will need to enable + PowerShell Script Block Logging on some or all endpoints. Additional setup here + https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. +known_false_positives: False positives should be limited as day to day scripts do + not use this method. references: - https://docs.microsoft.com/en-us/dotnet/api/system.reflection.assembly?view=net-5.0 - https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. @@ -23,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" and "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$$", "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$$", + "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -48,7 +68,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise @@ -58,6 +77,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/reflection.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/reflection.log source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational - sourcetype: XmlWinEventLog \ No newline at end of file + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/powershell_processing_stream_of_data.yml b/detections/endpoint/powershell_processing_stream_of_data.yml index 24967a1f8b..76d78cf424 100644 --- a/detections/endpoint/powershell_processing_stream_of_data.yml +++ b/detections/endpoint/powershell_processing_stream_of_data.yml @@ -1,7 +1,7 @@ name: Powershell Processing Stream Of Data id: 0d718b52-c9f1-11eb-bc61-acde48001122 -version: 6 -date: '2024-11-22' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: - PXA Stealer asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/powershell_remote_services_add_trustedhost.yml b/detections/endpoint/powershell_remote_services_add_trustedhost.yml index f8535f004f..7a96343fb7 100644 --- a/detections/endpoint/powershell_remote_services_add_trustedhost.yml +++ b/detections/endpoint/powershell_remote_services_add_trustedhost.yml @@ -1,7 +1,7 @@ name: Powershell Remote Services Add TrustedHost id: bef21d24-297e-45e3-9b9a-c6ac45450474 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.006 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_remove_windows_defender_directory.yml b/detections/endpoint/powershell_remove_windows_defender_directory.yml index 6f0ea6b1e1..8b6f9c3a6d 100644 --- a/detections/endpoint/powershell_remove_windows_defender_directory.yml +++ b/detections/endpoint/powershell_remove_windows_defender_directory.yml @@ -1,7 +1,7 @@ name: Powershell Remove Windows Defender Directory id: adf47620-79fa-11ec-b248-acde48001122 -version: 6 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_start_bitstransfer.yml b/detections/endpoint/powershell_start_bitstransfer.yml index 104e8afe41..6b50ec5b4f 100644 --- a/detections/endpoint/powershell_start_bitstransfer.yml +++ b/detections/endpoint/powershell_start_bitstransfer.yml @@ -1,6 +1,6 @@ name: PowerShell Start-BitsTransfer id: 39e2605a-90d8-11eb-899e-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/powershell_using_memory_as_backing_store.yml b/detections/endpoint/powershell_using_memory_as_backing_store.yml index a57cf47628..e33e455cd2 100644 --- a/detections/endpoint/powershell_using_memory_as_backing_store.yml +++ b/detections/endpoint/powershell_using_memory_as_backing_store.yml @@ -1,7 +1,7 @@ name: Powershell Using memory As Backing Store id: c396a0c4-c9f2-11eb-b4f5-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_windows_defender_exclusion_commands.yml b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml index 7e80adf439..04e6fb422d 100644 --- a/detections/endpoint/powershell_windows_defender_exclusion_commands.yml +++ b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml @@ -1,7 +1,7 @@ name: Powershell Windows Defender Exclusion Commands id: 907ac95c-4dd9-11ec-ba2c-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml index 0bac5ac032..06ea69848f 100644 --- a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml +++ b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml @@ -1,6 +1,6 @@ name: Prevent Automatic Repair Mode using Bcdedit id: 7742aa92-c9d9-11eb-bbfc-acde48001122 -version: 4 +version: 5 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/print_processor_registry_autostart.yml b/detections/endpoint/print_processor_registry_autostart.yml index e162953369..04f8f2a5d4 100644 --- a/detections/endpoint/print_processor_registry_autostart.yml +++ b/detections/endpoint/print_processor_registry_autostart.yml @@ -1,7 +1,7 @@ name: Print Processor Registry Autostart id: 1f5b68aa-2037-11ec-898e-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: experimental type: TTP @@ -51,7 +51,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/print_spooler_adding_a_printer_driver.yml b/detections/endpoint/print_spooler_adding_a_printer_driver.yml index 1c47ffd8df..8afd39363a 100644 --- a/detections/endpoint/print_spooler_adding_a_printer_driver.yml +++ b/detections/endpoint/print_spooler_adding_a_printer_driver.yml @@ -1,7 +1,7 @@ name: Print Spooler Adding A Printer Driver id: 313681a2-da8e-11eb-adad-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - CVE-2021-1675 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml index 5e37c7894e..7ad22f6b32 100644 --- a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml +++ b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml @@ -1,7 +1,7 @@ name: Print Spooler Failed to Load a Plug-in id: 1adc9548-da7c-11eb-8f13-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: - CVE-2021-1675 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml index 4cf346c8fa..820170d6e4 100644 --- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml +++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml @@ -1,7 +1,7 @@ name: Process Creating LNK file in Suspicious Location id: 5d814af1-1041-47b5-a9ac-d754e82e9a26 -version: 9 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: Jose Hernandez, Michael Haag, Splunk status: production type: TTP @@ -70,7 +70,6 @@ tags: - Gozi Malware asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.002 product: - Splunk Enterprise diff --git a/detections/endpoint/process_kill_base_on_file_path.yml b/detections/endpoint/process_kill_base_on_file_path.yml index 22d03dda5e..1ec53796f1 100644 --- a/detections/endpoint/process_kill_base_on_file_path.yml +++ b/detections/endpoint/process_kill_base_on_file_path.yml @@ -1,7 +1,7 @@ name: Process Kill Base On File Path id: 5ffaa42c-acdb-11eb-9ad3-acde48001122 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index e719a57984..212cf0f860 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -1,7 +1,7 @@ name: Processes launching netsh id: b89919ed-fe5f-492c-b139-95dbb162040e -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Josef Kuepker, Splunk status: production type: Anomaly @@ -74,7 +74,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/randomly_generated_scheduled_task_name.yml b/detections/endpoint/randomly_generated_scheduled_task_name.yml index ddca4c00e3..d54a781091 100644 --- a/detections/endpoint/randomly_generated_scheduled_task_name.yml +++ b/detections/endpoint/randomly_generated_scheduled_task_name.yml @@ -1,7 +1,7 @@ name: Randomly Generated Scheduled Task Name id: 9d22a780-5165-11ec-ad4f-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: experimental type: Hunting @@ -33,7 +33,6 @@ tags: - Scheduled Tasks asset_type: Endpoint mitre_attack_id: - - T1053 - T1053.005 product: - Splunk Enterprise diff --git a/detections/endpoint/randomly_generated_windows_service_name.yml b/detections/endpoint/randomly_generated_windows_service_name.yml index da693af615..eac52741ca 100644 --- a/detections/endpoint/randomly_generated_windows_service_name.yml +++ b/detections/endpoint/randomly_generated_windows_service_name.yml @@ -1,7 +1,7 @@ name: Randomly Generated Windows Service Name id: 2032a95a-5165-11ec-a2c3-3e22fbd008af -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: experimental type: Hunting @@ -30,7 +30,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml b/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml index 15539d184d..b217c5d2a0 100644 --- a/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml +++ b/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml @@ -1,6 +1,6 @@ name: Recon AVProduct Through Pwh or WMI id: 28077620-c9f6-11eb-8785-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml index 3ba5e16d48..89aa7cb4e4 100644 --- a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml +++ b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml @@ -1,7 +1,7 @@ name: Recursive Delete of Directory In Batch CMD id: ba570b3a-d356-11eb-8358-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1070.004 - - T1070 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml index f11cc03166..096acf7bf7 100644 --- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml +++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml @@ -1,7 +1,7 @@ name: Reg exe Manipulating Windows Services Registry Keys id: 8470d755-0c13-45b3-bd63-387a373c10cf -version: 8 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: Rico Valdez, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.011 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/registry_keys_for_creating_shim_databases.yml b/detections/endpoint/registry_keys_for_creating_shim_databases.yml index 7d20f02115..aeec02af3e 100644 --- a/detections/endpoint/registry_keys_for_creating_shim_databases.yml +++ b/detections/endpoint/registry_keys_for_creating_shim_databases.yml @@ -1,7 +1,7 @@ name: Registry Keys for Creating SHIM Databases id: f5f6af30-7aa7-4295-bfe9-07fe87c01bbb -version: 10 -date: '2024-12-08' +version: 12 +date: '2025-02-10' author: Patrick Bareiss, Teoderick Contreras, Splunk, Steven Dick, Bhavin Patel status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.011 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 9f542cbcf2..841571bdaf 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -1,7 +1,7 @@ name: Registry Keys Used For Persistence id: f5f6af30-7aa7-4295-bfe9-07fe87c01a4b -version: 15 -date: '2025-01-27' +version: 16 +date: '2025-02-10' author: Jose Hernandez, David Dorsey, Teoderick Contreras, Rod Soto, Splunk status: production type: TTP @@ -109,7 +109,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.001 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security @@ -118,6 +117,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml index 37f1c77d98..fe8be39dd9 100644 --- a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml +++ b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Registry Keys Used For Privilege Escalation id: c9f4b923-f8af-4155-b697-1354f5bcbc5e -version: 11 -date: '2024-12-08' +version: 12 +date: '2025-02-10' author: David Dorsey, Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.012 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml index fa6a03e4f6..89f088a05b 100644 --- a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml +++ b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml @@ -1,7 +1,7 @@ name: Regsvr32 Silent and Install Param Dll Loading id: f421c250-24e7-11ec-bc43-acde48001122 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -76,7 +76,6 @@ tags: - Suspicious Regsvr32 Activity asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.010 product: - Splunk Enterprise diff --git a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml index 624108b462..43b74c27f5 100644 --- a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml +++ b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml @@ -1,7 +1,7 @@ name: Regsvr32 with Known Silent Switch Cmdline id: c9ef7dc4-eeaf-11eb-b2b6-acde48001122 -version: 6 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -76,7 +76,6 @@ tags: - AsyncRAT asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.010 product: - Splunk Enterprise diff --git a/detections/endpoint/remote_desktop_process_running_on_system.yml b/detections/endpoint/remote_desktop_process_running_on_system.yml index 98b7d2a398..90532d273c 100644 --- a/detections/endpoint/remote_desktop_process_running_on_system.yml +++ b/detections/endpoint/remote_desktop_process_running_on_system.yml @@ -1,7 +1,7 @@ name: Remote Desktop Process Running On System id: f5939373-8054-40ad-8c64-cec478a22a4a -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Hunting @@ -40,7 +40,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml index 538d923090..c9b9804885 100644 --- a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml @@ -1,7 +1,7 @@ name: Remote Process Instantiation via DCOM and PowerShell id: d4f42098-4680-11ec-ad07-3e22fbd008af -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.003 product: - Splunk Enterprise diff --git a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml index 4f4648445b..2b3c8abaab 100644 --- a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml +++ b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml @@ -1,7 +1,7 @@ name: Remote Process Instantiation via DCOM and PowerShell Script Block id: fa1c3040-4680-11ec-a618-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.003 product: - Splunk Enterprise diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml index 8b574d9bb7..fc7a0db67d 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml @@ -1,7 +1,7 @@ name: Remote Process Instantiation via WinRM and PowerShell id: ba24cda8-4716-11ec-8009-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.006 product: - Splunk Enterprise diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml index d2cff18278..63c06643c1 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml @@ -1,7 +1,7 @@ name: Remote Process Instantiation via WinRM and PowerShell Script Block id: 7d4c618e-4716-11ec-951c-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.006 product: - Splunk Enterprise diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml index 4d5ae43729..f2d3dcf4d5 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml @@ -1,7 +1,7 @@ name: Remote Process Instantiation via WinRM and Winrs id: 0dd296a2-4338-11ec-ba02-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.006 product: - Splunk Enterprise diff --git a/detections/endpoint/rubeus_command_line_parameters.yml b/detections/endpoint/rubeus_command_line_parameters.yml index 9a0fe4997a..8d0e78f4ef 100644 --- a/detections/endpoint/rubeus_command_line_parameters.yml +++ b/detections/endpoint/rubeus_command_line_parameters.yml @@ -1,7 +1,7 @@ name: Rubeus Command Line Parameters id: cca37478-8377-11ec-b59a-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -78,9 +78,7 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1550 - T1550.003 - - T1558 - T1558.003 - T1558.004 product: diff --git a/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml b/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml index e9200fe464..5950c1ca67 100644 --- a/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml +++ b/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml @@ -1,7 +1,7 @@ name: Rubeus Kerberos Ticket Exports Through Winlogon Access id: 5ed8c50a-8869-11ec-876f-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1550 - T1550.003 product: - Splunk Enterprise diff --git a/detections/endpoint/runas_execution_in_commandline.yml b/detections/endpoint/runas_execution_in_commandline.yml index dd66057bfe..0ed47331a5 100644 --- a/detections/endpoint/runas_execution_in_commandline.yml +++ b/detections/endpoint/runas_execution_in_commandline.yml @@ -1,7 +1,7 @@ name: Runas Execution in CommandLine id: 4807e716-43a4-11ec-a0e7-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -44,7 +44,6 @@ tags: - Windows Privilege Escalation asset_type: Endpoint mitre_attack_id: - - T1134 - T1134.001 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_control_rundll_hunt.yml b/detections/endpoint/rundll32_control_rundll_hunt.yml index dc0beb376a..b1ad8f7ef5 100644 --- a/detections/endpoint/rundll32_control_rundll_hunt.yml +++ b/detections/endpoint/rundll32_control_rundll_hunt.yml @@ -1,7 +1,7 @@ name: Rundll32 Control RunDLL Hunt id: c8e7ced0-10c5-11ec-8b03-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -50,7 +50,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml index aa845361b4..1d2585be25 100644 --- a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml +++ b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml @@ -1,7 +1,7 @@ name: Rundll32 Control RunDLL World Writable Directory id: 1adffe86-10c3-11ec-8ce6-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -81,7 +81,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_dnsquery.yml b/detections/endpoint/rundll32_dnsquery.yml index f72c6c3ba3..398448fbaf 100644 --- a/detections/endpoint/rundll32_dnsquery.yml +++ b/detections/endpoint/rundll32_dnsquery.yml @@ -1,7 +1,7 @@ name: Rundll32 DNSQuery id: f1483f5e-ee29-11eb-9d23-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_lockworkstation.yml b/detections/endpoint/rundll32_lockworkstation.yml index b3a0ca0968..4f3f8a2188 100644 --- a/detections/endpoint/rundll32_lockworkstation.yml +++ b/detections/endpoint/rundll32_lockworkstation.yml @@ -1,7 +1,7 @@ name: Rundll32 LockWorkStation id: fa90f372-f91d-11eb-816c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: - Ransomware asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_process_creating_exe_dll_files.yml b/detections/endpoint/rundll32_process_creating_exe_dll_files.yml index 7381fd77d0..b3203c8ad4 100644 --- a/detections/endpoint/rundll32_process_creating_exe_dll_files.yml +++ b/detections/endpoint/rundll32_process_creating_exe_dll_files.yml @@ -1,7 +1,7 @@ name: Rundll32 Process Creating Exe Dll Files id: 6338266a-ee2a-11eb-bf68-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml index b668edd1ef..23f1723414 100644 --- a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml @@ -1,7 +1,7 @@ name: Rundll32 with no Command Line Arguments with Network id: 35307032-a12d-11eb-835f-acde48001122 -version: 8 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Steven Dick, Michael Haag, Splunk status: production type: TTP @@ -78,7 +78,6 @@ tags: cve: - CVE-2021-34527 mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/endpoint/rundll_loading_dll_by_ordinal.yml index b8fccdd6c4..fc41b88df5 100644 --- a/detections/endpoint/rundll_loading_dll_by_ordinal.yml +++ b/detections/endpoint/rundll_loading_dll_by_ordinal.yml @@ -1,7 +1,7 @@ name: RunDLL Loading DLL By Ordinal id: 6c135f8d-5e60-454e-80b7-c56eed739833 -version: 9 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: Michael Haag, David Dorsey, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: - IcedID asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/ryuk_wake_on_lan_command.yml b/detections/endpoint/ryuk_wake_on_lan_command.yml index e7f88ed5c7..4bfc808d08 100644 --- a/detections/endpoint/ryuk_wake_on_lan_command.yml +++ b/detections/endpoint/ryuk_wake_on_lan_command.yml @@ -1,7 +1,7 @@ name: Ryuk Wake on LAN Command id: 538d0152-7aaa-11eb-beaa-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: - Ryuk Ransomware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.003 product: - Splunk Enterprise diff --git a/detections/endpoint/sam_database_file_access_attempt.yml b/detections/endpoint/sam_database_file_access_attempt.yml index e76cbb1396..2ce1ddaa93 100644 --- a/detections/endpoint/sam_database_file_access_attempt.yml +++ b/detections/endpoint/sam_database_file_access_attempt.yml @@ -1,7 +1,7 @@ name: SAM Database File Access Attempt id: 57551656-ebdb-11eb-afdf-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: - CVE-2021-36934 mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index ab462622b5..d08cad9a5b 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -1,7 +1,7 @@ name: Sc exe Manipulating Windows Services id: f0c693d8-2a89-4ce7-80b4-98fea4c3ea6d -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Rico Valdez, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.003 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml index fff2339458..1d84e7384b 100644 --- a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml +++ b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml @@ -1,7 +1,7 @@ name: SchCache Change By App Connect And Create ADSI Object id: 991eb510-0fc6-11ec-82d3-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml index 7732be5bf9..f23eb706b0 100644 --- a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml +++ b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml @@ -1,7 +1,7 @@ name: Scheduled Task Creation on Remote Endpoint using At id: 4be54858-432f-11ec-8209-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Scheduled Tasks asset_type: Endpoint mitre_attack_id: - - T1053 - T1053.002 product: - Splunk Enterprise diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index 3b47886f19..5090e71991 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -1,7 +1,7 @@ name: Scheduled Task Deleted Or Created via CMD id: d5af132c-7c17-439c-9d31-13d55340f36c -version: 10 -date: '2025-01-27' +version: 12 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -95,7 +95,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security @@ -104,6 +103,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml index 80d3a28e57..d44dbd1f24 100644 --- a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml +++ b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml @@ -1,7 +1,7 @@ name: Scheduled Task Initiation on Remote Endpoint id: 95cf4608-4302-11ec-8194-3e22fbd008af -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk, Badoodish, Github Community status: production type: TTP @@ -64,7 +64,6 @@ tags: - Scheduled Tasks asset_type: Endpoint mitre_attack_id: - - T1053 - T1053.005 product: - Splunk Enterprise diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index a32d7dca97..48b5d1fa98 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -1,7 +1,7 @@ name: Schtasks scheduling job on remote system id: 1297fb80-f42a-4b4a-9c8a-88c066237cf6 -version: 11 -date: '2024-12-10' +version: 12 +date: '2025-02-10' author: David Dorsey, Mauricio Velazco, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index 72e8073ffc..ff5ff09caa 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -1,7 +1,7 @@ name: Schtasks used for forcing a reboot id: 1297fb80-f42a-4b4a-9c8a-88c066437cf6 -version: 7 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml index 1b68e6996f..b7668b1a51 100644 --- a/detections/endpoint/screensaver_event_trigger_execution.yml +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -1,7 +1,7 @@ name: Screensaver Event Trigger Execution id: 58cea3ec-1f6d-11ec-8560-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1546 - T1546.002 product: - Splunk Enterprise diff --git a/detections/endpoint/sdclt_uac_bypass.yml b/detections/endpoint/sdclt_uac_bypass.yml index 4efac5ec1b..c6c89c02b0 100644 --- a/detections/endpoint/sdclt_uac_bypass.yml +++ b/detections/endpoint/sdclt_uac_bypass.yml @@ -1,7 +1,7 @@ name: Sdclt UAC Bypass id: d71efbf6-da63-11eb-8c6e-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/sdelete_application_execution.yml b/detections/endpoint/sdelete_application_execution.yml index 30f375f28a..10aefc21a4 100644 --- a/detections/endpoint/sdelete_application_execution.yml +++ b/detections/endpoint/sdelete_application_execution.yml @@ -1,7 +1,7 @@ name: Sdelete Application Execution id: 31702fc0-2682-11ec-85c3-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -65,9 +65,8 @@ tags: - Masquerading - Rename System Utilities asset_type: Endpoint mitre_attack_id: - - T1485 - T1070.004 - - T1070 + - T1485 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index f973ba81b6..fb76934525 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -1,7 +1,7 @@ name: SecretDumps Offline NTDS Dumping Tool id: 5672819c-be09-11eb-bbfb-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.003 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml index 735ed9149a..1abd21eb3c 100644 --- a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml +++ b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml @@ -1,6 +1,6 @@ name: ServicePrincipalNames Discovery with SetSPN id: ae8b3efc-2d2e-11ec-8b57-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/services_lolbas_execution_process_spawn.yml b/detections/endpoint/services_lolbas_execution_process_spawn.yml index 7d8de9c979..50ab6ea4fd 100644 --- a/detections/endpoint/services_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/services_lolbas_execution_process_spawn.yml @@ -1,7 +1,7 @@ name: Services LOLBAS Execution Process Spawn id: ba9e1954-4c04-11ec-8b74-3e22fbd008af -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: - CISA AA23-347A asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index edfccceae6..00822bc0c3 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -1,7 +1,7 @@ name: Set Default PowerShell Execution Policy To Unrestricted or Bypass id: c2590137-0b08-4985-9ec5-6ae23d92f63d -version: 12 -date: '2024-11-13' +version: 13 +date: '2025-02-10' author: Steven Dick, Patrick Bareiss, Splunk status: production type: TTP @@ -79,7 +79,6 @@ tags: - DarkGate Malware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/shim_database_file_creation.yml b/detections/endpoint/shim_database_file_creation.yml index 21a14c236b..21bd64b76b 100644 --- a/detections/endpoint/shim_database_file_creation.yml +++ b/detections/endpoint/shim_database_file_creation.yml @@ -1,7 +1,7 @@ name: Shim Database File Creation id: 6e4c4588-ba2f-42fa-97e6-9f6f548eaa33 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.011 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index 9e30f471ff..37302453aa 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -1,7 +1,7 @@ name: Shim Database Installation With Suspicious Parameters id: 404620de-46d8-48b6-90cc-8a8d7b0876a3 -version: 8 -date: '2024-12-16' +version: 9 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -17,8 +17,21 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sdbinst.exe NOT Processes.process IN ("\"C:\\Windows\\System32\\sdbinst.exe\"", "C:\\Windows\\System32\\sdbinst.exe", "*-mm", "*-?", "*-m -bg") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `shim_database_installation_with_suspicious_parameters_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` values(Processes.process) as process + min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.process_name = sdbinst.exe NOT Processes.process IN ("\"C:\\Windows\\System32\\sdbinst.exe\"", + "C:\\Windows\\System32\\sdbinst.exe", "*-mm", "*-?", "*-m -bg") by Processes.process_name + Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `shim_database_installation_with_suspicious_parameters_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: None identified references: [] drilldown_searches: @@ -53,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.011 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security @@ -62,6 +74,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index 528b8e0280..2004bdfab1 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -1,7 +1,7 @@ name: Short Lived Windows Accounts id: b25f6f62-0782-43c1-b403-083231ffd97d -version: 7 -date: '2024-11-22' +version: 8 +date: '2025-02-10' author: David Dorsey, Bhavin Patel, Splunk status: production type: TTP @@ -64,9 +64,8 @@ tags: - Active Directory Lateral Movement asset_type: Windows mitre_attack_id: - - T1136.001 - - T1136 - T1078.003 + - T1136.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/silentcleanup_uac_bypass.yml b/detections/endpoint/silentcleanup_uac_bypass.yml index 9c6c70c9c5..a18bda03a1 100644 --- a/detections/endpoint/silentcleanup_uac_bypass.yml +++ b/detections/endpoint/silentcleanup_uac_bypass.yml @@ -1,7 +1,7 @@ name: SilentCleanup UAC Bypass id: 56d7cfcc-da63-11eb-92d4-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index 29bfc12c8d..8c6caa9566 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -1,7 +1,7 @@ name: Single Letter Process On Endpoint id: a4214f0b-e01c-41bc-8cc4-d2b71e3056b4 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1204 - T1204.002 product: - Splunk Enterprise diff --git a/detections/endpoint/slui_runas_elevated.yml b/detections/endpoint/slui_runas_elevated.yml index 02cbd1a2ae..fccaeca2c1 100644 --- a/detections/endpoint/slui_runas_elevated.yml +++ b/detections/endpoint/slui_runas_elevated.yml @@ -1,7 +1,7 @@ name: SLUI RunAs Elevated id: 8d124810-b3e4-11eb-96c7-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/slui_spawning_a_process.yml b/detections/endpoint/slui_spawning_a_process.yml index a9b5887f11..118a53b0ef 100644 --- a/detections/endpoint/slui_spawning_a_process.yml +++ b/detections/endpoint/slui_spawning_a_process.yml @@ -1,7 +1,7 @@ name: SLUI Spawning a Process id: 879c4330-b3e0-11eb-b1b1-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/spoolsv_spawning_rundll32.yml b/detections/endpoint/spoolsv_spawning_rundll32.yml index 04f2ce636b..70da48f52e 100644 --- a/detections/endpoint/spoolsv_spawning_rundll32.yml +++ b/detections/endpoint/spoolsv_spawning_rundll32.yml @@ -1,7 +1,7 @@ name: Spoolsv Spawning Rundll32 id: 15d905f6-da6b-11eb-ab82-acde48001122 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: - CVE-2021-34527 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml index eda8f672d8..07a521d03e 100644 --- a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml +++ b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml @@ -1,7 +1,7 @@ name: Spoolsv Suspicious Loaded Modules id: a5e451f8-da81-11eb-b245-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: - CVE-2021-34527 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/spoolsv_suspicious_process_access.yml b/detections/endpoint/spoolsv_suspicious_process_access.yml index ee46ef235d..a41111a7b1 100644 --- a/detections/endpoint/spoolsv_suspicious_process_access.yml +++ b/detections/endpoint/spoolsv_suspicious_process_access.yml @@ -1,6 +1,6 @@ name: Spoolsv Suspicious Process Access id: 799b606e-da81-11eb-93f8-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml index e4665434d5..3111e77d23 100644 --- a/detections/endpoint/spoolsv_writing_a_dll.yml +++ b/detections/endpoint/spoolsv_writing_a_dll.yml @@ -1,7 +1,7 @@ name: Spoolsv Writing a DLL id: d5bf5cf2-da71-11eb-92c2-acde48001122 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -70,7 +70,6 @@ tags: - CVE-2021-34527 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml index 255480b538..de8fec23dd 100644 --- a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml +++ b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml @@ -1,7 +1,7 @@ name: Spoolsv Writing a DLL - Sysmon id: 347fd388-da87-11eb-836d-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - CVE-2021-34527 mitre_attack_id: - T1547.012 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_computer_account_name_change.yml b/detections/endpoint/suspicious_computer_account_name_change.yml index 25a57db4be..e7aaee43b7 100644 --- a/detections/endpoint/suspicious_computer_account_name_change.yml +++ b/detections/endpoint/suspicious_computer_account_name_change.yml @@ -1,7 +1,7 @@ name: Suspicious Computer Account Name Change id: 35a61ed8-61c4-11ec-bc1e-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - CVE-2021-42287 - CVE-2021-42278 mitre_attack_id: - - T1078 - T1078.002 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_copy_on_system32.yml b/detections/endpoint/suspicious_copy_on_system32.yml index 552376e126..74724bd7d7 100644 --- a/detections/endpoint/suspicious_copy_on_system32.yml +++ b/detections/endpoint/suspicious_copy_on_system32.yml @@ -1,7 +1,7 @@ name: Suspicious Copy on System32 id: ce633e56-25b2-11ec-9e76-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1036.003 - - T1036 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_event_log_service_behavior.yml b/detections/endpoint/suspicious_event_log_service_behavior.yml index bac4d7f013..6900ba2b70 100644 --- a/detections/endpoint/suspicious_event_log_service_behavior.yml +++ b/detections/endpoint/suspicious_event_log_service_behavior.yml @@ -1,7 +1,7 @@ name: Suspicious Event Log Service Behavior id: 2b85aa3d-f5f6-4c2e-a081-a09f6e1c2e40 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -33,7 +33,6 @@ tags: - Clop Ransomware asset_type: Endpoint mitre_attack_id: - - T1070 - T1070.001 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml index f966afa7c3..0af0bc7214 100644 --- a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml +++ b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml @@ -1,7 +1,7 @@ name: Suspicious IcedID Rundll32 Cmdline id: bed761f8-ee29-11eb-8bf3-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_kerberos_service_ticket_request.yml b/detections/endpoint/suspicious_kerberos_service_ticket_request.yml index b8c5f71cac..2f08209956 100644 --- a/detections/endpoint/suspicious_kerberos_service_ticket_request.yml +++ b/detections/endpoint/suspicious_kerberos_service_ticket_request.yml @@ -1,7 +1,7 @@ name: Suspicious Kerberos Service Ticket Request id: 8b1297bc-6204-11ec-b7c4-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - CVE-2021-42287 - CVE-2021-42278 mitre_attack_id: - - T1078 - T1078.002 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml index 31415533bd..4484fb6321 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml @@ -1,7 +1,7 @@ name: Suspicious microsoft workflow compiler rename id: f0db4464-55d9-11eb-ae93-0242ac130002 -version: 8 -date: '2024-11-13' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -47,9 +47,8 @@ tags: - Graceful Wipe Out Attack asset_type: Endpoint mitre_attack_id: - - T1036 - - T1127 - T1036.003 + - T1127 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml index 1ee9e409d7..fc2f44999f 100644 --- a/detections/endpoint/suspicious_msbuild_path.yml +++ b/detections/endpoint/suspicious_msbuild_path.yml @@ -1,7 +1,7 @@ name: Suspicious msbuild path id: f5198224-551c-11eb-ae93-0242ac130002 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -72,8 +72,6 @@ tags: - Graceful Wipe Out Attack asset_type: Endpoint mitre_attack_id: - - T1036 - - T1127 - T1036.003 - T1127.001 product: diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml index 438fcdeb92..f9bd30e77d 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/endpoint/suspicious_msbuild_rename.yml @@ -1,7 +1,7 @@ name: Suspicious MSBuild Rename id: 4006adac-5937-11eb-ae93-0242ac130002 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -48,8 +48,6 @@ tags: - Graceful Wipe Out Attack asset_type: Endpoint mitre_attack_id: - - T1036 - - T1127 - T1036.003 - T1127.001 product: diff --git a/detections/endpoint/suspicious_msbuild_spawn.yml b/detections/endpoint/suspicious_msbuild_spawn.yml index 1c23444d24..897b1fd22e 100644 --- a/detections/endpoint/suspicious_msbuild_spawn.yml +++ b/detections/endpoint/suspicious_msbuild_spawn.yml @@ -1,7 +1,7 @@ name: Suspicious MSBuild Spawn id: a115fba6-5514-11eb-ae93-0242ac130002 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1127 - T1127.001 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index 55035b8d46..7e5a50e44b 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -1,7 +1,7 @@ name: Suspicious mshta child process id: 60023bb6-5500-11eb-ae93-0242ac130002 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: - Lumma Stealer asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_mshta_spawn.yml b/detections/endpoint/suspicious_mshta_spawn.yml index 95a3c39c82..bffd402f2c 100644 --- a/detections/endpoint/suspicious_mshta_spawn.yml +++ b/detections/endpoint/suspicious_mshta_spawn.yml @@ -1,7 +1,7 @@ name: Suspicious mshta spawn id: 4d33a488-5b5f-11eb-ae93-0242ac130002 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.005 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_plistbuddy_usage.yml b/detections/endpoint/suspicious_plistbuddy_usage.yml index 76c97f45ec..f3dc262cfd 100644 --- a/detections/endpoint/suspicious_plistbuddy_usage.yml +++ b/detections/endpoint/suspicious_plistbuddy_usage.yml @@ -1,7 +1,7 @@ name: Suspicious PlistBuddy Usage id: c3194009-e0eb-4f84-87a9-4070f8688f00 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: experimental type: TTP @@ -53,7 +53,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.001 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml b/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml index 6bb4e11150..ec7ee9dc78 100644 --- a/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml +++ b/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml @@ -1,7 +1,7 @@ name: Suspicious PlistBuddy Usage via OSquery id: 20ba6c32-c733-4a32-b64e-2688cf231399 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: experimental type: TTP @@ -37,7 +37,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.001 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml index 1bce9c0f7d..d239401dda 100644 --- a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml +++ b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml @@ -1,7 +1,7 @@ name: Suspicious Process DNS Query Known Abuse Web Services id: 3cf0dc36-484d-11ec-a6bc-acde48001122 -version: 8 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.005 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_process_with_discord_dns_query.yml b/detections/endpoint/suspicious_process_with_discord_dns_query.yml index 29366f73c9..4dd954857d 100644 --- a/detections/endpoint/suspicious_process_with_discord_dns_query.yml +++ b/detections/endpoint/suspicious_process_with_discord_dns_query.yml @@ -1,7 +1,7 @@ name: Suspicious Process With Discord DNS Query id: 4d4332ae-792c-11ec-89c1-acde48001122 -version: 6 -date: '2024-11-22' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.005 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index 1d7dfc280a..0add6178bb 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -1,6 +1,6 @@ name: Suspicious Reg exe Process id: a6b3ab4e-dd77-4213-95fa-fc94701995e0 -version: 8 +version: 9 date: '2024-11-13' author: David Dorsey, Splunk status: production diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml index 65c6989495..598771f5eb 100644 --- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml +++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml @@ -1,7 +1,7 @@ name: Suspicious Regsvr32 Register Suspicious Path id: 62732736-6250-11eb-ae93-0242ac130002 -version: 10 -date: '2025-01-27' +version: 12 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -82,7 +82,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.010 product: - Splunk Enterprise @@ -92,6 +91,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.010/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml index 31ca3d198e..3a91a79903 100644 --- a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml +++ b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 dllregisterserver id: 8c00a385-9b86-4ac0-8932-c9ec3713b159 -version: 6 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -78,7 +78,6 @@ tags: - IcedID asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml b/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml index 519b5bc050..a409f211ca 100644 --- a/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 no Command Line Arguments id: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: cve: - CVE-2021-34527 mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_rundll32_plugininit.yml b/detections/endpoint/suspicious_rundll32_plugininit.yml index ab0d1c31be..1d83ad1012 100644 --- a/detections/endpoint/suspicious_rundll32_plugininit.yml +++ b/detections/endpoint/suspicious_rundll32_plugininit.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 PluginInit id: 92d51712-ee29-11eb-b1ae-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - IcedID asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_rundll32_startw.yml b/detections/endpoint/suspicious_rundll32_startw.yml index 2c39e6dec8..734b077b09 100644 --- a/detections/endpoint/suspicious_rundll32_startw.yml +++ b/detections/endpoint/suspicious_rundll32_startw.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 StartW id: 9319dda5-73f2-4d43-a85a-67ce961bddb7 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: - Graceful Wipe Out Attack asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index 7fce587c31..8e78c248d6 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -1,7 +1,7 @@ name: Suspicious Scheduled Task from Public Directory id: 7feb7972-7ac3-11eb-bac8-acde48001122 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -81,7 +81,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security @@ -90,6 +89,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtasks/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtasks/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/suspicious_ticket_granting_ticket_request.yml b/detections/endpoint/suspicious_ticket_granting_ticket_request.yml index 069de0c8e2..e51bfe28b4 100644 --- a/detections/endpoint/suspicious_ticket_granting_ticket_request.yml +++ b/detections/endpoint/suspicious_ticket_granting_ticket_request.yml @@ -1,7 +1,7 @@ name: Suspicious Ticket Granting Ticket Request id: d77d349e-6269-11ec-9cfe-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -39,7 +39,6 @@ tags: - Active Directory Privilege Escalation asset_type: Endpoint mitre_attack_id: - - T1078 - T1078.002 product: - Splunk Enterprise diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index 321027b633..39b6278f58 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -1,7 +1,7 @@ name: Suspicious wevtutil Usage id: 2827c0fd-e1be-4868-ae25-59d28e0f9d4f -version: 8 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: David Dorsey, Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1070.001 - - T1070 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/svchost_lolbas_execution_process_spawn.yml b/detections/endpoint/svchost_lolbas_execution_process_spawn.yml index 256c4e7869..ef195b0980 100644 --- a/detections/endpoint/svchost_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/svchost_lolbas_execution_process_spawn.yml @@ -1,7 +1,7 @@ name: Svchost LOLBAS Execution Process Spawn id: 09e5c72a-4c0d-11ec-aa29-3e22fbd008af -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: - Scheduled Tasks asset_type: Endpoint mitre_attack_id: - - T1053 - T1053.005 product: - Splunk Enterprise diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index 689b31f757..4821dfd05e 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -1,7 +1,7 @@ name: System Processes Run From Unexpected Locations id: a34aae96-ccf8-4aef-952c-3ea21444444d -version: 9 -date: '2024-11-13' +version: 10 +date: '2025-02-10' author: David Dorsey, Michael Haag, Splunk status: production type: Anomaly @@ -72,7 +72,6 @@ tags: - DarkGate Malware asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.003 product: - Splunk Enterprise diff --git a/detections/endpoint/system_user_discovery_with_query.yml b/detections/endpoint/system_user_discovery_with_query.yml index 249c62b457..cd0788aeb9 100644 --- a/detections/endpoint/system_user_discovery_with_query.yml +++ b/detections/endpoint/system_user_discovery_with_query.yml @@ -1,7 +1,7 @@ name: System User Discovery With Query id: ad03bfcf-8a91-4bc2-a500-112993deba87 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-05' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -17,9 +17,8 @@ data_source: - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe") - (Processes.process=*user*) by Processes.dest Processes.user Processes.parent_process - Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe" OR Processes.original_file_name="query.exe") + AND Processes.process="*user*" AND ((NOT Processes.process="*/server*") OR Processes.process IN ("*/server:localhost*", "*/server:127.0.0.1*")) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `system_user_discovery_with_query_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml index 98a2391ac9..9ebc6d728f 100644 --- a/detections/endpoint/time_provider_persistence_registry.yml +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -1,7 +1,7 @@ name: Time Provider Persistence Registry id: 5ba382c4-2105-11ec-8d8f-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.003 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml b/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml index 669ef87e2e..03661c70d7 100644 --- a/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml +++ b/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml @@ -1,7 +1,7 @@ name: UAC Bypass MMC Load Unsigned Dll id: 7f04349c-e30d-11eb-bc7f-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -55,9 +55,8 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1548.002 - - T1548 - T1218.014 + - T1548.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/uac_bypass_with_colorui_com_object.yml b/detections/endpoint/uac_bypass_with_colorui_com_object.yml index c93938fb95..3b5ec1cdb6 100644 --- a/detections/endpoint/uac_bypass_with_colorui_com_object.yml +++ b/detections/endpoint/uac_bypass_with_colorui_com_object.yml @@ -1,7 +1,7 @@ name: UAC Bypass With Colorui COM Object id: 2bcccd20-fc2b-11eb-8d22-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - LockBit Ransomware asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.003 product: - Splunk Enterprise diff --git a/detections/endpoint/uninstall_app_using_msiexec.yml b/detections/endpoint/uninstall_app_using_msiexec.yml index 95e609aade..06248d5f3b 100644 --- a/detections/endpoint/uninstall_app_using_msiexec.yml +++ b/detections/endpoint/uninstall_app_using_msiexec.yml @@ -1,7 +1,7 @@ name: Uninstall App Using MsiExec id: 1fca2b28-f922-11eb-b2dd-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.007 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index 93302c30ba..74f3715365 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -1,7 +1,7 @@ name: Unload Sysmon Filter Driver id: e5928ff3-23eb-4d8b-b8a4-dcbc844fdfbe -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/unloading_amsi_via_reflection.yml b/detections/endpoint/unloading_amsi_via_reflection.yml index 3fba97f093..63a2cee57d 100644 --- a/detections/endpoint/unloading_amsi_via_reflection.yml +++ b/detections/endpoint/unloading_amsi_via_reflection.yml @@ -1,7 +1,7 @@ name: Unloading AMSI via Reflection id: a21e3484-c94d-11eb-b55b-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -57,9 +57,8 @@ tags: - Data Destruction asset_type: Endpoint mitre_attack_id: - - T1562 - T1059.001 - - T1059 + - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml b/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml index 7735319ec4..58affd514e 100644 --- a/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml +++ b/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml @@ -1,7 +1,7 @@ name: Unusual Number of Kerberos Service Tickets Requested id: eb3e6702-8936-11ec-98fe-acde48001122 -version: 6 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Mauricio Velazco, Dean Luxton, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.003 product: - Splunk Enterprise diff --git a/detections/endpoint/vbscript_execution_using_wscript_app.yml b/detections/endpoint/vbscript_execution_using_wscript_app.yml index e9fd89ca8c..a7a87ba473 100644 --- a/detections/endpoint/vbscript_execution_using_wscript_app.yml +++ b/detections/endpoint/vbscript_execution_using_wscript_app.yml @@ -1,7 +1,7 @@ name: Vbscript Execution Using Wscript App id: 35159940-228f-11ec-8a49-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.005 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/verclsid_clsid_execution.yml b/detections/endpoint/verclsid_clsid_execution.yml index fa5b44a719..f45344915b 100644 --- a/detections/endpoint/verclsid_clsid_execution.yml +++ b/detections/endpoint/verclsid_clsid_execution.yml @@ -1,7 +1,7 @@ name: Verclsid CLSID Execution id: 61e9a56a-20fa-11ec-8ba3-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -45,7 +45,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.012 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml index 30d7cd3caa..21d2e3fb4f 100644 --- a/detections/endpoint/w3wp_spawning_shell.yml +++ b/detections/endpoint/w3wp_spawning_shell.yml @@ -1,7 +1,7 @@ name: W3WP Spawning Shell id: 0f03423c-7c6a-11eb-bc47-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -79,7 +79,6 @@ tags: - CVE-2021-34523 - CVE-2021-31207 mitre_attack_id: - - T1505 - T1505.003 product: - Splunk Enterprise diff --git a/detections/endpoint/wbemprox_com_object_execution.yml b/detections/endpoint/wbemprox_com_object_execution.yml index 6e770d7563..3a63ebc37c 100644 --- a/detections/endpoint/wbemprox_com_object_execution.yml +++ b/detections/endpoint/wbemprox_com_object_execution.yml @@ -1,7 +1,7 @@ name: Wbemprox COM Object Execution id: 9d911ce0-c3be-11eb-b177-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - LockBit Ransomware asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.003 product: - Splunk Enterprise diff --git a/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml b/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml index fe60773917..5a0d5637a2 100644 --- a/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml +++ b/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml @@ -1,7 +1,7 @@ name: Wermgr Process Connecting To IP Check Web Services id: ed313326-a0f9-11eb-a89c-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - Trickbot asset_type: Endpoint mitre_attack_id: - - T1590 - T1590.005 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml index 9f00ab5ca2..66a85dd28f 100644 --- a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml +++ b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml @@ -1,7 +1,7 @@ name: Windows Access Token Manipulation SeDebugPrivilege id: 6ece9ed0-5f92-4315-889d-48560472b188 -version: 10 -date: '2025-01-27' +version: 11 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.002 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security @@ -79,6 +78,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/brute_ratel/sedebugprivilege_token/security-xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/brute_ratel/sedebugprivilege_token/security-xml.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml b/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml index 4dbd423a92..dd647d1112 100644 --- a/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml +++ b/detections/endpoint/windows_access_token_manipulation_winlogon_duplicate_token_handle.yml @@ -1,7 +1,7 @@ name: Windows Access Token Manipulation Winlogon Duplicate Token Handle id: dda126d7-1d99-4f0b-b72a-4c14031f9398 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -35,7 +35,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.001 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml b/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml index b3cc876fb9..662e51dcaf 100644 --- a/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml +++ b/detections/endpoint/windows_access_token_winlogon_duplicate_handle_in_uncommon_path.yml @@ -1,7 +1,7 @@ name: Windows Access Token Winlogon Duplicate Handle In Uncommon Path id: b8f7ed6b-0556-4c84-bffd-839c262b0278 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.001 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml b/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml index 709d34b600..efd6e3dd18 100644 --- a/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml +++ b/detections/endpoint/windows_account_access_removal_via_logoff_exec.yml @@ -1,21 +1,27 @@ name: Windows Account Access Removal via Logoff Exec id: 223572ab-8768-4e20-9b39-c38707af80dc -version: 1 -date: '2024-12-17' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Sysmon EventID 1 type: Anomaly status: production -description: The following analytic detects the process of logging off a user through the use of the quser and logoff commands. By monitoring for these commands, the analytic identifies actions where a user session is forcibly terminated, which could be part of an administrative task or a potentially unauthorized access attempt. This detection helps identify potential misuse or malicious activity where a user’s access is revoked without proper authorization, providing insight into potential security incidents involving account management or session manipulation. -search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where Processes.process_name = logoff.exe - by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_guid Processes.dest Processes.user - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `windows_account_access_removal_via_logoff_exec_filter`' -how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. +description: The following analytic detects the process of logging off a user through + the use of the quser and logoff commands. By monitoring for these commands, the + analytic identifies actions where a user session is forcibly terminated, which could + be part of an administrative task or a potentially unauthorized access attempt. + This detection helps identify potential misuse or malicious activity where a user’s + access is revoked without proper authorization, providing insight into potential + security incidents involving account management or session manipulation. +search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name = logoff.exe + by Processes.parent_process_name Processes.parent_process Processes.process_name + Processes.process Processes.process_guid Processes.dest Processes.user | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_account_access_removal_via_logoff_exec_filter`' +how_to_implement: The following Hunting analytic requires PowerShell operational logs + to be imported. Modify the powershell macro as needed to match the sourcetype or + add index. This analytic is specific to 4104, or PowerShell Script Block Logging. known_false_positives: Administrators or power users may use this command. references: - https://devblogs.microsoft.com/scripting/automating-quser-through-powershell/ @@ -25,7 +31,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -43,9 +54,8 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1531 - T1059.001 - - T1059 + - T1531 product: - Splunk Enterprise - Splunk Enterprise Security @@ -54,6 +64,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/powershell_log_process_tree/powershell_logoff.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/powershell_log_process_tree/powershell_logoff.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml b/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml index 501c9abd55..7ddbfdb697 100644 --- a/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml +++ b/detections/endpoint/windows_account_discovery_for_none_disable_user_account.yml @@ -1,7 +1,7 @@ name: Windows Account Discovery for None Disable User Account id: eddbf5ba-b89e-47ca-995e-2d259804e55e -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -35,7 +35,6 @@ tags: - CISA AA23-347A asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_ad_abnormal_object_access_activity.yml b/detections/endpoint/windows_ad_abnormal_object_access_activity.yml index d950358d37..30e8c78866 100644 --- a/detections/endpoint/windows_ad_abnormal_object_access_activity.yml +++ b/detections/endpoint/windows_ad_abnormal_object_access_activity.yml @@ -1,7 +1,7 @@ name: Windows AD Abnormal Object Access Activity id: 71b289db-5f2c-4c43-8256-8bf26ae7324a -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -60,7 +60,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml index 9b011c912c..87740e631d 100644 --- a/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml +++ b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml @@ -1,6 +1,6 @@ name: Windows AD AdminSDHolder ACL Modified id: 00d877c3-7b7b-443d-9562-6b231e2abab9 -version: 5 +version: 6 date: '2024-11-13' author: Mauricio Velazco, Dean Luxton, Splunk type: TTP diff --git a/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml b/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml index 1a951ffa45..79de518830 100644 --- a/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml +++ b/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml @@ -1,7 +1,7 @@ name: Windows AD Cross Domain SID History Addition id: 41bbb371-28ba-439c-bb5c-d9930c28365d -version: 5 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Dean Luxton type: TTP status: production @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.005 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ad_domain_replication_acl_addition.yml b/detections/endpoint/windows_ad_domain_replication_acl_addition.yml index 5afac44a1b..a303064df9 100644 --- a/detections/endpoint/windows_ad_domain_replication_acl_addition.yml +++ b/detections/endpoint/windows_ad_domain_replication_acl_addition.yml @@ -1,6 +1,6 @@ name: Windows AD Domain Replication ACL Addition id: 8c372853-f459-4995-afdc-280c114d33ab -version: 7 +version: 8 date: '2024-12-10' author: Dean Luxton type: TTP diff --git a/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml b/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml index b27e21cabe..c41aece18f 100644 --- a/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml +++ b/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml @@ -1,7 +1,7 @@ name: Windows AD Privileged Account SID History Addition id: 6b521149-b91c-43aa-ba97-c2cac59ec830 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Dean Luxton type: TTP status: production @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.005 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ad_privileged_object_access_activity.yml b/detections/endpoint/windows_ad_privileged_object_access_activity.yml index 022e799c23..505c7fd59b 100644 --- a/detections/endpoint/windows_ad_privileged_object_access_activity.yml +++ b/detections/endpoint/windows_ad_privileged_object_access_activity.yml @@ -1,7 +1,7 @@ name: Windows AD Privileged Object Access Activity id: dc2f58bc-8cd2-4e51-962a-694b963acde0 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -64,7 +64,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml b/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml index 559582d368..942a561d39 100644 --- a/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml +++ b/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml @@ -1,7 +1,7 @@ name: Windows AD Replication Request Initiated by User Account id: 51307514-1236-49f6-8686-d46d93cc2821 -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Dean Luxton type: TTP status: production @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.006 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml b/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml index 1d6a7be15c..7ec27540f3 100644 --- a/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml +++ b/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml @@ -1,7 +1,7 @@ name: Windows AD Replication Request Initiated from Unsanctioned Location id: 50998483-bb15-457b-a870-965080d9e3d3 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Dean Luxton type: TTP status: production @@ -77,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.006 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml b/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml index 00764a6d79..06ebf8cd4c 100644 --- a/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml +++ b/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml @@ -1,7 +1,7 @@ name: Windows AD Same Domain SID History Addition id: 5fde0b7c-df7a-40b1-9b3a-294c00f0289d -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Dean Luxton type: TTP status: production @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.005 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ad_sid_history_attribute_modified.yml b/detections/endpoint/windows_ad_sid_history_attribute_modified.yml index 55ba1e1045..65a1e2eedf 100644 --- a/detections/endpoint/windows_ad_sid_history_attribute_modified.yml +++ b/detections/endpoint/windows_ad_sid_history_attribute_modified.yml @@ -1,7 +1,7 @@ name: Windows AD SID History Attribute Modified id: 1155e47d-307f-4247-beab-71071e3a458c -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk type: TTP status: production @@ -56,7 +56,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1134 - T1134.005 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_admon_default_group_policy_object_modified.yml b/detections/endpoint/windows_admon_default_group_policy_object_modified.yml index dba80bbc1b..4194594106 100644 --- a/detections/endpoint/windows_admon_default_group_policy_object_modified.yml +++ b/detections/endpoint/windows_admon_default_group_policy_object_modified.yml @@ -1,7 +1,7 @@ name: Windows Admon Default Group Policy Object Modified id: 83458004-db60-4170-857d-8572f16f070b -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - T1484.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_admon_group_policy_object_created.yml b/detections/endpoint/windows_admon_group_policy_object_created.yml index 83a1435afa..88224156c8 100644 --- a/detections/endpoint/windows_admon_group_policy_object_created.yml +++ b/detections/endpoint/windows_admon_group_policy_object_created.yml @@ -1,7 +1,7 @@ name: Windows Admon Group Policy Object Created id: 69201633-30d9-48ef-b1b6-e680805f0582 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - T1484.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_alternate_datastream___base64_content.yml b/detections/endpoint/windows_alternate_datastream___base64_content.yml index 7a95b21409..ecd4e049de 100644 --- a/detections/endpoint/windows_alternate_datastream___base64_content.yml +++ b/detections/endpoint/windows_alternate_datastream___base64_content.yml @@ -1,7 +1,7 @@ name: Windows Alternate DataStream - Base64 Content id: 683f48de-982f-4a7e-9aac-9cec550da498 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Michael Haag, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1564 - T1564.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_alternate_datastream___executable_content.yml b/detections/endpoint/windows_alternate_datastream___executable_content.yml index 9ff5c8ee67..b60c3f31df 100644 --- a/detections/endpoint/windows_alternate_datastream___executable_content.yml +++ b/detections/endpoint/windows_alternate_datastream___executable_content.yml @@ -1,7 +1,7 @@ name: Windows Alternate DataStream - Executable Content id: a258bf2a-34fd-4986-8086-78f506e00206 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1564 - T1564.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_alternate_datastream___process_execution.yml b/detections/endpoint/windows_alternate_datastream___process_execution.yml index 3e11a4fef5..8f69a19e36 100644 --- a/detections/endpoint/windows_alternate_datastream___process_execution.yml +++ b/detections/endpoint/windows_alternate_datastream___process_execution.yml @@ -1,7 +1,7 @@ name: Windows Alternate DataStream - Process Execution id: 30c32c5c-41fe-45db-84fe-275e4320da3f -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -65,7 +65,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1564 - T1564.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_apache_benchmark_binary.yml b/detections/endpoint/windows_apache_benchmark_binary.yml index 17a494d0c6..ecbb29f74e 100644 --- a/detections/endpoint/windows_apache_benchmark_binary.yml +++ b/detections/endpoint/windows_apache_benchmark_binary.yml @@ -1,6 +1,6 @@ name: Windows Apache Benchmark Binary id: 894f48ea-8d85-4dcd-9132-c66cdb407c9b -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_archive_collected_data_via_rar.yml b/detections/endpoint/windows_archive_collected_data_via_rar.yml index d3403433b5..7a1bc686a4 100644 --- a/detections/endpoint/windows_archive_collected_data_via_rar.yml +++ b/detections/endpoint/windows_archive_collected_data_via_rar.yml @@ -1,7 +1,7 @@ name: Windows Archive Collected Data via Rar id: 2015de95-fe91-413d-9d62-2fe011b67e82 -version: 5 -date: '2025-01-27' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1560.001 - - T1560 product: - Splunk Enterprise - Splunk Enterprise Security @@ -76,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility_darkgate/rar_sys.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility_darkgate/rar_sys.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_attempt_to_stop_security_service.yml b/detections/endpoint/windows_attempt_to_stop_security_service.yml index 44e85bbc42..79ccda8ff8 100644 --- a/detections/endpoint/windows_attempt_to_stop_security_service.yml +++ b/detections/endpoint/windows_attempt_to_stop_security_service.yml @@ -1,18 +1,42 @@ name: Windows Attempt To Stop Security Service id: 9ed27cea-4e27-4eff-b2c6-aac9e78a7517 -version: 1 -date: '2025-01-13' +version: 3 +date: '2025-02-10' author: Rico Valdez, Nasreddine Bencherchali, Splunk status: production type: TTP -description: The following analytic detects attempts to stop security-related services on an endpoint, which may indicate malicious activity. It leverages data from Endpoint Detection and Response (EDR) agents, specifically searching for processes involving the "sc.exe" or "net.exe" command with the "stop" parameter or the PowerShell "Stop-Service" cmdlet. This activity is significant because disabling security services can undermine the organization's security posture, potentially leading to unauthorized access, data exfiltration, or further attacks like malware installation or privilege escalation. If confirmed malicious, this behavior could compromise the endpoint and the entire network, necessitating immediate investigation and response. +description: The following analytic detects attempts to stop security-related services + on an endpoint, which may indicate malicious activity. It leverages data from Endpoint + Detection and Response (EDR) agents, specifically searching for processes involving + the "sc.exe" or "net.exe" command with the "stop" parameter or the PowerShell "Stop-Service" + cmdlet. This activity is significant because disabling security services can undermine + the organization's security posture, potentially leading to unauthorized access, + data exfiltration, or further attacks like malware installation or privilege escalation. + If confirmed malicious, this behavior could compromise the endpoint and the entire + network, necessitating immediate investigation and response. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where ((`process_net` OR `process_sc`) Processes.process="* stop *") OR Processes.process="*Stop-Service *" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |lookup security_services_lookup service as process OUTPUTNEW category, description | search category=security | `windows_attempt_to_stop_security_service_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: None identified. Attempts to disable security-related services should be identified and understood. +search: '| tstats `security_content_summariesonly` values(Processes.process) as process + min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where ((`process_net` OR `process_sc`) Processes.process="* stop *") OR Processes.process="*Stop-Service + *" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name + Processes.process_name Processes.original_file_name Processes.process Processes.process_id + Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` |lookup security_services_lookup service as + process OUTPUTNEW category, description | search category=security | `windows_attempt_to_stop_security_service_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: None identified. Attempts to disable security-related services + should be identified and understood. references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ @@ -22,7 +46,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" and "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -51,7 +80,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security @@ -60,6 +88,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_autoit3_execution.yml b/detections/endpoint/windows_autoit3_execution.yml index 27d70e95ba..e6ddf3ce77 100644 --- a/detections/endpoint/windows_autoit3_execution.yml +++ b/detections/endpoint/windows_autoit3_execution.yml @@ -1,6 +1,6 @@ name: Windows AutoIt3 Execution id: 0ecb40d9-492b-4a57-9f87-515dd742794c -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml b/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml index a14fab9b60..873c2df5da 100644 --- a/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml +++ b/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml @@ -1,7 +1,7 @@ name: Windows Binary Proxy Execution Mavinject DLL Injection id: ccf4b61b-1b26-4f2e-a089-f2009c569c57 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.013 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_bitlockertogo_process_execution.yml b/detections/endpoint/windows_bitlockertogo_process_execution.yml index a6607a72a8..ac6f6b6ac4 100644 --- a/detections/endpoint/windows_bitlockertogo_process_execution.yml +++ b/detections/endpoint/windows_bitlockertogo_process_execution.yml @@ -1,10 +1,10 @@ name: Windows BitLockerToGo Process Execution id: 68cbc9e9-2882-46f2-b636-3b5080589d58 -version: 2 +version: 3 date: '2025-01-21' author: Michael Haag, Nasreddine Bencherchali, Splunk data_source: -- Sysmon Event ID 1 +- Sysmon EventID 1 - Windows Event Log Security 4688 type: Hunting status: production diff --git a/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml b/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml index 974d986e9f..9a96351ff5 100644 --- a/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml +++ b/detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml @@ -1,7 +1,7 @@ name: Windows Boot or Logon Autostart Execution In Startup Folder id: 99d157cb-923f-4a00-aee9-1f385412146f -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.001 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_bootloader_inventory.yml b/detections/endpoint/windows_bootloader_inventory.yml index 375c844994..7346f0b9f4 100644 --- a/detections/endpoint/windows_bootloader_inventory.yml +++ b/detections/endpoint/windows_bootloader_inventory.yml @@ -1,7 +1,7 @@ name: Windows BootLoader Inventory id: 4f7e3913-4db3-4ccd-afe4-31198982305d -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: experimental type: Hunting @@ -33,7 +33,6 @@ tags: atomic_guid: [] mitre_attack_id: - T1542.001 - - T1542 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_cached_domain_credentials_reg_query.yml b/detections/endpoint/windows_cached_domain_credentials_reg_query.yml index b0cf4007cc..3b9b8d4394 100644 --- a/detections/endpoint/windows_cached_domain_credentials_reg_query.yml +++ b/detections/endpoint/windows_cached_domain_credentials_reg_query.yml @@ -1,7 +1,7 @@ name: Windows Cached Domain Credentials Reg Query id: 40ccb8e0-1785-466e-901e-6a8b75c04ecd -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.005 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_certutil_download_with_url_argument.yml b/detections/endpoint/windows_certutil_download_with_url_argument.yml index e7ac8ebf6c..87ff45c03c 100644 --- a/detections/endpoint/windows_certutil_download_with_url_argument.yml +++ b/detections/endpoint/windows_certutil_download_with_url_argument.yml @@ -1,6 +1,6 @@ name: Windows CertUtil Download With URL Argument id: 4fc5ca00-4c7c-46b3-8772-c98a4b8bd944 -version: 2 +version: 3 date: '2025-01-07' author: Nasreddine Bencherchali, Splunk status: production diff --git a/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml b/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml index 36f61bdd44..161c19a39e 100644 --- a/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml +++ b/detections/endpoint/windows_change_default_file_association_for_no_file_ext.yml @@ -1,7 +1,7 @@ name: Windows Change Default File Association For No File Ext id: dbdf52ad-d6a1-4b68-975f-0a10939d8e38 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.001 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml b/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml index 76789b01ac..ea35cf83bc 100644 --- a/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml +++ b/detections/endpoint/windows_cmdline_tool_execution_from_non_shell_process.yml @@ -1,18 +1,42 @@ name: Windows Cmdline Tool Execution From Non-Shell Process id: 2afa393f-b88d-41b7-9793-623c93a2dfde -version: 1 -date: '2025-01-13' +version: 3 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`, or similar tools are executed by a non-standard shell parent process, excluding CMD, PowerShell, or Explorer. This detection leverages Endpoint Detection and Response (EDR) telemetry to monitor process creation events. Such behavior is significant as it may indicate adversaries using injected processes to perform system discovery, a tactic observed in FIN7's JSSLoader. If confirmed malicious, this activity could allow attackers to gather critical host information, aiding in further exploitation or lateral movement within the network. +description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`, + or similar tools are executed by a non-standard shell parent process, excluding + CMD, PowerShell, or Explorer. This detection leverages Endpoint Detection and Response + (EDR) telemetry to monitor process creation events. Such behavior is significant + as it may indicate adversaries using injected processes to perform system discovery, + a tactic observed in FIN7's JSSLoader. If confirmed malicious, this activity could + allow attackers to gather critical host information, aiding in further exploitation + or lateral movement within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("ipconfig.exe", "systeminfo.exe", "net1.exe", "arp.exe", "nslookup.exe", "route.exe", "netstat.exe", "whoami.exe") AND NOT Processes.parent_process_name IN ("cmd.exe", "powershell.exe", "powershell_ise.exe", "pwsh.exe", "explorer.exe", "-", "unknown") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process_id Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_cmdline_tool_execution_from_non_shell_process_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: A network operator or systems administrator may utilize an automated host discovery application that may generate false positives. Filter as needed. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("ipconfig.exe", + "systeminfo.exe", "net1.exe", "arp.exe", "nslookup.exe", "route.exe", "netstat.exe", + "whoami.exe") AND NOT Processes.parent_process_name IN ("cmd.exe", "powershell.exe", + "powershell_ise.exe", "pwsh.exe", "explorer.exe", "-", "unknown") by Processes.parent_process_name + Processes.parent_process Processes.process_name Processes.original_file_name Processes.process_id + Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_cmdline_tool_execution_from_non_shell_process_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: A network operator or systems administrator may utilize an + automated host discovery application that may generate false positives. Filter as + needed. references: - https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation - https://attack.mitre.org/groups/G0046/ @@ -23,7 +47,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" and "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", + "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -53,7 +82,6 @@ tags: - Gozi Malware asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.007 product: - Splunk Enterprise @@ -63,6 +91,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/jssloader/sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/jssloader/sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml b/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml index 80717d56c4..0e083199b3 100644 --- a/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml +++ b/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml @@ -1,7 +1,7 @@ name: Windows COM Hijacking InprocServer32 Modification id: b7bd83c0-92b5-4fc7-b286-23eccfa2c561 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.015 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml b/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml index 68a89ff942..749ef2a798 100644 --- a/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml +++ b/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml @@ -1,7 +1,7 @@ name: Windows Command Shell DCRat ForkBomb Payload id: 2bb1a362-7aa8-444a-92ed-1987e8da83e1 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.003 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_create_local_account.yml b/detections/endpoint/windows_create_local_account.yml index 91781c15e8..f6cc478ad7 100644 --- a/detections/endpoint/windows_create_local_account.yml +++ b/detections/endpoint/windows_create_local_account.yml @@ -1,7 +1,7 @@ name: Windows Create Local Account id: 3fb2e8e3-7bc0-4567-9722-c5ab9f8595eb -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_create_local_administrator_account_via_net.yml b/detections/endpoint/windows_create_local_administrator_account_via_net.yml index 518245a6d4..c555bb46ba 100644 --- a/detections/endpoint/windows_create_local_administrator_account_via_net.yml +++ b/detections/endpoint/windows_create_local_administrator_account_via_net.yml @@ -1,17 +1,40 @@ name: Windows Create Local Administrator Account Via Net id: 2c568c34-bb57-4b43-9d75-19c605b98e70 -version: 1 -date: '2025-01-13' +version: 3 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly -description: The following analytic detects the creation of a local administrator account using the "net.exe" command. It leverages Endpoint Detection and Response (EDR) data to identify processes named "net.exe" with the "/add" parameter and keywords related to administrator accounts. This activity is significant as it may indicate an attacker attempting to gain persistent access or escalate privileges. If confirmed malicious, this could lead to unauthorized access, data theft, or further system compromise. Review the process details, user context, and related artifacts to determine the legitimacy of the activity. +description: The following analytic detects the creation of a local administrator + account using the "net.exe" command. It leverages Endpoint Detection and Response + (EDR) data to identify processes named "net.exe" with the "/add" parameter and keywords + related to administrator accounts. This activity is significant as it may indicate + an attacker attempting to gain persistent access or escalate privileges. If confirmed + malicious, this could lead to unauthorized access, data theft, or further system + compromise. Review the process details, user context, and related artifacts to determine + the legitimacy of the activity. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count values(Processes.user) as user values(Processes.parent_process) as parent_process values(parent_process_name) as parent_process_name min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` AND Processes.process=*/add* AND Processes.process IN ("*administrators*", "*administratoren*", "*administrateurs*", "*administrador*", "*amministratori*", "*administratorer*", "*Rendszergazda*", "*Администратор*", "*Administratör*") by Processes.process Processes.process_name Processes.parent_process_name Processes.dest Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_create_local_administrator_account_via_net_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count values(Processes.user) as + user values(Processes.parent_process) as parent_process values(parent_process_name) + as parent_process_name min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where `process_net` AND Processes.process=*/add* AND Processes.process IN ("*administrators*", + "*administratoren*", "*administrateurs*", "*administrador*", "*amministratori*", + "*administratorer*", "*Rendszergazda*", "*Администратор*", "*Administratör*") by + Processes.process Processes.process_name Processes.parent_process_name Processes.dest + Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_create_local_administrator_account_via_net_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: Administrators often leverage net.exe to create admin accounts. references: [] drilldown_searches: @@ -20,7 +43,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" and "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -49,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1136.001 - - T1136 product: - Splunk Enterprise - Splunk Enterprise Security @@ -58,6 +85,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml b/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml index 1308709d7f..b33e006ced 100644 --- a/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml +++ b/detections/endpoint/windows_credential_dumping_lsass_memory_createdump.yml @@ -1,6 +1,6 @@ name: Windows Credential Dumping LSASS Memory Createdump id: b3b7ce35-fce5-4c73-85f4-700aeada81a9 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml b/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml index 25c6142e2f..862f0b722b 100644 --- a/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml +++ b/detections/endpoint/windows_credentials_from_password_stores_chrome_copied_in_temp_dir.yml @@ -1,7 +1,7 @@ name: Windows Credentials from Password Stores Chrome Copied in TEMP Dir id: 4d14c86d-fdee-4393-94da-238d2706902f -version: 2 -date: '2024-11-13' +version: 3 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Sysmon Event ID 11 @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1555.003 - - T1555 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml b/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml index f597206fbb..468917413d 100644 --- a/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml +++ b/detections/endpoint/windows_credentials_from_web_browsers_saved_in_temp_folder.yml @@ -1,7 +1,7 @@ name: Windows Credentials from Web Browsers Saved in TEMP Folder id: b36b23ea-763c-417b-bd4a-6a378dabad1a -version: 2 -date: '2024-11-13' +version: 3 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Sysmon Event ID 11 @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1555.003 - - T1555 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_credentials_in_registry_reg_query.yml b/detections/endpoint/windows_credentials_in_registry_reg_query.yml index 5465160a3a..c0718bc539 100644 --- a/detections/endpoint/windows_credentials_in_registry_reg_query.yml +++ b/detections/endpoint/windows_credentials_in_registry_reg_query.yml @@ -1,7 +1,7 @@ name: Windows Credentials in Registry Reg Query id: a8b3124e-2278-4b73-ae9c-585117079fb2 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.002 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index a267aa3e2f..fc5ad0009f 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -1,6 +1,6 @@ name: Windows Curl Download to Suspicious Path id: c32f091e-30db-11ec-8738-acde48001122 -version: 7 +version: 8 date: '2025-01-27' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_curl_upload_to_remote_destination.yml b/detections/endpoint/windows_curl_upload_to_remote_destination.yml index 0ebd3235eb..8b99b345c5 100644 --- a/detections/endpoint/windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/windows_curl_upload_to_remote_destination.yml @@ -1,6 +1,6 @@ name: Windows Curl Upload to Remote Destination id: 42f8f1a2-4228-11ec-aade-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_default_group_policy_object_modified.yml b/detections/endpoint/windows_default_group_policy_object_modified.yml index 4955cf8b89..efebc1aedd 100644 --- a/detections/endpoint/windows_default_group_policy_object_modified.yml +++ b/detections/endpoint/windows_default_group_policy_object_modified.yml @@ -1,7 +1,7 @@ name: Windows Default Group Policy Object Modified id: fe6a6cc4-9e0d-4d66-bcf4-2c7f44860876 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - T1484.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml b/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml index 6c21379d47..51664cc7ba 100644 --- a/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml +++ b/detections/endpoint/windows_default_group_policy_object_modified_with_gpme.yml @@ -1,7 +1,7 @@ name: Windows Default Group Policy Object Modified with GPME id: eaf688b3-bb8f-454d-b105-920a862cd8cb -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - T1484.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_defender_exclusion_registry_entry.yml b/detections/endpoint/windows_defender_exclusion_registry_entry.yml index f097a09992..185bb0b799 100644 --- a/detections/endpoint/windows_defender_exclusion_registry_entry.yml +++ b/detections/endpoint/windows_defender_exclusion_registry_entry.yml @@ -1,7 +1,7 @@ name: Windows Defender Exclusion Registry Entry id: 13395a44-4dd9-11ec-9df7-acde48001122 -version: 8 -date: '2024-12-08' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_delete_or_modify_system_firewall.yml b/detections/endpoint/windows_delete_or_modify_system_firewall.yml index bcb293d9d4..db9789944c 100644 --- a/detections/endpoint/windows_delete_or_modify_system_firewall.yml +++ b/detections/endpoint/windows_delete_or_modify_system_firewall.yml @@ -1,7 +1,7 @@ name: Windows Delete or Modify System Firewall id: b188d11a-eba7-419d-b8b6-cc265b4f2c4f -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -61,7 +61,6 @@ tags: - ShrinkLocker asset_type: Endpoint mitre_attack_id: - - T1562 - T1562.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_detect_network_scanner_behavior.yml b/detections/endpoint/windows_detect_network_scanner_behavior.yml index 7a05993d0d..0f75aeb776 100644 --- a/detections/endpoint/windows_detect_network_scanner_behavior.yml +++ b/detections/endpoint/windows_detect_network_scanner_behavior.yml @@ -1,63 +1,80 @@ -name: Windows Detect Network Scanner Behavior -id: 78e678d2-bf64-4fe6-aa52-2f7b11dddee7 -version: 2 -date: '2025-01-09' -author: Steven Dick -status: production -type: Anomaly -description: The following analytic detects when an application is used to connect a large number of unique ports/targets within a short time frame. Network enumeration may be used by adversaries as a method of discovery, lateral movement, or remote execution. This analytic may require significant tuning depending on the organization and applications being actively used, highly recommended to pre-populate the filter macro prior to activation. -data_source: -- Sysmon EventID 3 -search: '| tstats `security_content_summariesonly` count latest(All_Traffic.dest_port) as dest_port dc(All_Traffic.dest_port) as port_count dc(All_Traffic.dest) as dest_count min(_time) as firstTime max(_time) as lastTime values(All_Traffic.process_id) as process_id from datamodel=Network_Traffic.All_Traffic where sourcetype=XmlWinEventLog All_Traffic.app = "*\\*" All_Traffic.dest_port < 32000 NOT All_Traffic.dest_port IN (8443,8080,5353,3268,443,389,88,80,53,25) by host,All_Traffic.app,All_Traffic.src,All_Traffic.src_ip,All_Traffic.user _time span=5m -| `drop_dm_object_name(All_Traffic)` -| rex field=app ".*\\\(?.*)$" -| where port_count > 10 OR dest_count > 10 -| stats latest(src) as src, latest(src_ip) as src_ip, max(dest_count) as dest_count, max(port_count) as port_count, latest(dest_port) as dest_port, min(firstTime) as firstTime, max(lastTime) as lastTime, max(count) as count by host,user,app,process_name -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_detect_network_scanner_behavior_filter`' -how_to_implement: This detection relies on Sysmon EventID 3 events being ingested AND tagged into the Network_Traffic datamodel. -known_false_positives: Various, could be noisy depending on processes in the organization and sysmon configuration used. Adjusted port/dest count thresholds as needed. -references: -- https://attack.mitre.org/techniques/T1595 -drilldown_searches: -- name: View the detection results for - "$src$" and "$user$" - search: '%original_detection_search% | search src = "$src$" user = "$user$"' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -- name: View risk events for the last 7 days for - "$src$" and "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -rba: - message: A process exhibiting network scanning behavior [$process_name$] was detected on $src$ - risk_objects: - - field: src - type: system - score: 25 - - field: user - type: user - score: 25 - threat_objects: - - field: process_name - type: process_name -tags: - analytic_story: - - Network Discovery - - Windows Discovery Techniques - asset_type: Endpoint - mitre_attack_id: - - T1595 - - T1595.001 - - T1595.002 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - security_domain: network -tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/sysmon_scanning_events/sysmon_scanning_events.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog +name: Windows Detect Network Scanner Behavior +id: 78e678d2-bf64-4fe6-aa52-2f7b11dddee7 +version: 4 +date: '2025-02-10' +author: Steven Dick +status: production +type: Anomaly +description: The following analytic detects when an application is used to connect + a large number of unique ports/targets within a short time frame. Network enumeration + may be used by adversaries as a method of discovery, lateral movement, or remote + execution. This analytic may require significant tuning depending on the organization + and applications being actively used, highly recommended to pre-populate the filter + macro prior to activation. +data_source: +- Sysmon EventID 3 +search: '| tstats `security_content_summariesonly` count latest(All_Traffic.dest_port) + as dest_port dc(All_Traffic.dest_port) as port_count dc(All_Traffic.dest) as dest_count + min(_time) as firstTime max(_time) as lastTime values(All_Traffic.process_id) as + process_id from datamodel=Network_Traffic.All_Traffic where sourcetype=XmlWinEventLog + All_Traffic.app = "*\\*" All_Traffic.dest_port < 32000 NOT All_Traffic.dest_port + IN (8443,8080,5353,3268,443,389,88,80,53,25) by host,All_Traffic.app,All_Traffic.src,All_Traffic.src_ip,All_Traffic.user + _time span=5m | `drop_dm_object_name(All_Traffic)` | rex field=app ".*\\\(?.*)$" + | where port_count > 10 OR dest_count > 10 | stats latest(src) as src, latest(src_ip) + as src_ip, max(dest_count) as dest_count, max(port_count) as port_count, latest(dest_port) + as dest_port, min(firstTime) as firstTime, max(lastTime) as lastTime, max(count) + as count by host,user,app,process_name | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `windows_detect_network_scanner_behavior_filter`' +how_to_implement: This detection relies on Sysmon EventID 3 events being ingested + AND tagged into the Network_Traffic datamodel. +known_false_positives: Various, could be noisy depending on processes in the organization + and sysmon configuration used. Adjusted port/dest count thresholds as needed. +references: +- https://attack.mitre.org/techniques/T1595 +drilldown_searches: +- name: View the detection results for - "$src$" and "$user$" + search: '%original_detection_search% | search src = "$src$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$src$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: A process exhibiting network scanning behavior [$process_name$] was detected + on $src$ + risk_objects: + - field: src + type: system + score: 25 + - field: user + type: user + score: 25 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Network Discovery + - Windows Discovery Techniques + asset_type: Endpoint + mitre_attack_id: + - T1595.001 + - T1595.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: network +tests: +- name: True Positive Test + attack_data: + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/sysmon_scanning_events/sysmon_scanning_events.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_disable_memory_crash_dump.yml b/detections/endpoint/windows_disable_memory_crash_dump.yml index c8c1b362d2..c53c115e73 100644 --- a/detections/endpoint/windows_disable_memory_crash_dump.yml +++ b/detections/endpoint/windows_disable_memory_crash_dump.yml @@ -1,6 +1,6 @@ name: Windows Disable Memory Crash Dump id: 59e54602-9680-11ec-a8a6-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml b/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml index b21faffa59..89f5df049c 100644 --- a/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml +++ b/detections/endpoint/windows_disable_or_modify_tools_via_taskkill.yml @@ -1,7 +1,7 @@ name: Windows Disable or Modify Tools Via Taskkill id: a43ae66f-c410-4b3d-8741-9ce1ad17ddb0 -version: 6 -date: '2024-11-22' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -67,7 +67,6 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1562 - T1562.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_disable_or_stop_browser_process.yml b/detections/endpoint/windows_disable_or_stop_browser_process.yml index 3c49e0a8d1..2447b0a67e 100644 --- a/detections/endpoint/windows_disable_or_stop_browser_process.yml +++ b/detections/endpoint/windows_disable_or_stop_browser_process.yml @@ -1,10 +1,10 @@ name: Windows Disable or Stop Browser Process id: 220d34b7-b6c7-45fe-8dbb-c35cdd9fe6d5 -version: 2 -date: '2024-11-13' +version: 3 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: -- Sysmon Event ID 1 +- Sysmon EventID 1 type: TTP status: production description: The following analytic detects the use of the taskkill command in a process @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml b/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml index 8419dcfa0e..05bec76722 100644 --- a/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml +++ b/detections/endpoint/windows_disable_windows_event_logging_disable_http_logging.yml @@ -1,7 +1,7 @@ name: Windows Disable Windows Event Logging Disable HTTP Logging id: 23fb6787-255f-4d5b-9a66-9fd7504032b5 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,10 +77,8 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1562.002 - - T1562 - - T1505 - T1505.004 + - T1562.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_disableantispyware_registry.yml b/detections/endpoint/windows_disableantispyware_registry.yml index 4395bd7e96..0dda67a09d 100644 --- a/detections/endpoint/windows_disableantispyware_registry.yml +++ b/detections/endpoint/windows_disableantispyware_registry.yml @@ -1,7 +1,7 @@ name: Windows DisableAntiSpyware Registry id: 23150a40-9301-4195-b802-5bb4f43067fb -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Rod Soto, Jose Hernandez, Michael Haag, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dism_remove_defender.yml b/detections/endpoint/windows_dism_remove_defender.yml index 8a4786b5ea..8371b710fb 100644 --- a/detections/endpoint/windows_dism_remove_defender.yml +++ b/detections/endpoint/windows_dism_remove_defender.yml @@ -1,7 +1,7 @@ name: Windows DISM Remove Defender id: 8567da9e-47f0-11ec-99a9-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml b/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml index 69a5506c40..709369aecf 100644 --- a/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml +++ b/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml @@ -1,7 +1,7 @@ name: Windows DLL Search Order Hijacking Hunt with Sysmon id: 79c7d1fc-64c7-91be-a616-ccda752efe81 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -35,7 +35,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.001 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml b/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml index 5ddb5d8355..d5d279ce64 100644 --- a/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml +++ b/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml @@ -1,6 +1,6 @@ name: Windows DLL Search Order Hijacking with iscsicpl id: f39ee679-3b1e-4f47-841c-5c3c580acda2 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_dll_side_loading_in_calc.yml b/detections/endpoint/windows_dll_side_loading_in_calc.yml index bbaa20e218..6e02110e63 100644 --- a/detections/endpoint/windows_dll_side_loading_in_calc.yml +++ b/detections/endpoint/windows_dll_side_loading_in_calc.yml @@ -1,7 +1,7 @@ name: Windows DLL Side-Loading In Calc id: af01f6db-26ac-440e-8d89-2793e303f137 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml b/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml index 1e661f00bf..3d856442b6 100644 --- a/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml +++ b/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml @@ -1,7 +1,7 @@ name: Windows DLL Side-Loading Process Child Of Calc id: 295ca9ed-e97b-4520-90f7-dfb6469902e1 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml b/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml index 39e7c9496e..94664fd032 100644 --- a/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml +++ b/detections/endpoint/windows_dns_query_request_by_telegram_bot_api.yml @@ -1,20 +1,27 @@ name: Windows DNS Query Request by Telegram Bot API id: 86f66f44-94d9-412d-a71d-5d8ed0fef72e -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Sysmon EventID 22 type: Anomaly status: production -description: The following analytic detects the execution of a DNS query by a process to the associated Telegram API domain, which could indicate access via a Telegram bot commonly used by malware for command and control (C2) communications. By monitoring DNS queries related to Telegram's infrastructure, the detection identifies potential attempts to establish covert communication channels between a compromised system and external malicious actors. This behavior is often observed in cyberattacks where Telegram bots are used to receive commands or exfiltrate data, making it a key indicator of suspicious or malicious activity within a network. +description: The following analytic detects the execution of a DNS query by a process + to the associated Telegram API domain, which could indicate access via a Telegram + bot commonly used by malware for command and control (C2) communications. By monitoring + DNS queries related to Telegram's infrastructure, the detection identifies potential + attempts to establish covert communication channels between a compromised system + and external malicious actors. This behavior is often observed in cyberattacks where + Telegram bots are used to receive commands or exfiltrate data, making it a key indicator + of suspicious or malicious activity within a network. search: '`sysmon` EventCode=22 query = "api.telegram.org" process_name != "telegram.exe" - | stats count min(_time) as firstTime max(_time) as lastTime by query answer QueryResults QueryStatus process_name process_guid Computer - | rename Computer as dest - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `windows_dns_query_request_by_telegram_bot_api_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name and eventcode = 22 dnsquery executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + | stats count min(_time) as firstTime max(_time) as lastTime by query answer QueryResults + QueryStatus process_name process_guid Computer | rename Computer as dest | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_dns_query_request_by_telegram_bot_api_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name and eventcode = 22 dnsquery executions from your endpoints. + If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. known_false_positives: a third part automation using telegram API. references: - https://www.splunk.com/en_us/blog/security/threat-advisory-telegram-crypto-botnet-strt-ta01.html @@ -24,7 +31,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -39,10 +51,8 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1102.002 - T1071.004 - - T1071 - - T1102 + - T1102.002 product: - Splunk Enterprise - Splunk Enterprise Security @@ -51,6 +61,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1102.002/telegram_api_dns/telegram_dns.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1102.002/telegram_api_dns/telegram_dns.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml b/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml index eb09f87426..ad894aeeb8 100644 --- a/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml +++ b/detections/endpoint/windows_domain_account_discovery_via_get_netcomputer.yml @@ -1,7 +1,7 @@ name: Windows Domain Account Discovery Via Get-NetComputer id: a7fbbc4e-4571-424a-b627-6968e1c939e4 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -53,7 +53,6 @@ tags: - CISA AA23-347A asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml index a356cdce76..55465e1839 100644 --- a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml +++ b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml @@ -1,7 +1,7 @@ name: Windows DotNet Binary in Non Standard Path id: fddf3b56-7933-11ec-98a6-acde48001122 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -82,9 +82,7 @@ tags: - WhisperGate asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.003 - - T1218 - T1218.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_driver_load_non_standard_path.yml b/detections/endpoint/windows_driver_load_non_standard_path.yml index bf5adb05b7..e36e98bcbd 100644 --- a/detections/endpoint/windows_driver_load_non_standard_path.yml +++ b/detections/endpoint/windows_driver_load_non_standard_path.yml @@ -1,7 +1,7 @@ name: Windows Driver Load Non-Standard Path id: 9216ef3d-066a-4958-8f27-c84589465e62 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-01-27' author: Michael Haag, Splunk status: production type: TTP @@ -17,7 +17,7 @@ data_source: - Windows Event Log System 7045 search: >- `wineventlog_system` EventCode=7045 ServiceType="kernel mode driver" - | regex ImagePath!="(?i)^(\w:\\\\Windows\\\\|\w:\\\\Program\sFile|\\\\systemroot\\\\|%SystemRoot%|system32\\\\)" + | regex ImagePath!="(?i)^(\w:\\\\Windows\\\\|\w:\\\\Program\sFile|\\\\systemroot\\\\|%SystemRoot%|system32\\\\|\\\\ProgramData\\\\Microsoft\\\\Windows\sDefender\\\\Definition\sUpdates\\\\)" | stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode ImagePath ServiceName ServiceType | rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_driver_load_non_standard_path_filter` diff --git a/detections/endpoint/windows_esx_admins_group_creation_via_net.yml b/detections/endpoint/windows_esx_admins_group_creation_via_net.yml index 0fecbadc81..373e172977 100644 --- a/detections/endpoint/windows_esx_admins_group_creation_via_net.yml +++ b/detections/endpoint/windows_esx_admins_group_creation_via_net.yml @@ -1,6 +1,6 @@ name: Windows ESX Admins Group Creation via Net id: 3d7df60b-3332-4667-8090-afe03e08dce0 -version: 4 +version: 5 date: '2025-01-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml b/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml index 71b3808e94..fd301786bb 100644 --- a/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml +++ b/detections/endpoint/windows_esx_admins_group_creation_via_powershell.yml @@ -1,6 +1,6 @@ name: Windows ESX Admins Group Creation via PowerShell id: f48a5557-be06-4b96-b8e8-be563e387620 -version: 3 +version: 4 date: '2024-11-13' author: Michael Haag, Splunk data_source: diff --git a/detections/endpoint/windows_event_for_service_disabled.yml b/detections/endpoint/windows_event_for_service_disabled.yml index 070028f5ee..aef5a45b51 100644 --- a/detections/endpoint/windows_event_for_service_disabled.yml +++ b/detections/endpoint/windows_event_for_service_disabled.yml @@ -1,7 +1,7 @@ name: Windows Event For Service Disabled id: 9c2620a8-94a1-11ec-b40c-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -32,7 +32,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_event_log_cleared.yml b/detections/endpoint/windows_event_log_cleared.yml index 2bfd8a88e7..cff4ffa150 100644 --- a/detections/endpoint/windows_event_log_cleared.yml +++ b/detections/endpoint/windows_event_log_cleared.yml @@ -1,7 +1,7 @@ name: Windows Event Log Cleared id: ad517544-aff9-4c96-bd99-d6eb43bfbb6a -version: 12 -date: '2024-12-10' +version: 13 +date: '2025-02-10' author: Rico Valdez, Michael Haag, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Clop Ransomware asset_type: Endpoint mitre_attack_id: - - T1070 - T1070.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_excessive_disabled_services_event.yml b/detections/endpoint/windows_excessive_disabled_services_event.yml index 9f17eac2d5..047bd056e9 100644 --- a/detections/endpoint/windows_excessive_disabled_services_event.yml +++ b/detections/endpoint/windows_excessive_disabled_services_event.yml @@ -1,7 +1,7 @@ name: Windows Excessive Disabled Services Event id: c3f85976-94a5-11ec-9a58-acde48001122 -version: 7 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_excessive_usage_of_net_app.yml b/detections/endpoint/windows_excessive_usage_of_net_app.yml index 68d8e0a30f..10716cc575 100644 --- a/detections/endpoint/windows_excessive_usage_of_net_app.yml +++ b/detections/endpoint/windows_excessive_usage_of_net_app.yml @@ -1,6 +1,6 @@ name: Windows Excessive Usage Of Net App id: 355ba810-0a20-4215-8485-9ce3f87f2e38 -version: 1 +version: 2 date: '2025-01-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml b/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml index 576e79a52b..abbcec0359 100644 --- a/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml +++ b/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml @@ -1,6 +1,6 @@ name: Windows Execute Arbitrary Commands with MSDT id: e1d5145f-38fe-42b9-a5d5-457796715f97 -version: 8 +version: 9 date: '2024-12-10' author: Michael Haag, Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/windows_export_certificate.yml b/detections/endpoint/windows_export_certificate.yml index bb27c581d8..745605dc64 100644 --- a/detections/endpoint/windows_export_certificate.yml +++ b/detections/endpoint/windows_export_certificate.yml @@ -1,7 +1,7 @@ name: Windows Export Certificate id: d8ddfa9b-b724-4df9-9dbe-f34cc0936714 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -51,7 +51,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 - T1649 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml b/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml index 314c2ed9fd..cbe465f6fb 100644 --- a/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml +++ b/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml @@ -1,7 +1,7 @@ name: Windows File Transfer Protocol In Non-Common Process Path id: 0f43758f-1fe9-470a-a9e4-780acc4d5407 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.003 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml b/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml index 6f4b92d1c5..356e3e7925 100644 --- a/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml +++ b/detections/endpoint/windows_files_and_dirs_access_rights_modification_via_icacls.yml @@ -1,7 +1,7 @@ name: Windows Files and Dirs Access Rights Modification Via Icacls id: c76b796c-27e1-4520-91c4-4a58695c749e -version: 5 -date: '2024-12-16' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: - 3309f53e-b22b-4eb6-8fd2-a6cf58b355a9 mitre_attack_id: - T1222.001 - - T1222 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml b/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml index 936ae3761c..dd165dc33e 100644 --- a/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml +++ b/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml @@ -1,7 +1,7 @@ name: Windows Find Domain Organizational Units with GetDomainOU id: 0ada2f82-b7af-40cc-b1d7-1e5985afcb4e -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml b/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml index e855820ea9..ffed352753 100644 --- a/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml +++ b/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml @@ -1,7 +1,7 @@ name: Windows Find Interesting ACL with FindInterestingDomainAcl id: e4a96dfd-667a-4487-b942-ccef5a1e81e8 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_findstr_gpp_discovery.yml b/detections/endpoint/windows_findstr_gpp_discovery.yml index b141be9c81..2ce7f83865 100644 --- a/detections/endpoint/windows_findstr_gpp_discovery.yml +++ b/detections/endpoint/windows_findstr_gpp_discovery.yml @@ -1,7 +1,7 @@ name: Windows Findstr GPP Discovery id: 1631ac2d-f2a9-42fa-8a59-d6e210d472f5 -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk type: TTP status: production @@ -70,7 +70,6 @@ tags: - Active Directory Privilege Escalation asset_type: Endpoint mitre_attack_id: - - T1552 - T1552.006 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml b/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml index aac21bf7bb..c8bcb30a51 100644 --- a/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml +++ b/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml @@ -1,7 +1,7 @@ name: Windows Forest Discovery with GetForestDomain id: a14803b2-4bd9-4c08-8b57-c37980edebe8 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_gather_victim_host_information_camera.yml b/detections/endpoint/windows_gather_victim_host_information_camera.yml index 44ac29e470..9bf473e971 100644 --- a/detections/endpoint/windows_gather_victim_host_information_camera.yml +++ b/detections/endpoint/windows_gather_victim_host_information_camera.yml @@ -1,7 +1,7 @@ name: Windows Gather Victim Host Information Camera id: e4df4676-ea41-4397-b160-3ee0140dc332 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1592.001 - - T1592 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_gather_victim_identity_sam_info.yml b/detections/endpoint/windows_gather_victim_identity_sam_info.yml index 58829b5f21..783965ba95 100644 --- a/detections/endpoint/windows_gather_victim_identity_sam_info.yml +++ b/detections/endpoint/windows_gather_victim_identity_sam_info.yml @@ -1,7 +1,7 @@ name: Windows Gather Victim Identity SAM Info id: a18e85d7-8b98-4399-820c-d46a1ca3516f -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -34,7 +34,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1589.001 - - T1589 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml b/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml index 1f6f6dcc37..ddc18ae497 100644 --- a/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml +++ b/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml @@ -1,7 +1,7 @@ name: Windows Gather Victim Network Info Through Ip Check Web Services id: 70f7c952-0758-46d6-9148-d8969c4481d1 -version: 8 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -42,7 +42,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1590.005 - - T1590 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml b/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml index 8d7779ac20..79e2ef2681 100644 --- a/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml +++ b/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml @@ -1,7 +1,7 @@ name: Windows Get Local Admin with FindLocalAdminAccess id: d2988160-3ce9-4310-b59d-905334920cdd -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_group_discovery_via_net.yml b/detections/endpoint/windows_group_discovery_via_net.yml index b351dac9de..bd02d34030 100644 --- a/detections/endpoint/windows_group_discovery_via_net.yml +++ b/detections/endpoint/windows_group_discovery_via_net.yml @@ -1,17 +1,37 @@ name: Windows Group Discovery Via Net id: c5c8e0f3-147a-43da-bf04-4cfaec27dc44 -version: 1 -date: '2025-01-13' +version: 2 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: Hunting -description: The following analytic identifies the execution of `net.exe` with command-line arguments used to query global, local and domain groups. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries to enumerate local or domain groups, which is a common step in Active Directory or privileged accounts discovery. If confirmed malicious, this behavior could allow attackers to gain insights into the domain structure, aiding in further attacks such as privilege escalation or lateral movement. +description: The following analytic identifies the execution of `net.exe` with command-line + arguments used to query global, local and domain groups. It leverages data from + Endpoint Detection and Response (EDR) agents, focusing on process names and command-line + arguments. This activity is significant as it indicates potential reconnaissance + efforts by adversaries to enumerate local or domain groups, which is a common step + in Active Directory or privileged accounts discovery. If confirmed malicious, this + behavior could allow attackers to gain insights into the domain structure, aiding + in further attacks such as privilege escalation or lateral movement. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*" AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_group_discovery_via_net_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*" + AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest + Processes.user Processes.parent_process Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_group_discovery_via_net_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: Administrators or power users may use this command for troubleshooting. references: - https://attack.mitre.org/techniques/T1069/002/ @@ -33,7 +53,6 @@ tags: - Azorult asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 - T1069.002 product: @@ -44,11 +63,13 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog \ No newline at end of file + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_group_policy_object_created.yml b/detections/endpoint/windows_group_policy_object_created.yml index f3a08ffa82..bd4406e610 100644 --- a/detections/endpoint/windows_group_policy_object_created.yml +++ b/detections/endpoint/windows_group_policy_object_created.yml @@ -1,7 +1,7 @@ name: Windows Group Policy Object Created id: 23add2a8-ea22-4fd4-8bc0-8c0b822373a1 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco status: production type: TTP @@ -61,9 +61,8 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1484 - - T1484.001 - T1078.002 + - T1484.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml b/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml index 392783e8d3..20958cf465 100644 --- a/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml +++ b/detections/endpoint/windows_hijack_execution_flow_version_dll_side_load.yml @@ -1,7 +1,7 @@ name: Windows Hijack Execution Flow Version Dll Side Load id: 8351340b-ac0e-41ec-8b07-dd01bf32d6ea -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -53,7 +53,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.001 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_http_network_communication_from_msiexec.yml b/detections/endpoint/windows_http_network_communication_from_msiexec.yml index 46426413d7..d312721aa7 100644 --- a/detections/endpoint/windows_http_network_communication_from_msiexec.yml +++ b/detections/endpoint/windows_http_network_communication_from_msiexec.yml @@ -1,6 +1,6 @@ name: Windows HTTP Network Communication From MSIExec id: b0fd38c7-f71a-43a2-870e-f3ca06bcdd99 -version: 1 +version: 2 date: '2025-01-17' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml b/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml index 8dd3e10940..f839a81cb1 100644 --- a/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml +++ b/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml @@ -1,7 +1,7 @@ name: Windows Hunting System Account Targeting Lsass id: 1c6abb08-73d1-11ec-9ca0-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -38,7 +38,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_iis_components_add_new_module.yml b/detections/endpoint/windows_iis_components_add_new_module.yml index bd66a0d8fb..b8e4617559 100644 --- a/detections/endpoint/windows_iis_components_add_new_module.yml +++ b/detections/endpoint/windows_iis_components_add_new_module.yml @@ -1,7 +1,7 @@ name: Windows IIS Components Add New Module id: 38fe731c-1f13-43d4-b878-a5bbe44807e3 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -76,7 +76,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml b/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml index 25f6016ba5..67cbd0e5c9 100644 --- a/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml +++ b/detections/endpoint/windows_iis_components_get_webglobalmodule_module_query.yml @@ -1,7 +1,7 @@ name: Windows IIS Components Get-WebGlobalModule Module Query id: 20db5f70-34b4-4e83-8926-fa26119de173 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -33,7 +33,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1505.004 - - T1505 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_iis_components_module_failed_to_load.yml b/detections/endpoint/windows_iis_components_module_failed_to_load.yml index cf09db6fe1..292c33dcc8 100644 --- a/detections/endpoint/windows_iis_components_module_failed_to_load.yml +++ b/detections/endpoint/windows_iis_components_module_failed_to_load.yml @@ -1,7 +1,7 @@ name: Windows IIS Components Module Failed to Load id: 40c2ba5b-dd6a-496b-9e6e-c9524d0be167 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_iis_components_new_module_added.yml b/detections/endpoint/windows_iis_components_new_module_added.yml index 6b24987b30..3042160dcc 100644 --- a/detections/endpoint/windows_iis_components_new_module_added.yml +++ b/detections/endpoint/windows_iis_components_new_module_added.yml @@ -1,7 +1,7 @@ name: Windows IIS Components New Module Added id: 55f22929-cfd3-4388-ba5c-4d01fac7ee7e -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml b/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml index 2bc0b705bb..9b97d2d1cf 100644 --- a/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml +++ b/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Add Xml Applocker Rules id: 467ed9d9-8035-470e-ad5e-ae5189283033 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml b/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml index 5ce4ca602b..01111a8dfa 100644 --- a/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml +++ b/detections/endpoint/windows_impair_defense_change_win_defender_health_check_intervals.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Change Win Defender Health Check Intervals id: 5211c260-820e-4366-b983-84bbfb5c263a -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml b/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml index a04ac54542..9bd8d4dcd9 100644 --- a/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml +++ b/detections/endpoint/windows_impair_defense_change_win_defender_quick_scan_interval.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Change Win Defender Quick Scan Interval id: 783f0798-f679-4c17-b3b3-187febf0b9b8 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml b/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml index 0be8d9fe47..56fe8964d2 100644 --- a/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml +++ b/detections/endpoint/windows_impair_defense_change_win_defender_throttle_rate.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Change Win Defender Throttle Rate id: f7da5fca-9261-43de-a4d0-130dad1e4f4d -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml b/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml index a4a8c000b8..6f1170901c 100644 --- a/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml +++ b/detections/endpoint/windows_impair_defense_change_win_defender_tracing_level.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Change Win Defender Tracing Level id: fe9391cd-952a-4c64-8f56-727cb0d4f2d4 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_configure_app_install_control.yml b/detections/endpoint/windows_impair_defense_configure_app_install_control.yml index 4e1f435595..c8924b0876 100644 --- a/detections/endpoint/windows_impair_defense_configure_app_install_control.yml +++ b/detections/endpoint/windows_impair_defense_configure_app_install_control.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Configure App Install Control id: c54b7439-cfb1-44c3-bb35-b0409553077c -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml b/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml index 29afaf77bb..997dcd5e85 100644 --- a/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml +++ b/detections/endpoint/windows_impair_defense_define_win_defender_threat_action.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Define Win Defender Threat Action id: 7215831c-8252-4ae3-8d43-db588e82f952 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml b/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml index d8200b4cfd..a259c74bc3 100644 --- a/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml +++ b/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Delete Win Defender Context Menu id: 395ed5fe-ad13-4366-9405-a228427bdd91 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -39,7 +39,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml b/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml index e431440431..c47f826bdd 100644 --- a/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml +++ b/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Delete Win Defender Profile Registry id: 65d4b105-ec52-48ec-ac46-289d0fbf7d96 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml b/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml index 47a77e773c..a6c48f740b 100644 --- a/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml +++ b/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Deny Security Software With Applocker id: e0b6ca60-9e29-4450-b51a-bba0abae2313 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml b/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml index d6b1155f4e..8f40b00e62 100644 --- a/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml +++ b/detections/endpoint/windows_impair_defense_disable_controlled_folder_access.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Controlled Folder Access id: 3032741c-d6fc-4c69-8988-be8043d6478c -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml b/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml index 17bd6686b7..9c02486387 100644 --- a/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml +++ b/detections/endpoint/windows_impair_defense_disable_defender_firewall_and_network.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Defender Firewall And Network id: 8467d8cd-b0f9-46fa-ac84-a30ad138983e -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml b/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml index c9c51d2ebb..ae01a2aeff 100644 --- a/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml +++ b/detections/endpoint/windows_impair_defense_disable_defender_protocol_recognition.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Defender Protocol Recognition id: b2215bfb-6171-4137-af17-1a02fdd8d043 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_pua_protection.yml b/detections/endpoint/windows_impair_defense_disable_pua_protection.yml index 0ec711df2b..9727759c6f 100644 --- a/detections/endpoint/windows_impair_defense_disable_pua_protection.yml +++ b/detections/endpoint/windows_impair_defense_disable_pua_protection.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable PUA Protection id: fbfef407-cfee-4866-88c1-f8de1c16147c -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml b/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml index 0516b79f28..a609983158 100644 --- a/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml +++ b/detections/endpoint/windows_impair_defense_disable_realtime_signature_delivery.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Realtime Signature Delivery id: ffd99aea-542f-448e-b737-091c1b417274 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml b/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml index 14fe3afff2..ca7527eacf 100644 --- a/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml +++ b/detections/endpoint/windows_impair_defense_disable_web_evaluation.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Web Evaluation id: e234970c-dcf5-4f80-b6a9-3a562544ca5b -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml index a9396eab83..4113418ced 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_app_guard.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender App Guard id: 8b700d7e-54ad-4d7d-81cc-1456c4703306 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml index d8d1c3e1dd..0e827549ac 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_compute_file_hashes.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Compute File Hashes id: fe52c280-98bd-4596-b6f6-a13bbf8ac7c6 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml index 0b07829d29..508ebf0f28 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_gen_reports.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Gen reports id: 93f114f6-cb1e-419b-ac3f-9e11a3045e70 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml index 2fd33fce86..f97411180b 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_network_protection.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Network Protection id: 8b6c15c7-5556-463d-83c7-986326c21f12 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml index 3311e301c4..118feb49cd 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_report_infection.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Report Infection id: 201946c6-b1d5-42bb-a7e0-5f7123f47fc4 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml index 9f723c9a7a..4d35f7fcf8 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_scan_on_update.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Scan On Update id: 0418e72f-e710-4867-b656-0688e1523e09 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml b/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml index 1f812f4b95..828bc431c3 100644 --- a/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml +++ b/detections/endpoint/windows_impair_defense_disable_win_defender_signature_retirement.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Disable Win Defender Signature Retirement id: 7567a72f-bada-489d-aef1-59743fb64a66 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml b/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml index 89ec865e6b..fa8a6726f1 100644 --- a/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml +++ b/detections/endpoint/windows_impair_defense_overide_win_defender_phishing_filter.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Overide Win Defender Phishing Filter id: 10ca081c-57b1-4a78-ba56-14a40a7e116a -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml b/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml index 89c4b37a2d..25e00f2f42 100644 --- a/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml +++ b/detections/endpoint/windows_impair_defense_override_smartscreen_prompt.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Override SmartScreen Prompt id: 08058866-7987-486f-b042-275715ef6e9d -version: 5 -date: '2025-01-21' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml b/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml index 119a81d84b..c5e32b8b14 100644 --- a/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml +++ b/detections/endpoint/windows_impair_defense_set_win_defender_smart_screen_level_to_warn.yml @@ -1,7 +1,7 @@ name: Windows Impair Defense Set Win Defender Smart Screen Level To Warn id: cc2a3425-2703-47e7-818f-3dca1b0bc56f -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml b/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml index 5a904d707d..1220aac4a3 100644 --- a/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml +++ b/detections/endpoint/windows_impair_defenses_disable_auto_logger_session.yml @@ -1,7 +1,7 @@ name: Windows Impair Defenses Disable Auto Logger Session id: dc6a5613-d024-47e7-9997-ab6477a483d3 -version: 2 -date: '2025-01-07' +version: 3 +date: '2025-02-10' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -50,7 +50,8 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: Windows Auto Logger Session or Provider registry value set to 'disabled' on $dest$ + message: Windows Auto Logger Session or Provider registry value set to 'disabled' + on $dest$ risk_objects: - field: dest type: system @@ -63,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml b/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml index 9d3ed5adac..0499d7e3de 100644 --- a/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml +++ b/detections/endpoint/windows_impair_defenses_disable_av_autostart_via_registry.yml @@ -1,6 +1,6 @@ name: Windows Impair Defenses Disable AV AutoStart via Registry id: 31a13f43-812e-4752-a6ca-c6c87bf03e83 -version: 4 +version: 5 date: '2024-11-13' author: Teoderick Contreras, Splunk data_source: diff --git a/detections/endpoint/windows_impair_defenses_disable_hvci.yml b/detections/endpoint/windows_impair_defenses_disable_hvci.yml index 761a7e1811..cbcc2f8739 100644 --- a/detections/endpoint/windows_impair_defenses_disable_hvci.yml +++ b/detections/endpoint/windows_impair_defenses_disable_hvci.yml @@ -1,7 +1,7 @@ name: Windows Impair Defenses Disable HVCI id: b061dfcc-f0aa-42cc-a6d4-a87f172acb79 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - 70bd71e6-eba4-4e00-92f7-617911dbe020 mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml b/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml index 26e0268183..4faf3a1895 100644 --- a/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml +++ b/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml @@ -1,7 +1,7 @@ name: Windows Impair Defenses Disable Win Defender Auto Logging id: 76406a0f-f5e0-4167-8e1f-337fdc0f1b0c -version: 5 -date: '2024-12-16' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml index 8bfb3df253..75fd3bf93a 100644 --- a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml +++ b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml @@ -1,6 +1,6 @@ name: Windows Ingress Tool Transfer Using Explorer id: 76753bab-f116-4ea3-8fb9-89b638be58a9 -version: 6 +version: 7 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml b/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml index 2f551ec808..6778cf87fd 100644 --- a/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml +++ b/detections/endpoint/windows_input_capture_using_credential_ui_dll.yml @@ -1,7 +1,7 @@ name: Windows Input Capture Using Credential UI Dll id: 406c21d6-6c75-4e9f-9ca9-48049a1dd90e -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -34,7 +34,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1056.002 - - T1056 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_credential_theft.yml b/detections/endpoint/windows_installutil_credential_theft.yml index 715a74abb6..647e38256d 100644 --- a/detections/endpoint/windows_installutil_credential_theft.yml +++ b/detections/endpoint/windows_installutil_credential_theft.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil Credential Theft id: ccfeddec-43ec-11ec-b494-acde48001122 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Mauricio Velazo, Splunk status: production type: TTP @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.004 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_in_non_standard_path.yml b/detections/endpoint/windows_installutil_in_non_standard_path.yml index 3f0452bd4f..139e8140d7 100644 --- a/detections/endpoint/windows_installutil_in_non_standard_path.yml +++ b/detections/endpoint/windows_installutil_in_non_standard_path.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil in Non Standard Path id: dcf74b22-7933-11ec-857c-acde48001122 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -81,9 +81,7 @@ tags: - WhisperGate asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.003 - - T1218 - T1218.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_installutil_remote_network_connection.yml b/detections/endpoint/windows_installutil_remote_network_connection.yml index 7058757a08..3c11ba94f9 100644 --- a/detections/endpoint/windows_installutil_remote_network_connection.yml +++ b/detections/endpoint/windows_installutil_remote_network_connection.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil Remote Network Connection id: 4fbf9270-43da-11ec-9486-acde48001122 -version: 8 -date: '2024-12-10' +version: 10 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -76,7 +76,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.004 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_uninstall_option.yml b/detections/endpoint/windows_installutil_uninstall_option.yml index 97ee5f6a58..014a79d1e8 100644 --- a/detections/endpoint/windows_installutil_uninstall_option.yml +++ b/detections/endpoint/windows_installutil_uninstall_option.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil Uninstall Option id: cfa7b9ac-43f0-11ec-9b48-acde48001122 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -77,7 +77,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.004 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml b/detections/endpoint/windows_installutil_uninstall_option_with_network.yml index fb760e80bd..0b7b0f9896 100644 --- a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml +++ b/detections/endpoint/windows_installutil_uninstall_option_with_network.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil Uninstall Option with Network id: 1a52c836-43ef-11ec-a36c-acde48001122 -version: 7 -date: '2024-12-10' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -78,7 +78,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.004 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_installutil_url_in_command_line.yml b/detections/endpoint/windows_installutil_url_in_command_line.yml index bfae587299..3374400f25 100644 --- a/detections/endpoint/windows_installutil_url_in_command_line.yml +++ b/detections/endpoint/windows_installutil_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil URL in Command Line id: 28e06670-43df-11ec-a569-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.004 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_iso_lnk_file_creation.yml b/detections/endpoint/windows_iso_lnk_file_creation.yml index fcbbbebeea..06ff0f1426 100644 --- a/detections/endpoint/windows_iso_lnk_file_creation.yml +++ b/detections/endpoint/windows_iso_lnk_file_creation.yml @@ -1,7 +1,7 @@ name: Windows ISO LNK File Creation id: d7c2c09b-9569-4a9e-a8b6-6a39a99c1d32 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Teoderick Contreras, Splunk status: production type: Hunting @@ -47,10 +47,8 @@ tags: - Gozi Malware asset_type: Endpoint mitre_attack_id: - - T1566.001 - - T1566 - T1204.001 - - T1204 + - T1566.001 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_java_spawning_shells.yml b/detections/endpoint/windows_java_spawning_shells.yml index 8ed67cb7ab..19a3260fbf 100644 --- a/detections/endpoint/windows_java_spawning_shells.yml +++ b/detections/endpoint/windows_java_spawning_shells.yml @@ -1,6 +1,6 @@ name: Windows Java Spawning Shells id: 28c81306-5c47-11ec-bfea-acde48001122 -version: 7 +version: 8 date: '2024-12-16' author: Michael Haag, Splunk status: experimental diff --git a/detections/endpoint/windows_known_abused_dll_created.yml b/detections/endpoint/windows_known_abused_dll_created.yml index 8c1f4b886f..4ab43c381b 100644 --- a/detections/endpoint/windows_known_abused_dll_created.yml +++ b/detections/endpoint/windows_known_abused_dll_created.yml @@ -1,7 +1,7 @@ name: Windows Known Abused DLL Created id: ea91651a-772a-4b02-ac3d-985b364a5f07 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -87,7 +87,6 @@ tags: mitre_attack_id: - T1574.001 - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml index 1509baa004..fd906a1af0 100644 --- a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml +++ b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml @@ -1,7 +1,7 @@ name: Windows Known Abused DLL Loaded Suspiciously id: dd6d1f16-adc0-4e87-9c34-06189516b803 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -68,7 +68,6 @@ tags: mitre_attack_id: - T1574.001 - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml b/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml index 0aca5b42c9..8d8b1036e8 100644 --- a/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml +++ b/detections/endpoint/windows_known_graphicalproton_loaded_modules.yml @@ -1,7 +1,7 @@ name: Windows Known GraphicalProton Loaded Modules id: bf471c94-0324-4b19-a113-d02749b969bc -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_ldifde_directory_object_behavior.yml b/detections/endpoint/windows_ldifde_directory_object_behavior.yml index f03a5ff5a1..30ab7ce4b3 100644 --- a/detections/endpoint/windows_ldifde_directory_object_behavior.yml +++ b/detections/endpoint/windows_ldifde_directory_object_behavior.yml @@ -1,6 +1,6 @@ name: Windows Ldifde Directory Object Behavior id: 35cd29ca-f08c-4489-8815-f715c45460d3 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml b/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml index f2b645134e..a18658909b 100644 --- a/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml +++ b/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml @@ -1,7 +1,7 @@ name: Windows Linked Policies In ADSI Discovery id: 510ea428-4731-4d2f-8829-a28293e427aa -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_local_administrator_credential_stuffing.yml b/detections/endpoint/windows_local_administrator_credential_stuffing.yml index 4669dc1fbe..00ae64da90 100644 --- a/detections/endpoint/windows_local_administrator_credential_stuffing.yml +++ b/detections/endpoint/windows_local_administrator_credential_stuffing.yml @@ -1,7 +1,7 @@ name: Windows Local Administrator Credential Stuffing id: 09555511-aca6-484a-b6ab-72cd03d73c34 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk type: TTP status: production @@ -62,7 +62,6 @@ tags: - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml b/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml index 6a79741770..571055f6e9 100644 --- a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml +++ b/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml @@ -1,7 +1,7 @@ name: Windows LOLBAS Executed As Renamed File id: fd496996-7d9e-4894-8d40-bb85b6192dc6 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -74,7 +74,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.003 - T1218.011 product: diff --git a/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml b/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml index a11c57c45e..3c51c0705d 100644 --- a/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml +++ b/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml @@ -1,7 +1,7 @@ name: Windows LOLBAS Executed Outside Expected Path id: 326fdf44-b90c-4d2e-adca-1fd140b10536 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -65,7 +65,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1036 - T1036.005 - T1218.011 product: diff --git a/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml b/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml index f3b8b38435..6661897452 100644 --- a/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml +++ b/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml @@ -1,7 +1,7 @@ name: Windows Mail Protocol In Non-Common Process Path id: ac3311f5-661d-4e99-bd1f-3ec665b05441 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.003 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_masquerading_explorer_as_child_process.yml b/detections/endpoint/windows_masquerading_explorer_as_child_process.yml index eba3eda086..ff9d52c49c 100644 --- a/detections/endpoint/windows_masquerading_explorer_as_child_process.yml +++ b/detections/endpoint/windows_masquerading_explorer_as_child_process.yml @@ -1,7 +1,7 @@ name: Windows Masquerading Explorer As Child Process id: 61490da9-52a1-4855-a0c5-28233c88c481 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_mimikatz_binary_execution.yml b/detections/endpoint/windows_mimikatz_binary_execution.yml index b33a7416d4..8578d406d4 100644 --- a/detections/endpoint/windows_mimikatz_binary_execution.yml +++ b/detections/endpoint/windows_mimikatz_binary_execution.yml @@ -1,6 +1,6 @@ name: Windows Mimikatz Binary Execution id: a9e0d6d3-9676-4e26-994d-4e0406bb4467 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml b/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml index 6d180da12f..f83503b284 100644 --- a/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml +++ b/detections/endpoint/windows_modify_registry_valleyrat_c2_config.yml @@ -1,6 +1,6 @@ name: Windows Modify Registry ValleyRAT C2 Config id: ac59298a-8d81-4c02-8c9b-ffdac993891f -version: 4 +version: 5 date: '2024-11-13' author: Teoderick Contreras, Splunk data_source: diff --git a/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml b/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml index cc16e59756..1f0d757c88 100644 --- a/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml +++ b/detections/endpoint/windows_modify_registry_valleyrat_pwn_reg_entry.yml @@ -1,6 +1,6 @@ name: Windows Modify Registry ValleyRat PWN Reg Entry id: 6947c44e-be1f-4dd9-b198-bc42be5be196 -version: 5 +version: 6 date: '2024-12-16' author: Teoderick Contreras, Splunk data_source: diff --git a/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml b/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml index 3ace7c862d..97cd11c575 100644 --- a/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml +++ b/detections/endpoint/windows_modify_system_firewall_with_notable_process_path.yml @@ -1,7 +1,7 @@ name: Windows Modify System Firewall with Notable Process Path id: cd6d7410-9146-4471-a418-49edba6dadc4 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Will Metcalf, Splunk status: production type: TTP @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.004 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml b/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml index 273ecf6bf3..5906eedfab 100644 --- a/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml +++ b/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml @@ -1,6 +1,6 @@ name: Windows MOF Event Triggered Execution via WMI id: e59b5a73-32bf-4467-a585-452c36ae10c1 -version: 7 +version: 8 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml b/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml index 5e1bac285c..8cc18bc69f 100644 --- a/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml +++ b/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml @@ -1,7 +1,7 @@ name: Windows MSExchange Management Mailbox Cmdlet Usage id: 396de86f-25e7-4b0e-be09-a330be35249d -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: - ProxyNotShell asset_type: Endpoint mitre_attack_id: - - T1059 - T1059.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_msiexec_dllregisterserver.yml b/detections/endpoint/windows_msiexec_dllregisterserver.yml index fab94a6582..862e6c9f89 100644 --- a/detections/endpoint/windows_msiexec_dllregisterserver.yml +++ b/detections/endpoint/windows_msiexec_dllregisterserver.yml @@ -1,6 +1,6 @@ name: Windows MSIExec DLLRegisterServer id: fdb59aef-d88f-4909-8369-ec2afbd2c398 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml b/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml index 92c0e1c8b6..c5d9918949 100644 --- a/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml +++ b/detections/endpoint/windows_msiexec_hidewindow_rundll32_execution.yml @@ -1,7 +1,7 @@ name: Windows MsiExec HideWindow Rundll32 Execution id: 9683271d-92e4-43b5-a907-1983bfb9f7fd -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.007 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_msiexec_remote_download.yml b/detections/endpoint/windows_msiexec_remote_download.yml index 1d89715d94..ea822dfe4d 100644 --- a/detections/endpoint/windows_msiexec_remote_download.yml +++ b/detections/endpoint/windows_msiexec_remote_download.yml @@ -1,6 +1,6 @@ name: Windows MSIExec Remote Download id: 6aa49ff2-3c92-4586-83e0-d83eb693dfda -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_msiexec_spawn_discovery_command.yml b/detections/endpoint/windows_msiexec_spawn_discovery_command.yml index dde48d4cb7..a604c6a7d5 100644 --- a/detections/endpoint/windows_msiexec_spawn_discovery_command.yml +++ b/detections/endpoint/windows_msiexec_spawn_discovery_command.yml @@ -1,6 +1,6 @@ name: Windows MSIExec Spawn Discovery Command id: e9d05aa2-32f0-411b-930c-5b8ca5c4fcee -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_msiexec_spawn_windbg.yml b/detections/endpoint/windows_msiexec_spawn_windbg.yml index 4e4121a5d0..c80059d8d6 100644 --- a/detections/endpoint/windows_msiexec_spawn_windbg.yml +++ b/detections/endpoint/windows_msiexec_spawn_windbg.yml @@ -1,6 +1,6 @@ name: Windows MSIExec Spawn WinDBG id: 9a18f7c2-1fe3-47b8-9467-8b3976770a30 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml b/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml index b7255c3665..697c254586 100644 --- a/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml +++ b/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml @@ -1,6 +1,6 @@ name: Windows MSIExec Unregister DLLRegisterServer id: a27db3c5-1a9a-46df-a577-765d3f1a3c24 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml b/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml index 382204bb18..f223d20020 100644 --- a/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml +++ b/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml @@ -1,7 +1,7 @@ name: Windows Multi hop Proxy TOR Website Query id: 4c2d198b-da58-48d7-ba27-9368732d0054 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -55,7 +55,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.003 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml b/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml index 730fe3867d..cc48eeadc3 100644 --- a/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml +++ b/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml @@ -1,7 +1,7 @@ name: Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos id: 98f22d82-9d62-11eb-9fcf-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk type: TTP status: production @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml b/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml index 7696c03e9d..993132ddda 100644 --- a/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml +++ b/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml @@ -1,7 +1,7 @@ name: Windows Multiple Invalid Users Fail To Authenticate Using Kerberos id: 001266a6-9d5b-11eb-829b-acde48001122 -date: '2024-11-13' -version: 5 +date: '2025-02-10' +version: 6 type: TTP status: production author: Mauricio Velazco, Splunk @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml b/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml index c8db8b309f..88dc4a2ca2 100644 --- a/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml +++ b/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml @@ -1,12 +1,12 @@ name: Windows Multiple Invalid Users Failed To Authenticate Using NTLM id: 57ad5a64-9df7-11eb-a290-acde48001122 type: TTP -version: 6 +version: 7 author: Mauricio Velazco, Splunk status: production data_source: - Windows Event Log Security 4776 -date: '2024-11-13' +date: '2025-02-10' description: The following analytic detects a single source endpoint failing to authenticate with 30 unique invalid users using the NTLM protocol. It leverages EventCode 4776 from Domain Controller logs, focusing on error code 0xC0000064, which indicates @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml b/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml index cda160cc85..e9ffe53973 100644 --- a/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml +++ b/detections/endpoint/windows_multiple_ntlm_null_domain_authentications.yml @@ -1,7 +1,7 @@ name: Windows Multiple NTLM Null Domain Authentications id: c187ce2c-c88e-4cec-8a1c-607ca0dedd78 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -64,7 +64,6 @@ tags: - Active Directory Password Spraying asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml b/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml index c57c7baf7e..7d72b1462b 100644 --- a/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml +++ b/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml @@ -1,12 +1,12 @@ name: Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials id: e61918fa-9ca4-11eb-836c-acde48001122 type: TTP -version: 6 +version: 7 status: production author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4648 -date: '2024-11-13' +date: '2025-02-10' description: The following analytic identifies a source user failing to authenticate with 30 unique users using explicit credentials on a host. It leverages Windows Event 4648, which is generated when a process attempts an account logon by explicitly @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml index 4791ed5824..d3c8a07eb4 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml @@ -3,10 +3,10 @@ id: 7ed272a4-9c77-11eb-af22-acde48001122 author: Mauricio Velazco, Splunk type: TTP status: production -version: 6 +version: 7 data_source: - Windows Event Log Security 4776 -date: '2024-11-13' +date: '2025-02-10' description: The following analytic identifies a single source endpoint failing to authenticate with 30 unique valid users using the NTLM protocol. It leverages EventCode 4776 from Domain Controller logs, focusing on error code 0xC000006A, which indicates @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml index b4e4eb9ae2..8d8df90f05 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml @@ -1,12 +1,12 @@ name: Windows Multiple Users Failed To Authenticate From Process id: 9015385a-9c84-11eb-bef2-acde48001122 type: TTP -version: 6 +version: 7 status: production author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4625 -date: '2024-11-13' +date: '2025-02-10' description: The following analytic detects a source process failing to authenticate with 30 unique users, indicating a potential Password Spraying attack. It leverages Windows Event 4625 with Logon Type 2, collected from domain controllers, member @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml index 15df1ec8be..2a4325b756 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Multiple Users Failed To Authenticate Using Kerberos id: 3a91a212-98a9-11eb-b86a-acde48001122 type: TTP -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' status: production author: Mauricio Velazco, Splunk data_source: @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml b/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml index 3c72e172b9..8e5c99c808 100644 --- a/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml +++ b/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml @@ -3,8 +3,8 @@ id: 80f9d53e-9ca1-11eb-b0d6-acde48001122 author: Mauricio Velazco, Splunk type: TTP status: production -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' data_source: - Windows Event Log Security 4625 description: The following analytic identifies a source host failing to authenticate @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml b/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml index bfeca92a28..4703844127 100644 --- a/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml +++ b/detections/endpoint/windows_new_custom_security_descriptor_set_on_eventlog_channel.yml @@ -16,22 +16,9 @@ description: The following analytic detects suspicious modifications to the Even viewing, ingesting and interacting event logs. data_source: - Sysmon EventID 13 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime FROM datamodel=Endpoint.Registry WHERE Registry.registry_path= "*\\Services\\Eventlog\\*" - AND Registry.registry_value_name=CustomSD BY Registry.dest Registry.registry_value_data - Registry.action Registry.process_guid Registry.process_id Registry.registry_key_name - Registry.user Registry.registry_value_name Registry.registry_path | `drop_dm_object_name(Registry)` | where - isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `windows_new_custom_security_descriptor_set_on_eventlog_channel_filter`' -how_to_implement: To successfully implement this search, you must be ingesting data - that records registry activity from your hosts to populate the endpoint data model - in the registry node. This is typically populated via endpoint detection-and-response - product, such as Carbon Black or endpoint data sources, such as Sysmon. The data - used for this search is typically generated via logs that report reads and writes - to the registry. If you are using Sysmon, you must have at least version 2.0 of - the official Sysmon TA. https://splunkbase.splunk.com/app/5709 -known_false_positives: None identified, setting up the "CustomSD" value is considered - a legacy option and shouldn't be a common activity. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry WHERE Registry.registry_path= "*\\Services\\Eventlog\\*" AND Registry.registry_value_name=CustomSD BY Registry.dest Registry.registry_value_data Registry.action Registry.process_guid Registry.process_id Registry.registry_key_name Registry.user Registry.registry_value_name Registry.registry_path | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_new_custom_security_descriptor_set_on_eventlog_channel_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. If you are using Sysmon, you must have at least version 2.0 of the official Sysmon TA. https://splunkbase.splunk.com/app/5709 +known_false_positives: None identified, setting up the "CustomSD" value is considered a legacy option and shouldn't be a common activity. references: - https://learn.microsoft.com/en-us/troubleshoot/windows-server/group-policy/set-event-log-security-locally-or-via-group-policy - https://attack.mitre.org/techniques/T1562/002/ diff --git a/detections/endpoint/windows_new_default_file_association_value_set.yml b/detections/endpoint/windows_new_default_file_association_value_set.yml index ad44980ccf..74809b6e75 100644 --- a/detections/endpoint/windows_new_default_file_association_value_set.yml +++ b/detections/endpoint/windows_new_default_file_association_value_set.yml @@ -1,16 +1,35 @@ name: Windows New Default File Association Value Set id: 7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a -version: 1 -date: '2025-01-15' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting -description: The following analytic detects registry changes to the default file association value. It leverages data from the Endpoint data model, specifically monitoring registry paths under "HKCR\\*\\shell\\open\\command\\*". This activity can be significant because, attackers might alter the default file associations in order to execute arbitrary scripts or payloads when a user opens a file, leading to potential code execution. If confirmed malicious, this technique can enable attackers to persist on the compromised host and execute further malicious commands, posing a severe threat to the environment. +description: The following analytic detects registry changes to the default file association + value. It leverages data from the Endpoint data model, specifically monitoring registry + paths under "HKCR\\*\\shell\\open\\command\\*". This activity can be significant + because, attackers might alter the default file associations in order to execute + arbitrary scripts or payloads when a user opens a file, leading to potential code + execution. If confirmed malicious, this technique can enable attackers to persist + on the compromised host and execute further malicious commands, posing a severe + threat to the environment. data_source: - Sysmon EventID 13 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\shell\\open\\command\\*" Registry.registry_path IN ("*HKCR\\*", "*HKEY_CLASSES_ROOT\\*") by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `windows_new_default_file_association_value_set_filter`' -how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. -known_false_positives: Windows and third party software will create and modify these file associations during installation or upgrades. Additional filters needs to be applied to tune environment specific false positives. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\shell\\open\\command\\*" + Registry.registry_path IN ("*HKCR\\*", "*HKEY_CLASSES_ROOT\\*") by Registry.dest Registry.user + Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data + | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` + | `windows_new_default_file_association_value_set_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: Windows and third party software will create and modify these + file associations during installation or upgrades. Additional filters needs to be + applied to tune environment specific false positives. references: - https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features drilldown_searches: @@ -19,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" and "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", + "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ tags: @@ -33,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.001 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security @@ -42,6 +65,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml b/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml index 9d6caf3abd..aae826157a 100644 --- a/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml +++ b/detections/endpoint/windows_ngrok_reverse_proxy_usage.yml @@ -1,6 +1,6 @@ name: Windows Ngrok Reverse Proxy Usage id: e2549f2c-0aef-408a-b0c1-e0f270623436 -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_nirsoft_advancedrun.yml b/detections/endpoint/windows_nirsoft_advancedrun.yml index 62b05e5300..4a5461615e 100644 --- a/detections/endpoint/windows_nirsoft_advancedrun.yml +++ b/detections/endpoint/windows_nirsoft_advancedrun.yml @@ -1,6 +1,6 @@ name: Windows NirSoft AdvancedRun id: bb4f3090-7ae4-11ec-897f-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml b/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml index b152d8f05a..22f73f858f 100644 --- a/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml +++ b/detections/endpoint/windows_njrat_fileless_storage_via_registry.yml @@ -1,7 +1,7 @@ name: Windows Njrat Fileless Storage via Registry id: a5fffbbd-271f-4980-94ed-4fbf17f0af1c -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1027.011 - - T1027 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_non_system_account_targeting_lsass.yml b/detections/endpoint/windows_non_system_account_targeting_lsass.yml index 0a6c933bc2..b6588d58e9 100644 --- a/detections/endpoint/windows_non_system_account_targeting_lsass.yml +++ b/detections/endpoint/windows_non_system_account_targeting_lsass.yml @@ -1,7 +1,7 @@ name: Windows Non-System Account Targeting Lsass id: b1ce9a72-73cf-11ec-981b-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_odbcconf_load_dll.yml b/detections/endpoint/windows_odbcconf_load_dll.yml index 815aa3b02f..f7a52f0e6a 100644 --- a/detections/endpoint/windows_odbcconf_load_dll.yml +++ b/detections/endpoint/windows_odbcconf_load_dll.yml @@ -1,6 +1,6 @@ name: Windows Odbcconf Load DLL id: 141e7fca-a9f0-40fd-a539-9aac8be41f1b -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_odbcconf_load_response_file.yml b/detections/endpoint/windows_odbcconf_load_response_file.yml index 0fa23e5e03..7d234fd114 100644 --- a/detections/endpoint/windows_odbcconf_load_response_file.yml +++ b/detections/endpoint/windows_odbcconf_load_response_file.yml @@ -1,6 +1,6 @@ name: Windows Odbcconf Load Response File id: 1acafff9-1347-4b40-abae-f35aa4ba85c1 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml b/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml index 52313880e5..f6134c4079 100644 --- a/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml +++ b/detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml @@ -1,17 +1,36 @@ name: Windows Office Product Dropped Cab or Inf File id: dbdd251e-dd45-4ec9-a555-f5e151391746 -version: 1 -date: '2025-01-20' +version: 2 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP -description: The following analytic detects Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation. It leverages the Endpoint.Processes and Endpoint.Filesystem data models to identify Office applications creating these file types. This activity is significant as it may signal an attempt to load malicious ActiveX controls and download remote payloads, a known attack vector. If confirmed malicious, this could lead to remote code execution, allowing attackers to gain control over the affected system and potentially compromise sensitive data. +description: The following analytic detects Office products writing .cab or .inf files, + indicative of CVE-2021-40444 exploitation. It leverages the Endpoint.Processes and + Endpoint.Filesystem data models to identify Office applications creating these file + types. This activity is significant as it may signal an attempt to load malicious + ActiveX controls and download remote payloads, a known attack vector. If confirmed + malicious, this could lead to remote code execution, allowing attackers to gain + control over the affected system and potentially compromise sensitive data. data_source: - Sysmon EventID 1 AND Sysmon EventID 11 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_office_products` by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | join proc_guid, _time [ | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.cab", "*.inf") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid | `drop_dm_object_name(Filesystem)` |rename process_guid as proc_guid | fields _time dest file_create_time file_name file_path process_name process_path process proc_guid] | dedup file_create_time | table dest, process_name, process, file_create_time, file_name, file_path, proc_guid | `windows_office_product_dropped_cab_or_inf_file_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + where `process_office_products` by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)` + |rename process_guid as proc_guid | join proc_guid, _time [ | tstats `security_content_summariesonly` + count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem + where Filesystem.file_name IN ("*.cab", "*.inf") by _time span=1h Filesystem.dest + Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid + | `drop_dm_object_name(Filesystem)` |rename process_guid as proc_guid | fields _time + dest file_create_time file_name file_path process_name process_path process proc_guid] + | dedup file_create_time | table dest, process_name, process, file_create_time, + file_name, file_path, proc_guid | `windows_office_product_dropped_cab_or_inf_file_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` + node. known_false_positives: The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. @@ -54,7 +73,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -64,6 +82,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_cabinf.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_cabinf.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_dropped_uncommon_file.yml b/detections/endpoint/windows_office_product_dropped_uncommon_file.yml index bf3090d832..fad1a08049 100644 --- a/detections/endpoint/windows_office_product_dropped_uncommon_file.yml +++ b/detections/endpoint/windows_office_product_dropped_uncommon_file.yml @@ -1,15 +1,35 @@ name: Windows Office Product Dropped Uncommon File id: 7ac0fced-9eae-4381-a748-90dcd1aa9393 -version: 1 -date: '2025-01-20' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github status: production type: Anomaly -description: The following analytic detects Microsoft Office applications dropping or creating executables or scripts on a Windows OS. It leverages process creation and file system events from the Endpoint data model to identify Office applications like Word or Excel generating files with extensions such as ".exe", ".dll", or ".ps1". This behavior is significant as it is often associated with spear-phishing attacks where malicious files are dropped to compromise the host. If confirmed malicious, this activity could lead to code execution, privilege escalation, or persistent access, posing a severe threat to the environment. +description: The following analytic detects Microsoft Office applications dropping + or creating executables or scripts on a Windows OS. It leverages process creation + and file system events from the Endpoint data model to identify Office applications + like Word or Excel generating files with extensions such as ".exe", ".dll", or ".ps1". + This behavior is significant as it is often associated with spear-phishing attacks + where malicious files are dropped to compromise the host. If confirmed malicious, + this activity could lead to code execution, privilege escalation, or persistent + access, posing a severe threat to the environment. data_source: - Sysmon EventID 1 AND Sysmon EventID 11 -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_office_products` by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)` | join process_guid, _time [| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.dll", "*.exe", "*.js", "*.pif", "*.ps1", "*.scr", "*.vbe", "*.vbs") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time file_name file_path process_name process_path process process_guid] | dedup file_create_time | table dest, process_name, process, file_create_time, file_name, file_path, process_guid | `windows_office_product_dropped_uncommon_file_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + where `process_office_products` by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.process_guid | `drop_dm_object_name(Processes)` + | join process_guid, _time [| tstats `security_content_summariesonly` count min(_time) + as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name + IN ("*.dll", "*.exe", "*.js", "*.pif", "*.ps1", "*.scr", "*.vbe", "*.vbs") by _time + span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.process_guid + Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time + file_name file_path process_name process_path process process_guid] | dedup file_create_time + | table dest, process_name, process, file_create_time, file_name, file_path, process_guid + | `windows_office_product_dropped_uncommon_file_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. known_false_positives: office macro for automation may do this behavior references: - https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation @@ -49,7 +69,6 @@ tags: - PlugX asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -59,6 +78,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_macro_js_1/sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_loaded_mshtml_module.yml b/detections/endpoint/windows_office_product_loaded_mshtml_module.yml index 2d546a5b2b..cb6ba413cc 100644 --- a/detections/endpoint/windows_office_product_loaded_mshtml_module.yml +++ b/detections/endpoint/windows_office_product_loaded_mshtml_module.yml @@ -1,16 +1,31 @@ name: Windows Office Product Loaded MSHTML Module id: 4cc015c9-687c-40d2-adcc-46350f66e10c -version: 1 -date: '2025-01-20' +version: 2 +date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk status: production type: Anomaly -description: The following analytic detects the loading of the mshtml.dll module into an Office product, which is indicative of CVE-2021-40444 exploitation. It leverages Sysmon EventID 7 to monitor image loads by specific Office processes. This activity is significant because it can indicate an attempt to exploit a vulnerability in the MSHTML component via a malicious document. If confirmed malicious, this could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further network penetration. +description: The following analytic detects the loading of the mshtml.dll module into + an Office product, which is indicative of CVE-2021-40444 exploitation. It leverages + Sysmon EventID 7 to monitor image loads by specific Office processes. This activity + is significant because it can indicate an attempt to exploit a vulnerability in + the MSHTML component via a malicious document. If confirmed malicious, this could + allow an attacker to execute arbitrary code, potentially leading to system compromise, + data exfiltration, or further network penetration. data_source: - Sysmon EventID 7 -search: '`sysmon` EventID=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe", "wordpad.exe", "wordview.exe") loaded_file_path IN ("*\\mshtml.dll", "*\\Microsoft.mshtml.dll","*\\IE.Interop.MSHTML.dll","*\\MshtmlDac.dll","*\\MshtmlDed.dll","*\\MshtmlDer.dll") | stats count min(_time) as firstTime max(_time) as lastTime by user_id, dest, process_name, loaded_file, loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loaded_mshtml_module_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs with the process names and image loads from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -known_false_positives: Limited false positives will be present, however, tune as necessary. Some applications may legitimately load mshtml.dll. +search: '`sysmon` EventID=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", + "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", + "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe", "wordpad.exe", "wordview.exe") + loaded_file_path IN ("*\\mshtml.dll", "*\\Microsoft.mshtml.dll","*\\IE.Interop.MSHTML.dll","*\\MshtmlDac.dll","*\\MshtmlDed.dll","*\\MshtmlDer.dll") + | stats count min(_time) as firstTime max(_time) as lastTime by user_id, dest, process_name, + loaded_file, loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_office_product_loaded_mshtml_module_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process names and image loads from your endpoints. If you are using + Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +known_false_positives: Limited false positives will be present, however, tune as necessary. + Some applications may legitimately load mshtml.dll. references: - https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/ - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 @@ -22,7 +37,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -44,7 +64,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -54,6 +73,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_mshtml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_mshtml.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_loading_taskschd_dll.yml b/detections/endpoint/windows_office_product_loading_taskschd_dll.yml index b16c25faa3..a7ba40103b 100644 --- a/detections/endpoint/windows_office_product_loading_taskschd_dll.yml +++ b/detections/endpoint/windows_office_product_loading_taskschd_dll.yml @@ -1,16 +1,33 @@ name: Windows Office Product Loading Taskschd DLL id: d7297cfa-1f04-4714-bfbe-3679e0666959 -version: 1 -date: '2025-01-20' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic detects an Office document creating a scheduled task, either through a macro VBA API or by loading `taskschd.dll`. This detection leverages Sysmon EventCode 7 to identify when Office applications load the `taskschd.dll` file. This activity is significant as it is a common technique used by malicious macro malware to establish persistence or initiate beaconing. If confirmed malicious, this could allow an attacker to maintain persistence, execute arbitrary commands, or schedule future malicious activities, posing a significant threat to the environment. +description: The following analytic detects an Office document creating a scheduled + task, either through a macro VBA API or by loading `taskschd.dll`. This detection + leverages Sysmon EventCode 7 to identify when Office applications load the `taskschd.dll` + file. This activity is significant as it is a common technique used by malicious + macro malware to establish persistence or initiate beaconing. If confirmed malicious, + this could allow an attacker to maintain persistence, execute arbitrary commands, + or schedule future malicious activities, posing a significant threat to the environment. data_source: - Sysmon EventID 7 -search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path = "*\\taskschd.dll" | stats min(_time) as firstTime max(_time) as lastTime count by user_id, dest, process_name,loaded_file, loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loading_taskschd_dll_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Also be sure to include those monitored dll to your own sysmon config. -known_false_positives: False positives may occur if legitimate office documents are creating scheduled tasks. Ensure to investigate the scheduled task and the command to be executed. If the task is benign, add the task name to the exclusion list. Some applications may legitimately load taskschd.dll. +search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", + "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", + "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path = "*\\taskschd.dll" + | stats min(_time) as firstTime max(_time) as lastTime count by user_id, dest, process_name,loaded_file, + loaded_file_path, original_file_name, process_guid | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_office_product_loading_taskschd_dll_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. + If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + Also be sure to include those monitored dll to your own sysmon config. +known_false_positives: False positives may occur if legitimate office documents are + creating scheduled tasks. Ensure to investigate the scheduled task and the command + to be executed. If the task is benign, add the task name to the exclusion list. + Some applications may legitimately load taskschd.dll. references: - https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/ - https://redcanary.com/threat-detection-report/techniques/scheduled-task-job/ @@ -21,7 +38,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -37,7 +59,6 @@ tags: - Spearphishing Attachments asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -47,6 +68,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_loading_vbe7_dll.yml b/detections/endpoint/windows_office_product_loading_vbe7_dll.yml index d4aa93a79a..e68293a575 100644 --- a/detections/endpoint/windows_office_product_loading_vbe7_dll.yml +++ b/detections/endpoint/windows_office_product_loading_vbe7_dll.yml @@ -1,16 +1,33 @@ name: Windows Office Product Loading VBE7 DLL id: 7cfec906-2697-43f7-898b-83634a051d9a -version: 1 -date: '2025-01-20' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly -description: The following analytic identifies office documents executing macro code. It leverages Sysmon EventCode 7 to detect when processes like WINWORD.EXE or EXCEL.EXE load specific DLLs associated with macros (e.g., VBE7.DLL). This activity is significant because macros are a common attack vector for delivering malicious payloads, such as malware. If confirmed malicious, this could lead to unauthorized code execution, data exfiltration, or further compromise of the system. Disabling macros by default is recommended to mitigate this risk. +description: The following analytic identifies office documents executing macro code. + It leverages Sysmon EventCode 7 to detect when processes like WINWORD.EXE or EXCEL.EXE + load specific DLLs associated with macros (e.g., VBE7.DLL). This activity is significant + because macros are a common attack vector for delivering malicious payloads, such + as malware. If confirmed malicious, this could lead to unauthorized code execution, + data exfiltration, or further compromise of the system. Disabling macros by default + is recommended to mitigate this risk. data_source: - Sysmon EventID 7 -search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path IN ("*\\VBE7INTL.DLL", "*\\VBE7.DLL", "*\\VBEUI.DLL") | stats min(_time) as firstTime max(_time) as lastTime values(loaded_file) as loaded_file count by dest EventCode process_name process_guid | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loading_vbe7_dll_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Also be sure to include those monitored dll to your own sysmon config. -known_false_positives: False positives may occur if legitimate office documents are executing macro code. Ensure to investigate the macro code and the command to be executed. If the macro code is benign, add the document name to the exclusion list. Some applications may legitimately load VBE7INTL.DLL, VBE7.DLL, or VBEUI.DLL. +search: '`sysmon` EventCode=7 process_name IN ("EQNEDT32.exe", "excel.exe", "Graph.exe", + "msaccess.exe", "mspub.exe", "onenote.exe", "onenoteim.exe", "onenotem.exe", "outlook.exe", + "powerpnt.exe", "visio.exe", "winproj.exe", "winword.exe") loaded_file_path IN ("*\\VBE7INTL.DLL", + "*\\VBE7.DLL", "*\\VBEUI.DLL") | stats min(_time) as firstTime max(_time) as lastTime + values(loaded_file) as loaded_file count by dest EventCode process_name process_guid + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_loading_vbe7_dll_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name and ImageLoaded (Like sysmon EventCode 7) from your endpoints. + If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + Also be sure to include those monitored dll to your own sysmon config. +known_false_positives: False positives may occur if legitimate office documents are + executing macro code. Ensure to investigate the macro code and the command to be + executed. If the macro code is benign, add the document name to the exclusion list. + Some applications may legitimately load VBE7INTL.DLL, VBE7.DLL, or VBEUI.DLL. references: - https://www.joesandbox.com/analysis/386500/0/html - https://www.joesandbox.com/analysis/702680/0/html @@ -24,7 +41,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -48,7 +70,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -58,6 +79,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml b/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml index 0b215898be..60bbc6b349 100644 --- a/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml +++ b/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml @@ -1,17 +1,38 @@ name: Windows Office Product Spawned Child Process For Download id: f02b64b8-cbea-4f75-bf77-7a05111566b1 -version: 1 -date: '2025-01-14' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic identifies Office applications spawning child processes to download content via HTTP/HTTPS. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process creation events where Office applications like Word or Excel initiate network connections, excluding common browsers. This activity is significant as it often indicates the use of malicious documents to execute living-off-the-land binaries (LOLBins) for payload delivery. If confirmed malicious, this behavior could lead to unauthorized code execution, data exfiltration, or further malware deployment, posing a severe threat to the organization's security. +description: The following analytic identifies Office applications spawning child + processes to download content via HTTP/HTTPS. It leverages data from Endpoint Detection + and Response (EDR) agents, focusing on process creation events where Office applications + like Word or Excel initiate network connections, excluding common browsers. This + activity is significant as it often indicates the use of malicious documents to + execute living-off-the-land binaries (LOLBins) for payload delivery. If confirmed + malicious, this behavior could lead to unauthorized code execution, data exfiltration, + or further malware deployment, posing a severe threat to the organization's security. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` Processes.process IN ("*http:*","*https:*") NOT (Processes.original_file_name IN ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_spawned_child_process_for_download_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` + Processes.process IN ("*http:*","*https:*") NOT (Processes.original_file_name IN + ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) by Processes.dest Processes.user + Processes.parent_process_name Processes.process_name Processes.process Processes.process_id + Processes.parent_process_id Processes.original_file_name | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_office_product_spawned_child_process_for_download_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: Default browser not in the filter list. references: - https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/ @@ -22,7 +43,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -40,7 +66,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -50,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets2/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets2/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_spawned_control.yml b/detections/endpoint/windows_office_product_spawned_control.yml index 5590c761b9..12ffb28a63 100644 --- a/detections/endpoint/windows_office_product_spawned_control.yml +++ b/detections/endpoint/windows_office_product_spawned_control.yml @@ -1,7 +1,7 @@ name: Windows Office Product Spawned Control id: 081c485d-ac8d-4bee-ad4c-525772fead4d -version: 1 -date: '2025-01-14' +version: 3 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -17,7 +17,12 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` Processes.process_name=control.exe by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `windows_office_product_spawned_control_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` + Processes.process_name=control.exe by Processes.dest Processes.user Processes.parent_process_name + Processes.parent_process Processes.process_name Processes.process Processes.process_id + Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)`| `windows_office_product_spawned_control_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -71,7 +76,6 @@ tags: cve: - CVE-2021-40444 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -81,6 +85,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_control.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_control.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_spawned_msdt.yml b/detections/endpoint/windows_office_product_spawned_msdt.yml index 3a79e47208..9f855ec660 100644 --- a/detections/endpoint/windows_office_product_spawned_msdt.yml +++ b/detections/endpoint/windows_office_product_spawned_msdt.yml @@ -1,7 +1,7 @@ name: Windows Office Product Spawned MSDT id: a3148fad-3734-4b7f-9a71-62f08d39fab1 -version: 1 -date: '2025-01-14' +version: 3 +date: '2025-02-10' author: Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -17,7 +17,12 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` Processes.process_name=msdt.exe by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_msdt_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` + Processes.process_name=msdt.exe by Processes.dest Processes.user Processes.parent_process_name + Processes.parent_process Processes.process_name Processes.original_file_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_msdt_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -74,7 +79,6 @@ tags: cve: - CVE-2022-30190 mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -84,6 +88,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/msdt.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml b/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml index 21813278bb..f44212470f 100644 --- a/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml +++ b/detections/endpoint/windows_office_product_spawned_rundll32_with_no_dll.yml @@ -1,7 +1,7 @@ name: Windows Office Product Spawned Rundll32 With No DLL id: f28e787e-69ca-480e-9f98-ab970e6d4bcc -version: 1 -date: '2025-01-14' +version: 2 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -17,7 +17,12 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` `process_rundll32` (Processes.process!=*.dll*) by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_rundll32_with_no_dll_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` + `process_rundll32` (Processes.process!=*.dll*) by Processes.dest Processes.user + Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_rundll32_with_no_dll_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -68,7 +73,6 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -78,6 +82,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_icedid.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_icedid.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_office_product_spawned_uncommon_process.yml b/detections/endpoint/windows_office_product_spawned_uncommon_process.yml index 5dc516ea3d..be1ba871e9 100644 --- a/detections/endpoint/windows_office_product_spawned_uncommon_process.yml +++ b/detections/endpoint/windows_office_product_spawned_uncommon_process.yml @@ -1,17 +1,39 @@ name: Windows Office Product Spawned Uncommon Process id: 55d8741c-fa32-4692-8109-410304961eb8 -version: 1 -date: '2025-01-13' +version: 2 +date: '2025-02-10' author: Michael Haag, Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects a Microsoft Office product spawning uncommon processes. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process creation events where Office applications are the parent process. This activity is significant as it may indicate an attempt of a malicious macro execution or exploitation of an unknown vulnerability in an office product, in order to bypass security controls. If confirmed malicious, this behavior could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further lateral movement within the network. +description: The following analytic detects a Microsoft Office product spawning uncommon + processes. This detection leverages data from Endpoint Detection and Response (EDR) + agents, focusing on process creation events where Office applications are the parent + process. This activity is significant as it may indicate an attempt of a malicious + macro execution or exploitation of an unknown vulnerability in an office product, + in order to bypass security controls. If confirmed malicious, this behavior could + allow an attacker to execute arbitrary code, potentially leading to system compromise, + data exfiltration, or further lateral movement within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` AND (`process_bitsadmin` OR `process_certutil` OR `process_cmd` OR `process_cscript` OR `process_mshta` OR `process_powershell` OR `process_regsvr32` OR `process_rundll32` OR `process_wmic` OR `process_wscript`) by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_uncommon_process_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` + AND (`process_bitsadmin` OR `process_certutil` OR `process_cmd` OR `process_cscript` + OR `process_mshta` OR `process_powershell` OR `process_regsvr32` OR `process_rundll32` + OR `process_wmic` OR `process_wscript`) by Processes.dest Processes.user Processes.parent_process_name + Processes.parent_process Processes.process_name Processes.original_file_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_office_product_spawned_uncommon_process_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: False positives should be limited, however filter as needed. references: - https://any.run/malware-trends/trickbot @@ -74,7 +96,6 @@ tags: - Warzone RAT asset_type: Endpoint mitre_attack_id: - - T1566 - T1566.001 product: - Splunk Enterprise @@ -84,26 +105,31 @@ tags: tests: - name: True Positive Test - Macro attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/datasets/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog - name: True Positive Test - IcedId attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/phish_icedid/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/phish_icedid/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog -- name: True Positive Test +- name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog - name: True Positive Test - TrickBot attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/spear_phish/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_papercut_ng_spawn_shell.yml b/detections/endpoint/windows_papercut_ng_spawn_shell.yml index 31198dc5a3..d647e50311 100644 --- a/detections/endpoint/windows_papercut_ng_spawn_shell.yml +++ b/detections/endpoint/windows_papercut_ng_spawn_shell.yml @@ -1,6 +1,6 @@ name: Windows PaperCut NG Spawn Shell id: a602d9a2-aaea-45f8-bf0f-d851168d61ca -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml b/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml index 11cc9f084e..1fb1a5fb88 100644 --- a/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml +++ b/detections/endpoint/windows_parent_pid_spoofing_with_explorer.yml @@ -1,7 +1,7 @@ name: Windows Parent PID Spoofing with Explorer id: 17f8f69c-5d00-4c88-9c6f-493bbdef20a1 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1134.004 - - T1134 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml b/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml index 18c5531a67..13103b18d8 100644 --- a/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml +++ b/detections/endpoint/windows_phishing_pdf_file_executes_url_link.yml @@ -1,7 +1,7 @@ name: Windows Phishing PDF File Executes URL Link id: 2fa9dec8-9d8e-46d3-96c1-202c06f0e6e1 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml b/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml index 2b4bed4e9f..bc0b87b903 100644 --- a/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml +++ b/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml @@ -1,7 +1,7 @@ name: Windows Phishing Recent ISO Exec Registry id: cb38ee66-8ae5-47de-bd66-231c7bbc0b2c -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -48,7 +48,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_possible_credential_dumping.yml b/detections/endpoint/windows_possible_credential_dumping.yml index 470fcafb77..2d20510beb 100644 --- a/detections/endpoint/windows_possible_credential_dumping.yml +++ b/detections/endpoint/windows_possible_credential_dumping.yml @@ -1,7 +1,7 @@ name: Windows Possible Credential Dumping id: e4723b92-7266-11ec-af45-acde48001122 -version: 7 -date: '2024-11-13' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -74,7 +74,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.001 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml b/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml index be0d947169..e74b775e06 100644 --- a/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml +++ b/detections/endpoint/windows_powershell_add_module_to_global_assembly_cache.yml @@ -1,7 +1,7 @@ name: Windows PowerShell Add Module to Global Assembly Cache id: 3fc16961-97e5-4a5b-a079-e4ab0d9763eb -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powershell_cryptography_namespace.yml b/detections/endpoint/windows_powershell_cryptography_namespace.yml index bf088f301f..cdcc825296 100644 --- a/detections/endpoint/windows_powershell_cryptography_namespace.yml +++ b/detections/endpoint/windows_powershell_cryptography_namespace.yml @@ -1,7 +1,7 @@ name: Windows Powershell Cryptography Namespace id: f8b482f4-6d62-49fa-a905-dfa15698317b -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_disable_http_logging.yml b/detections/endpoint/windows_powershell_disable_http_logging.yml index 4c3060bb6a..b770a22794 100644 --- a/detections/endpoint/windows_powershell_disable_http_logging.yml +++ b/detections/endpoint/windows_powershell_disable_http_logging.yml @@ -1,7 +1,7 @@ name: Windows PowerShell Disable HTTP Logging id: 27958de0-2857-43ca-9d4c-b255cf59dcab -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -58,10 +58,8 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1562 - - T1562.002 - - T1505 - T1505.004 + - T1562.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_export_certificate.yml b/detections/endpoint/windows_powershell_export_certificate.yml index bbe40a4adc..acbed42b34 100644 --- a/detections/endpoint/windows_powershell_export_certificate.yml +++ b/detections/endpoint/windows_powershell_export_certificate.yml @@ -1,7 +1,7 @@ name: Windows PowerShell Export Certificate id: 5e38ded4-c964-41f4-8cb6-4a1a53c6929f -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -55,7 +55,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 - T1649 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powershell_export_pfxcertificate.yml b/detections/endpoint/windows_powershell_export_pfxcertificate.yml index 7f493a22c9..8a44eca228 100644 --- a/detections/endpoint/windows_powershell_export_pfxcertificate.yml +++ b/detections/endpoint/windows_powershell_export_pfxcertificate.yml @@ -1,7 +1,7 @@ name: Windows PowerShell Export PfxCertificate id: ed06725f-6da6-439f-9dcc-ab30e891297c -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -54,7 +54,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 - T1649 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml b/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml index ae73b3a6e6..3a9bdc8cc3 100644 --- a/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml +++ b/detections/endpoint/windows_powershell_iis_components_webglobalmodule_usage.yml @@ -1,7 +1,7 @@ name: Windows PowerShell IIS Components WebGlobalModule Usage id: 33fc9f6f-0ce7-4696-924e-a69ec61a3d57 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powershell_import_applocker_policy.yml b/detections/endpoint/windows_powershell_import_applocker_policy.yml index a2cfb60449..b7e2a44f69 100644 --- a/detections/endpoint/windows_powershell_import_applocker_policy.yml +++ b/detections/endpoint/windows_powershell_import_applocker_policy.yml @@ -1,7 +1,7 @@ name: Windows Powershell Import Applocker Policy id: 102af98d-0ca3-4aa4-98d6-7ab2b98b955a -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -58,9 +58,7 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_logoff_user_via_quser.yml b/detections/endpoint/windows_powershell_logoff_user_via_quser.yml index c22dd241a4..1e2d7ad33b 100644 --- a/detections/endpoint/windows_powershell_logoff_user_via_quser.yml +++ b/detections/endpoint/windows_powershell_logoff_user_via_quser.yml @@ -1,20 +1,26 @@ name: Windows Powershell Logoff User via Quser id: 6d70780d-4cfe-4820-bafd-1b43941986b5 -version: 1 -date: '2024-12-12' +version: 2 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Powershell Script Block Logging 4104 type: Anomaly status: production -description: The following analytic detects the process of logging off a user through the use of the quser and logoff commands. By monitoring for these commands, the analytic identifies actions where a user session is forcibly terminated, which could be part of an administrative task or a potentially unauthorized access attempt. This detection helps identify potential misuse or malicious activity where a user’s access is revoked without proper authorization, providing insight into potential security incidents involving account management or session manipulation. -search: '`powershell` EventCode=4104 ScriptBlockText = "*quser*logoff*" - | stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText UserID Computer - | rename Computer as dest, UserID as user - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `windows_powershell_logoff_user_via_quser_filter`' -how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. +description: The following analytic detects the process of logging off a user through + the use of the quser and logoff commands. By monitoring for these commands, the + analytic identifies actions where a user session is forcibly terminated, which could + be part of an administrative task or a potentially unauthorized access attempt. + This detection helps identify potential misuse or malicious activity where a user’s + access is revoked without proper authorization, providing insight into potential + security incidents involving account management or session manipulation. +search: '`powershell` EventCode=4104 ScriptBlockText = "*quser*logoff*" | stats count + min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText UserID + Computer | rename Computer as dest, UserID as user | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_powershell_logoff_user_via_quser_filter`' +how_to_implement: The following Hunting analytic requires PowerShell operational logs + to be imported. Modify the powershell macro as needed to match the sourcetype or + add index. This analytic is specific to 4104, or PowerShell Script Block Logging. known_false_positives: Administrators or power users may use this command. references: - https://devblogs.microsoft.com/scripting/automating-quser-through-powershell/ @@ -24,11 +30,17 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: Powershell process having commandline [$ScriptBlockText$] used to logoff user on [$dest$]. + message: Powershell process having commandline [$ScriptBlockText$] used to logoff + user on [$dest$]. risk_objects: - field: dest type: system @@ -39,9 +51,8 @@ tags: - Crypto Stealer asset_type: Endpoint mitre_attack_id: - - T1531 - T1059.001 - - T1059 + - T1531 product: - Splunk Enterprise - Splunk Enterprise Security @@ -50,6 +61,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/log_off_user/pwh_quser_logoff.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/log_off_user/pwh_quser_logoff.log source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_powershell_remotesigned_file.yml b/detections/endpoint/windows_powershell_remotesigned_file.yml index 64bd011024..63df593e37 100644 --- a/detections/endpoint/windows_powershell_remotesigned_file.yml +++ b/detections/endpoint/windows_powershell_remotesigned_file.yml @@ -1,7 +1,7 @@ name: Windows Powershell RemoteSigned File id: f7f7456b-470d-4a95-9703-698250645ff4 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_scheduletask.yml b/detections/endpoint/windows_powershell_scheduletask.yml index 2cb840930a..0aaa0d5614 100644 --- a/detections/endpoint/windows_powershell_scheduletask.yml +++ b/detections/endpoint/windows_powershell_scheduletask.yml @@ -1,7 +1,7 @@ name: Windows PowerShell ScheduleTask id: ddf82fcb-e9ee-40e3-8712-a50b5bf323fc -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -65,7 +65,6 @@ tags: mitre_attack_id: - T1053.005 - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml b/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml index 358d2f9f2c..4ec8982c98 100644 --- a/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml +++ b/detections/endpoint/windows_powershell_wmi_win32_scheduledjob.yml @@ -1,7 +1,7 @@ name: Windows PowerShell WMI Win32 ScheduledJob id: 47c69803-2c09-408b-b40a-063c064cbb16 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk type: TTP status: production @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1059.001 - - T1059 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_powersploit_gpp_discovery.yml b/detections/endpoint/windows_powersploit_gpp_discovery.yml index c0bc3bffb3..cdd8803bc9 100644 --- a/detections/endpoint/windows_powersploit_gpp_discovery.yml +++ b/detections/endpoint/windows_powersploit_gpp_discovery.yml @@ -1,7 +1,7 @@ name: Windows PowerSploit GPP Discovery id: 0130a0df-83a1-4647-9011-841e950ff302 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: - Active Directory Privilege Escalation asset_type: Endpoint mitre_attack_id: - - T1552 - T1552.006 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml b/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml index 77bff74777..0fa3ee8fe5 100644 --- a/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml +++ b/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml @@ -1,7 +1,7 @@ name: Windows PowerView Kerberos Service Ticket Request id: 970455a1-4ac2-47e1-a9a5-9e75443ddcb9 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_powerview_spn_discovery.yml b/detections/endpoint/windows_powerview_spn_discovery.yml index a3184c2941..8abe7becab 100644 --- a/detections/endpoint/windows_powerview_spn_discovery.yml +++ b/detections/endpoint/windows_powerview_spn_discovery.yml @@ -1,7 +1,7 @@ name: Windows PowerView SPN Discovery id: a7093c28-796c-4ebb-9997-e2c18b870837 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: - Active Directory Kerberos Attacks asset_type: Endpoint mitre_attack_id: - - T1558 - T1558.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_private_keys_discovery.yml b/detections/endpoint/windows_private_keys_discovery.yml index 27fffec337..74c47622aa 100644 --- a/detections/endpoint/windows_private_keys_discovery.yml +++ b/detections/endpoint/windows_private_keys_discovery.yml @@ -1,7 +1,7 @@ name: Windows Private Keys Discovery id: 5c1c2877-06c0-40ee-a1a2-db71f1372b5b -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -70,7 +70,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1552.004 - - T1552 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml b/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml index 6b4490c90e..c94417e9e5 100644 --- a/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml +++ b/detections/endpoint/windows_privilege_escalation_suspicious_process_elevation.yml @@ -1,6 +1,6 @@ name: Windows Privilege Escalation Suspicious Process Elevation id: 6a80300a-9f8a-4f22-bd3e-09ca577cfdfc -version: 4 +version: 5 date: '2024-11-13' author: Steven Dick status: production diff --git a/detections/endpoint/windows_process_executed_from_removable_media.yml b/detections/endpoint/windows_process_executed_from_removable_media.yml new file mode 100644 index 0000000000..6e3b66300b --- /dev/null +++ b/detections/endpoint/windows_process_executed_from_removable_media.yml @@ -0,0 +1,81 @@ +name: Windows Process Executed From Removable Media +id: b483804a-4cc0-49a4-9f00-ac29ba844d08 +version: 1 +date: '2025-01-17' +author: Steven Dick +status: production +type: Anomaly +description: This analytic is used to identify when a removable media device is attached to a machine and then a process is executed from the same drive letter assigned to the removable media device. Adversaries and Insider Threats may use removable media devices for several malicious activities, including initial access, execution, and exfiltration. +data_source: +- Windows Security Event ID 4688 +- Sysmon Event ID 1 +- Sysmon Event ID 12 +- Sysmon Event ID 13 +- CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_current_directory=* AND NOT Processes.process_current_directory IN ("C:\\*","*\\sysvol\\*") by Processes.dest Processes.user Processes.process_name Processes.parent_process_name Processes.process_current_directory + | `drop_dm_object_name(Processes)` + | rex field=process_current_directory "^(?[^\\\]+\\\)" + | where isnotnull(object_handle) + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | join dest,object_handle + [| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry where Registry.registry_value_data="*:\\*" AND Registry.registry_path="*USBSTOR*" AND Registry.registry_path IN ("HKLM\\SOFTWARE\\Microsoft\\Windows Portable Devices\\Devices\\*","HKLM\\System\\CurrentControlSet\\Enum\\SWD\\WPDBUSENUM\\*") by Registry.dest,Registry.registry_value_data,Registry.registry_path + | `drop_dm_object_name(Registry)` + | eval object_handle = registry_value_data, object_name = replace(mvindex(split(mvindex(split(registry_path, "??"),1),"&"),2),"PROD_","") + ] + | `windows_process_executed_from_removable_media_filter` +how_to_implement: To successfully implement this search, you must ingest endpoint logging that tracks changes to the HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices\ or HKLM\System\CurrentControlSet\Enum\SWD\WPDBUSENUM\ registry keys as well as Process Execution commands. Ensure that the field from the event logs is being mapped to the proper fields in the Endpoint.Registry data model. This analytic joins the Process and Registry datamodels together based on the drive letter extract to the "object_handle" field from both datasets. +known_false_positives: Legitimate USB activity will also be detected. Please verify and investigate as appropriate. +references: +- https://attack.mitre.org/techniques/T1200/ +- https://www.cisa.gov/news-events/news/using-caution-usb-drives +- https://www.bleepingcomputer.com/news/security/fbi-hackers-use-badusb-to-target-defense-firms-with-ransomware/ +drilldown_searches: +- name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" and user= "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$" , "$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate USB events on $dest$ + search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_current_directory=$object_handle$*' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The process [$process_name$] was launched using files on a removable storage device named [$object_name$] by [$user$] on $dest$ + risk_objects: + - field: user + type: user + score: 35 + - field: dest + type: system + score: 35 + threat_objects: + - field: process_name + type: process_name + - field: object_name + type: registry_value_name + - field: object_handle + type: registry_value_text +tags: + analytic_story: + - Data Protection + asset_type: Endpoint + mitre_attack_id: + - T1200 + - T1025 + - T1091 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1200/sysmon_usb_use_execution/sysmon_usb_use_execution.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_process_execution_in_temp_dir.yml b/detections/endpoint/windows_process_execution_in_temp_dir.yml new file mode 100644 index 0000000000..c8909b0013 --- /dev/null +++ b/detections/endpoint/windows_process_execution_in_temp_dir.yml @@ -0,0 +1,87 @@ +name: Windows Process Execution in Temp Dir +id: f6fbe929-4187-4ba4-901e-8a34be838443 +version: 1 +date: '2025-01-27' +author: Teoderick Contreras, Splunk +status: production +type: Anomaly +description: The following analytic identifies processes running from %temp% directory file paths. + It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint + data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges. If confirmed malicious, this behavior could indicate an attempt to bypass security controls, leading to unauthorized software execution, potential system compromise, and further malicious activities within the environment. +data_source: +- Sysmon EventID 1 +- Windows Event Log Security 4688 +- CrowdStrike ProcessRollup2 +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.process_path IN("*\\temp\\*") + by Processes.parent_process_name Processes.parent_process Processes.process_path Processes.dest Processes.user + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_process_execution_in_temp_dir_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: Administrators may allow execution of specific binaries in + non-standard paths. Filter as needed. +references: +- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://twitter.com/pr0xylife/status/1590394227758104576 +- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Suspicious process $process_name$ running from temp directory- + $process_path$ on host- $dest$ + risk_objects: + - field: dest + type: system + score: 30 + threat_objects: + - field: process_path + type: process_name +tags: + analytic_story: + - Ryuk Ransomware + - Trickbot + - Qakbot + - AgentTesla + - Remcos + - NjRAT + - Ransomware + asset_type: Endpoint + mitre_attack_id: + - T1543 + - T1036.005 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/process_temp_path/process_temp_path.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_process_injection_into_notepad.yml b/detections/endpoint/windows_process_injection_into_notepad.yml index 6e1e86e9f8..8a4a772575 100644 --- a/detections/endpoint/windows_process_injection_into_notepad.yml +++ b/detections/endpoint/windows_process_injection_into_notepad.yml @@ -1,7 +1,7 @@ name: Windows Process Injection into Notepad id: b8340d0f-ba48-4391-bea7-9e793c5aae36 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk type: Anomaly status: production @@ -61,7 +61,6 @@ tags: - BishopFox Sliver Adversary Emulation Framework asset_type: Endpoint mitre_attack_id: - - T1055 - T1055.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml b/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml index 7ca8139ceb..4c35239780 100644 --- a/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml +++ b/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml @@ -1,7 +1,7 @@ name: Windows Process Injection Of Wermgr to Known Browser id: aec755a5-3a2c-4be0-ab34-6540e68644e9 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1055.001 - - T1055 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_process_injection_remote_thread.yml b/detections/endpoint/windows_process_injection_remote_thread.yml index acb2c928e0..48d56aec9f 100644 --- a/detections/endpoint/windows_process_injection_remote_thread.yml +++ b/detections/endpoint/windows_process_injection_remote_thread.yml @@ -1,7 +1,7 @@ name: Windows Process Injection Remote Thread id: 8a618ade-ca8f-4d04-b972-2d526ba59924 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - Warzone RAT asset_type: Endpoint mitre_attack_id: - - T1055 - T1055.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_process_injection_with_public_source_path.yml b/detections/endpoint/windows_process_injection_with_public_source_path.yml index 6ff6638edb..3034d4db52 100644 --- a/detections/endpoint/windows_process_injection_with_public_source_path.yml +++ b/detections/endpoint/windows_process_injection_with_public_source_path.yml @@ -1,7 +1,7 @@ name: Windows Process Injection With Public Source Path id: 492f09cf-5d60-4d87-99dd-0bc325532dda -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -33,7 +33,6 @@ tags: - Brute Ratel C4 asset_type: Endpoint mitre_attack_id: - - T1055 - T1055.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml b/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml index 578832eea3..82eb5c76bd 100644 --- a/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml +++ b/detections/endpoint/windows_process_with_netexec_command_line_parameters.yml @@ -1,70 +1,68 @@ -name: Windows Process With NetExec Command Line Parameters -id: adbff89c-c1f2-4a2e-88a4-b5e645856510 -version: 2 -date: '2025-01-09' -author: Steven Dick, Github Community -status: production -type: TTP -description: The following analytic detects the use of NetExec (formally CrackmapExec) a toolset used for post-exploitation enumeration and attack within Active Directory environments through command line parameters. It leverages Endpoint Detection and Response (EDR) data to identify specific command-line arguments associated with actions like ticket manipulation, kerberoasting, and password spraying. This activity is significant as NetExec is used by adversaries to exploit Kerberos for privilege escalation and lateral movement. If confirmed malicious, this could lead to unauthorized access, persistence, and potential compromise of sensitive information within the network. -data_source: -- Windows Security Event ID 4688 -- Sysmon Event ID 1 -- CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` values(Processes.parent_process) as Processes.parent_process, values(Processes.process) as Processes.process values(Processes.process_current_directory) AS process_current_directory, values(Processes.process_id) as Processes.process_id, values(Processes.process_guid) as Processes.process_guid, count min(_time) AS firstTime, max(_time) AS lastTime FROM datamodel=Endpoint.Processes where Processes.process_name IN ("nxc.exe") OR Processes.original_file_name IN ("nxc.exe") OR (Processes.process IN ("* smb *","* ssh *","* ldap *","* ftp *","* wmi *","* winrm *","* rdp *","* vnc *","* mssql *","* nfs *") AND ((Processes.process = "* -p *" AND Processes.process = "* -u *") OR Processes.process IN ("* -x *","* -M *","* --*"))) BY _time span=1h Processes.user Processes.dest Processes.process_name Processes.parent_process_name -|`drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_process_with_netexec_command_line_parameters_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: Although unlikely, legitimate applications may use the same command line parameters as NetExec. Filter as needed. -references: -- https://www.netexec.wiki/ -- https://www.johnvictorwolfe.com/2024/07/21/the-successor-to-crackmapexec/ -- https://attack.mitre.org/software/S0488/ -drilldown_searches: -- name: View the detection results for - "$dest$" and "$user$" - search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -- name: View risk events for the last 7 days for - "$dest$" and "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$","$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -- name: Investigate processes on $dest$ - search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_name = $process_name$' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -rba: - message: NetExec command line parameters were used on $dest$ by $user$ - risk_objects: - - field: user - type: user - score: 64 - - field: dest - type: system - score: 64 - threat_objects: - - field: parent_process_name - type: parent_process_name -tags: - analytic_story: - - Active Directory Kerberos Attacks - - Active Directory Privilege Escalation - asset_type: Endpoint - mitre_attack_id: - - T1550 - - T1550.003 - - T1558 - - T1558.003 - - T1558.004 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - security_domain: endpoint -tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550/netexec_toolkit_usage/netexec_toolkit_usage.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog +name: Windows Process With NetExec Command Line Parameters +id: adbff89c-c1f2-4a2e-88a4-b5e645856510 +version: 3 +date: '2025-02-11' +author: Steven Dick, Github Community +status: production +type: TTP +description: The following analytic detects the use of NetExec (formally CrackmapExec) a toolset used for post-exploitation enumeration and attack within Active Directory environments through command line parameters. It leverages Endpoint Detection and Response (EDR) data to identify specific command-line arguments associated with actions like ticket manipulation, kerberoasting, and password spraying. This activity is significant as NetExec is used by adversaries to exploit Kerberos for privilege escalation and lateral movement. If confirmed malicious, this could lead to unauthorized access, persistence, and potential compromise of sensitive information within the network. +data_source: +- Windows Security Event ID 4688 +- Sysmon EventID 1 +- CrowdStrike ProcessRollup2 +search: '| tstats `security_content_summariesonly` values(Processes.parent_process) as Processes.parent_process, values(Processes.process) as Processes.process values(Processes.process_current_directory) AS process_current_directory, values(Processes.process_id) as Processes.process_id, values(Processes.process_guid) as Processes.process_guid, count min(_time) AS firstTime, max(_time) AS lastTime FROM datamodel=Endpoint.Processes where Processes.process_name IN ("nxc.exe") OR Processes.original_file_name IN ("nxc.exe") OR (Processes.process IN ("* smb *","* ssh *","* ldap *","* ftp *","* wmi *","* winrm *","* rdp *","* vnc *","* mssql *","* nfs *") AND ((Processes.process = "* -p *" AND Processes.process = "* -u *") OR Processes.process IN ("* -x *","* -M *","* --*"))) BY _time span=1h Processes.user Processes.dest Processes.process_name Processes.parent_process_name +|`drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `windows_process_with_netexec_command_line_parameters_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +known_false_positives: Although unlikely, legitimate applications may use the same command line parameters as NetExec. Filter as needed. +references: +- https://www.netexec.wiki/ +- https://www.johnvictorwolfe.com/2024/07/21/the-successor-to-crackmapexec/ +- https://attack.mitre.org/software/S0488/ +drilldown_searches: +- name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$","$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate processes on $dest$ + search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_name = $process_name$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: NetExec command line parameters were used on $dest$ by $user$ + risk_objects: + - field: user + type: user + score: 64 + - field: dest + type: system + score: 64 + threat_objects: + - field: parent_process_name + type: parent_process_name +tags: + analytic_story: + - Active Directory Kerberos Attacks + - Active Directory Privilege Escalation + asset_type: Endpoint + mitre_attack_id: + - T1550.003 + - T1558.003 + - T1558.004 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550/netexec_toolkit_usage/netexec_toolkit_usage.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_protocol_tunneling_with_plink.yml b/detections/endpoint/windows_protocol_tunneling_with_plink.yml index 3a6481da48..b55caf7791 100644 --- a/detections/endpoint/windows_protocol_tunneling_with_plink.yml +++ b/detections/endpoint/windows_protocol_tunneling_with_plink.yml @@ -1,6 +1,6 @@ name: Windows Protocol Tunneling with Plink id: 8aac5e1e-0fab-4437-af0b-c6e60af23eed -version: 6 +version: 7 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_proxy_via_netsh.yml b/detections/endpoint/windows_proxy_via_netsh.yml index 66dcbfa6da..639a557efe 100644 --- a/detections/endpoint/windows_proxy_via_netsh.yml +++ b/detections/endpoint/windows_proxy_via_netsh.yml @@ -1,7 +1,7 @@ name: Windows Proxy Via Netsh id: c137bfe8-6036-4cff-b77b-4e327dd0a1cf -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -71,7 +71,6 @@ tags: - b8223ea9-4be2-44a6-b50a-9657a3d4e72a mitre_attack_id: - T1090.001 - - T1090 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_proxy_via_registry.yml b/detections/endpoint/windows_proxy_via_registry.yml index df29fba982..ab99e0cb4e 100644 --- a/detections/endpoint/windows_proxy_via_registry.yml +++ b/detections/endpoint/windows_proxy_via_registry.yml @@ -1,7 +1,7 @@ name: Windows Proxy Via Registry id: 0270455b-1385-4579-9ac5-e77046c508ae -version: 5 -date: '2024-12-16' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: - b8223ea9-4be2-44a6-b50a-9657a3d4e72a mitre_attack_id: - T1090.001 - - T1090 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml index 4c61efa0c7..9e419ace18 100644 --- a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml +++ b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml @@ -1,6 +1,6 @@ name: Windows Raccine Scheduled Task Deletion id: c9f010da-57ab-11ec-82bd-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_rasautou_dll_execution.yml b/detections/endpoint/windows_rasautou_dll_execution.yml index f04f743ef0..8e15a67174 100644 --- a/detections/endpoint/windows_rasautou_dll_execution.yml +++ b/detections/endpoint/windows_rasautou_dll_execution.yml @@ -1,7 +1,7 @@ name: Windows Rasautou DLL Execution id: 6f42b8be-8e96-11ec-ad5a-acde48001122 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: mitre_attack_id: - T1055.001 - T1218 - - T1055 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml index d6193ca528..b12079e3c2 100644 --- a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml +++ b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml @@ -1,7 +1,7 @@ name: Windows Raw Access To Disk Volume Partition id: a85aa37e-9647-11ec-90c5-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -23,8 +23,9 @@ how_to_implement: To successfully implement this search, you need to be ingestin logs with the raw access read event (like sysmon eventcode 9), process name and process guid from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -known_false_positives: There are som minimal number of normal applications from system32 folder like svchost.exe accessing the MBR. In this - case we used 'system32' and 'syswow64' path as a filter for this detection. +known_false_positives: There are som minimal number of normal applications from system32 + folder like svchost.exe accessing the MBR. In this case we used 'system32' and 'syswow64' + path as a filter for this detection. references: - https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html drilldown_searches: @@ -60,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1561.002 - - T1561 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml index 3692033d81..a689fa523f 100644 --- a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml +++ b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml @@ -1,7 +1,7 @@ name: Windows Raw Access To Master Boot Record Drive id: 7b83f666-900c-11ec-a2d9-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -23,8 +23,9 @@ how_to_implement: To successfully implement this search, you need to be ingestin logs with the raw access read event (like sysmon eventcode 9), process name and process guid from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -known_false_positives: There are som minimal number of normal applications from system32 folder like svchost.exe accessing the MBR. In this - case we used 'system32' and 'syswow64' path as a filter for this detection. +known_false_positives: There are som minimal number of normal applications from system32 + folder like svchost.exe accessing the MBR. In this case we used 'system32' and 'syswow64' + path as a filter for this detection. references: - https://www.splunk.com/en_us/blog/security/threat-advisory-strt-ta02-destructive-software.html - https://www.crowdstrike.com/blog/technical-analysis-of-whispergate-malware/ @@ -63,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1561.002 - - T1561 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_registry_certificate_added.yml b/detections/endpoint/windows_registry_certificate_added.yml index 2781d73827..f8c97ce6b7 100644 --- a/detections/endpoint/windows_registry_certificate_added.yml +++ b/detections/endpoint/windows_registry_certificate_added.yml @@ -1,7 +1,7 @@ name: Windows Registry Certificate Added id: 5ee98b2f-8b9e-457a-8bdc-dd41aaba9e87 -version: 6 -date: '2025-01-21' +version: 7 +date: '2025-02-10' author: Michael Haag, Teodeerick Contreras, Splunk status: production type: Anomaly @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1553.004 - - T1553 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml b/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml index d938db4eac..5e2ddf9fce 100644 --- a/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml +++ b/detections/endpoint/windows_registry_dotnet_etw_disabled_via_env_variable.yml @@ -1,7 +1,7 @@ name: Windows Registry Dotnet ETW Disabled Via ENV Variable id: 55502381-5cce-491b-9277-7cb1d10bc0df -version: 2 -date: '2025-01-07' +version: 4 +date: '2025-02-10' author: Nasreddine Bencherchali, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.006 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml b/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml index fbd1a12913..7a88c95d54 100644 --- a/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml +++ b/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml @@ -1,7 +1,7 @@ name: Windows Registry Modification for Safe Mode Persistence id: c6149154-c9d8-11eb-9da7-acde48001122 -version: 8 -date: '2025-01-21' +version: 9 +date: '2025-02-10' author: Teoderick Contreras, Michael Haag, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.001 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_registry_payload_injection.yml b/detections/endpoint/windows_registry_payload_injection.yml index 9a2dcd0047..e798fc114f 100644 --- a/detections/endpoint/windows_registry_payload_injection.yml +++ b/detections/endpoint/windows_registry_payload_injection.yml @@ -1,7 +1,7 @@ name: Windows Registry Payload Injection id: c6b2d80f-179a-41a1-b95e-ce5601d7427a -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -77,7 +77,6 @@ tags: - Unusual Processes asset_type: Endpoint mitre_attack_id: - - T1027 - T1027.011 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_regsvr32_renamed_binary.yml b/detections/endpoint/windows_regsvr32_renamed_binary.yml index 64e9e406e3..53b64d87dd 100644 --- a/detections/endpoint/windows_regsvr32_renamed_binary.yml +++ b/detections/endpoint/windows_regsvr32_renamed_binary.yml @@ -1,7 +1,7 @@ name: Windows Regsvr32 Renamed Binary id: 7349a9e9-3cf6-4171-bb0c-75607a8dcd1a -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.010 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_remote_assistance_spawning_process.yml b/detections/endpoint/windows_remote_assistance_spawning_process.yml index 90cb689064..e6810e6c34 100644 --- a/detections/endpoint/windows_remote_assistance_spawning_process.yml +++ b/detections/endpoint/windows_remote_assistance_spawning_process.yml @@ -1,6 +1,6 @@ name: Windows Remote Assistance Spawning Process id: ced50492-8849-11ec-9f68-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_remote_create_service.yml b/detections/endpoint/windows_remote_create_service.yml index 93c28d5380..ffa6ead077 100644 --- a/detections/endpoint/windows_remote_create_service.yml +++ b/detections/endpoint/windows_remote_create_service.yml @@ -1,7 +1,7 @@ name: Windows Remote Create Service id: 0dc44d03-8c00-482d-ba7c-796ba7ab18c9 -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -72,7 +72,6 @@ tags: - BlackSuit Ransomware asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml b/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml index 73d240c71e..780c0b7854 100644 --- a/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml +++ b/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml @@ -1,7 +1,7 @@ name: Windows Remote Service Rdpwinst Tool Execution id: c8127f87-c7c9-4036-89ed-8fe4b30e678c -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml b/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml index 01e73f560f..52c5aed5a0 100644 --- a/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml +++ b/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml @@ -1,7 +1,7 @@ name: Windows Remote Services Allow Rdp In Firewall id: 9170cb54-ea15-41e1-9dfc-9f3363ce9b02 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -66,7 +66,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_remote_services_allow_remote_assistance.yml b/detections/endpoint/windows_remote_services_allow_remote_assistance.yml index 39dfcd8333..4f5028aa36 100644 --- a/detections/endpoint/windows_remote_services_allow_remote_assistance.yml +++ b/detections/endpoint/windows_remote_services_allow_remote_assistance.yml @@ -1,7 +1,7 @@ name: Windows Remote Services Allow Remote Assistance id: 9bce3a97-bc97-4e89-a1aa-ead151c82fbb -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_remote_services_rdp_enable.yml b/detections/endpoint/windows_remote_services_rdp_enable.yml index db44d18d43..16dc4dcfb1 100644 --- a/detections/endpoint/windows_remote_services_rdp_enable.yml +++ b/detections/endpoint/windows_remote_services_rdp_enable.yml @@ -1,7 +1,7 @@ name: Windows Remote Services Rdp Enable id: 8fbd2e88-4ea5-40b9-9217-fd0855e08cc0 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_root_domain_linked_policies_discovery.yml b/detections/endpoint/windows_root_domain_linked_policies_discovery.yml index f006024e2d..b4b40d775a 100644 --- a/detections/endpoint/windows_root_domain_linked_policies_discovery.yml +++ b/detections/endpoint/windows_root_domain_linked_policies_discovery.yml @@ -1,7 +1,7 @@ name: Windows Root Domain linked policies Discovery id: 80ffaede-1f12-49d5-a86e-b4b599b68b3c -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1087.002 - - T1087 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml b/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml index 711d2c152e..f1c867ecd3 100644 --- a/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml +++ b/detections/endpoint/windows_rundll32_apply_user_settings_changes.yml @@ -1,7 +1,7 @@ name: Windows Rundll32 Apply User Settings Changes id: b9fb8d97-dbc9-4a09-804c-ff0e3862bb2d -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -64,7 +64,6 @@ tags: - Rhysida Ransomware asset_type: Endpoint mitre_attack_id: - - T1218 - T1218.011 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_rundll32_webdav_request.yml b/detections/endpoint/windows_rundll32_webdav_request.yml index ce111cff26..68ccb04ab4 100644 --- a/detections/endpoint/windows_rundll32_webdav_request.yml +++ b/detections/endpoint/windows_rundll32_webdav_request.yml @@ -1,6 +1,6 @@ name: Windows Rundll32 WebDAV Request id: 320099b7-7eb1-4153-a2b4-decb53267de2 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk type: TTP diff --git a/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml b/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml index de78c6f02b..8ef7992823 100644 --- a/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml +++ b/detections/endpoint/windows_rundll32_webdav_with_network_connection.yml @@ -1,6 +1,6 @@ name: Windows Rundll32 WebDav With Network Connection id: f03355e0-28b5-4e9b-815a-6adffc63b38c -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk type: TTP diff --git a/detections/endpoint/windows_scheduled_task_created_via_xml.yml b/detections/endpoint/windows_scheduled_task_created_via_xml.yml index b29963f952..0a239e80fc 100644 --- a/detections/endpoint/windows_scheduled_task_created_via_xml.yml +++ b/detections/endpoint/windows_scheduled_task_created_via_xml.yml @@ -1,7 +1,7 @@ name: Windows Scheduled Task Created Via XML id: 7e03b682-3965-4598-8e91-a60a40a3f7e4 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml b/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml index 2111e93ad4..0cb70faff7 100644 --- a/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml +++ b/detections/endpoint/windows_scheduled_task_with_highest_privileges.yml @@ -1,7 +1,7 @@ name: Windows Scheduled Task with Highest Privileges id: 2f15e1a4-0fc2-49dd-919e-cbbe60699218 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: - RedLine Stealer asset_type: Endpoint mitre_attack_id: - - T1053 - T1053.005 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_schtasks_create_run_as_system.yml b/detections/endpoint/windows_schtasks_create_run_as_system.yml index 0803309dab..bb349b102f 100644 --- a/detections/endpoint/windows_schtasks_create_run_as_system.yml +++ b/detections/endpoint/windows_schtasks_create_run_as_system.yml @@ -1,7 +1,7 @@ name: Windows Schtasks Create Run As System id: 41a0e58e-884c-11ec-9976-acde48001122 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -71,7 +71,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_security_and_backup_services_stop.yml b/detections/endpoint/windows_security_and_backup_services_stop.yml new file mode 100644 index 0000000000..47e8f2e8cf --- /dev/null +++ b/detections/endpoint/windows_security_and_backup_services_stop.yml @@ -0,0 +1,78 @@ +name: Windows Security And Backup Services Stop +id: 9c24aef6-cad9-4931-acce-74318aa5663b +version: 1 +date: '2025-02-07' +author: Teoderick Contreras, Splunk +status: production +type: TTP +description: The following analytic detects the suspicious termination of known services + commonly targeted by ransomware before file encryption. It leverages Windows System + Event Logs (EventCode 7036) to identify when critical services such as Volume Shadow + Copy, backup, and antivirus services are stopped. This activity is significant because + ransomware often disables these services to avoid errors and ensure successful file + encryption. If confirmed malicious, this behavior could lead to widespread data + encryption, rendering files inaccessible and potentially causing significant operational + disruption and data loss. +data_source: +- Windows Event Log System 7036 +search: '`wineventlog_system` `normalized_service_binary_field` + | rename param1 as display_name + | where param2="stopped" AND (match(display_name, "(?i)(Volume Shadow Copy|VSS|backup|sophos|sql|memtas|mepocs|veeam|svc\$|DefWatch|ccEvtMgr|ccSetMgr|SavRoam|RTVscan|QBFCService|QBIDPService|Intuit\.QuickBooks\.FCS|QBCFMonitorService|YooBackup|YooIT|Veeam|PDVFSService|BackupExec|WdBoot|WdFilter|WdNisDrv|WdNisSvc|WinDefend|wscsvc|Sense|sppsvc|SecurityHealthService)") + OR match(normalized_service_name, "(?i)(Volume Shadow Copy|VSS|backup|sophos|sql|memtas|mepocs|veeam|svc\$|DefWatch|ccEvtMgr|ccSetMgr|SavRoam|RTVscan|QBFCService|QBIDPService|Intuit\.QuickBooks\.FCS|QBCFMonitorService|YooBackup|YooIT|Veeam|PDVFSService|BackupExec|WdBoot|WdFilter|WdNisDrv|WdNisSvc|WinDefend|wscsvc|Sense|sppsvc|SecurityHealthService)")) + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode display_name dest normalized_service_name + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_security_and_backup_services_stop_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the 7036 EventCode ScManager in System audit Logs from your endpoints. +known_false_positives: Admin activities or installing related updates may do a sudden + stop to list of services we monitor. +references: +- https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/ +- https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/ +- https://news.sophos.com/en-us/2020/04/24/lockbit-ransomware-borrows-tricks-to-keep-up-with-revil-and-maze/ +- https://blogs.vmware.com/security/2022/10/lockbit-3-0-also-known-as-lockbit-black.html +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Known services $param1$ terminated by a potential ransomware on $dest$ + risk_objects: + - field: dest + type: system + score: 72 + threat_objects: + - field: display_name + type: service +tags: + analytic_story: + - LockBit Ransomware + - Ransomware + - Compromised Windows Host + - BlackMatter Ransomware + asset_type: Endpoint + mitre_attack_id: + - T1490 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/known_services_killed_by_ransomware/windows-xml.log + source: XmlWinEventLog:System + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_security_support_provider_reg_query.yml b/detections/endpoint/windows_security_support_provider_reg_query.yml index 1ec47ad04d..78ab163dc2 100644 --- a/detections/endpoint/windows_security_support_provider_reg_query.yml +++ b/detections/endpoint/windows_security_support_provider_reg_query.yml @@ -1,7 +1,7 @@ name: Windows Security Support Provider Reg Query id: 31302468-93c9-4eca-9ae3-2d41f53a4e2b -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -69,7 +69,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1547.005 - - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_sensitive_group_discovery_with_net.yml b/detections/endpoint/windows_sensitive_group_discovery_with_net.yml index 6a7c924fe9..57b7d6e524 100644 --- a/detections/endpoint/windows_sensitive_group_discovery_with_net.yml +++ b/detections/endpoint/windows_sensitive_group_discovery_with_net.yml @@ -1,17 +1,39 @@ name: Windows Sensitive Group Discovery With Net id: d9eb7cda-5622-4722-bc88-7f2442f4b5af -version: 1 -date: '2025-01-13' +version: 2 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: Anomaly -description: The following analytic detects the execution of `net.exe` with command-line arguments used to query elevated domain or sensitive groups. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as it indicates potential reconnaissance efforts by adversaries to identify high-privileged users within Active Directory. If confirmed malicious, this behavior could lead to further attacks aimed at compromising privileged accounts, escalating privileges, or gaining unauthorized access to sensitive systems and data. +description: The following analytic detects the execution of `net.exe` with command-line + arguments used to query elevated domain or sensitive groups. It leverages data from + Endpoint Detection and Response (EDR) agents, focusing on process names and command-line + executions. This activity is significant as it indicates potential reconnaissance + efforts by adversaries to identify high-privileged users within Active Directory. + If confirmed malicious, this behavior could lead to further attacks aimed at compromising + privileged accounts, escalating privileges, or gaining unauthorized access to sensitive + systems and data. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*" Processes.process IN ("*Domain Admins*", "*Enterprise Admins*", "*Schema Admins*", "*Account Operators*", "*Server Operators*", "*Protected Users*", "*Dns Admins*", "*Domain Computers*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_sensitive_group_discovery_with_net_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_net` Processes.process="*group*" + Processes.process IN ("*Domain Admins*", "*Enterprise Admins*", "*Schema Admins*", + "*Account Operators*", "*Server Operators*", "*Protected Users*", "*Dns Admins*", + "*Domain Computers*") by Processes.dest Processes.user Processes.parent_process + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `windows_sensitive_group_discovery_with_net_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: Administrators or power users may use this command for troubleshooting. references: - https://attack.mitre.org/techniques/T1069/002/ @@ -25,7 +47,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -44,7 +71,6 @@ tags: - IcedID asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.002 product: - Splunk Enterprise @@ -54,6 +80,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml b/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml index d8050741e3..fba9efd879 100644 --- a/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml +++ b/detections/endpoint/windows_sensitive_registry_hive_dump_via_commandline.yml @@ -1,18 +1,41 @@ name: Windows Sensitive Registry Hive Dump Via CommandLine id: 5aaff29d-0cce-405b-9ee8-5d06b49d045e -version: 1 -date: '2025-01-15' +version: 3 +date: '2025-02-10' author: Michael Haag, Patrick Bareiss, Nasreddine Bencherchali, Splunk status: production type: TTP -description: The following analytic detects the use of `reg.exe` to export Windows Registry hives, which may contain sensitive credentials. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving `save` or `export` actions targeting the `sam`, `system`, or `security` hives. This activity is significant as it indicates potential offline credential access attacks, often executed from untrusted processes or scripts. If confirmed malicious, attackers could gain access to credential data, enabling further compromise and lateral movement within the network. +description: The following analytic detects the use of `reg.exe` to export Windows + Registry hives, which may contain sensitive credentials. This detection leverages + data from Endpoint Detection and Response (EDR) agents, focusing on command-line + executions involving `save` or `export` actions targeting the `sam`, `system`, or + `security` hives. This activity is significant as it indicates potential offline + credential access attacks, often executed from untrusted processes or scripts. If + confirmed malicious, attackers could gain access to credential data, enabling further + compromise and lateral movement within the network. data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where ((`process_reg` Processes.process IN ("*save*", "*export*")) OR (`process_regedit` Processes.process IN ("*/E *", "*-E *"))) AND Processes.process IN ("*HKEY_LOCAL_MACHINE*", "*HKLM*") AND Processes.process IN ("*SAM*", "*System*", "*Security*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.parent_process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_sensitive_registry_hive_dump_via_commandline_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: It is possible some agent based products will generate false positives. Filter as needed. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where ((`process_reg` Processes.process + IN ("*save*", "*export*")) OR (`process_regedit` Processes.process IN ("*/E *", + "*-E *"))) AND Processes.process IN ("*HKEY_LOCAL_MACHINE*", "*HKLM*") AND Processes.process + IN ("*SAM*", "*System*", "*Security*") by Processes.dest Processes.user Processes.parent_process + Processes.process_name Processes.parent_process_name Processes.process Processes.process_id + Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_sensitive_registry_hive_dump_via_commandline_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: It is possible some agent based products will generate false + positives. Filter as needed. references: - https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md @@ -23,7 +46,12 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$user$" and "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: @@ -53,7 +81,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1003.002 - - T1003 product: - Splunk Enterprise - Splunk Enterprise Security @@ -62,6 +89,7 @@ tags: tests: - name: True Positive Test - Sysmon attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml b/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml index 64c9bcdd4f..f0baa10770 100644 --- a/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml +++ b/detections/endpoint/windows_server_software_component_gacutil_install_to_gac.yml @@ -1,7 +1,7 @@ name: Windows Server Software Component GACUtil Install to GAC id: 7c025ef0-9e65-4c57-be39-1c13dbb1613e -version: 5 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: - IIS Components asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.004 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_service_create_kernel_mode_driver.yml b/detections/endpoint/windows_service_create_kernel_mode_driver.yml index a183f4a0d9..b9a59dae84 100644 --- a/detections/endpoint/windows_service_create_kernel_mode_driver.yml +++ b/detections/endpoint/windows_service_create_kernel_mode_driver.yml @@ -1,7 +1,7 @@ name: Windows Service Create Kernel Mode Driver id: 0b4e3b06-1b2b-4885-b752-cf06d12a90cb -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,9 +67,8 @@ tags: - CISA AA22-320A asset_type: Endpoint mitre_attack_id: - - T1543.003 - - T1543 - T1068 + - T1543.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_service_create_remcomsvc.yml b/detections/endpoint/windows_service_create_remcomsvc.yml index 23e3442fbb..642022aaff 100644 --- a/detections/endpoint/windows_service_create_remcomsvc.yml +++ b/detections/endpoint/windows_service_create_remcomsvc.yml @@ -1,7 +1,7 @@ name: Windows Service Create RemComSvc id: 0be4b5d6-c449-4084-b945-2392b519c33b -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk type: Anomaly status: production @@ -53,7 +53,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.003 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_service_create_sliverc2.yml b/detections/endpoint/windows_service_create_sliverc2.yml index 43a0ccd75b..d9279cedf9 100644 --- a/detections/endpoint/windows_service_create_sliverc2.yml +++ b/detections/endpoint/windows_service_create_sliverc2.yml @@ -1,7 +1,7 @@ name: Windows Service Create SliverC2 id: 89dad3ee-57ec-43dc-9044-131c4edd663f -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk type: TTP status: production @@ -53,7 +53,6 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_service_create_with_tscon.yml b/detections/endpoint/windows_service_create_with_tscon.yml index 150f198cc2..747300e74b 100644 --- a/detections/endpoint/windows_service_create_with_tscon.yml +++ b/detections/endpoint/windows_service_create_with_tscon.yml @@ -1,7 +1,7 @@ name: Windows Service Create with Tscon id: c13b3d74-6b63-4db5-a841-4206f0370077 -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk type: TTP status: production @@ -81,9 +81,8 @@ tags: - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - - T1563.002 - - T1563 - T1543.003 + - T1563.002 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_service_created_with_suspicious_service_path.yml b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml index 9dfedd34e8..d87ac0bdb8 100644 --- a/detections/endpoint/windows_service_created_with_suspicious_service_path.yml +++ b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml @@ -1,7 +1,7 @@ name: Windows Service Created with Suspicious Service Path id: 429141be-8311-11eb-adb6-acde48001122 -version: 11 -date: '2025-01-27' +version: 12 +date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: - Earth Estries asset_type: Endpoint mitre_attack_id: - - T1569 - T1569.002 product: - Splunk Enterprise @@ -78,6 +77,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/windows_service_created_with_suspicious_service_path/windows-xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/windows_service_created_with_suspicious_service_path/windows-xml.log source: XmlWinEventLog:System sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_service_created_within_public_path.yml b/detections/endpoint/windows_service_created_within_public_path.yml index 6ff175c139..393b3eb567 100644 --- a/detections/endpoint/windows_service_created_within_public_path.yml +++ b/detections/endpoint/windows_service_created_within_public_path.yml @@ -1,7 +1,7 @@ name: Windows Service Created Within Public Path id: 3abb2eda-4bb8-11ec-9ae4-3e22fbd008af -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -57,7 +57,6 @@ tags: - Snake Malware asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml index 19ea16bb63..ec3397951e 100644 --- a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml +++ b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml @@ -1,7 +1,7 @@ name: Windows Service Creation on Remote Endpoint id: e0eea4fa-4274-11ec-882b-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -66,7 +66,6 @@ tags: - CISA AA23-347A asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_service_execution_remcom.yml b/detections/endpoint/windows_service_execution_remcom.yml index 01840501c6..43198428c0 100644 --- a/detections/endpoint/windows_service_execution_remcom.yml +++ b/detections/endpoint/windows_service_execution_remcom.yml @@ -1,6 +1,6 @@ name: Windows Service Execution RemCom id: 7e3d68db-ea4d-419b-adbd-e14a525ecf09 -version: 2 +version: 3 date: '2025-01-07' author: Michael Haag, Splunk type: TTP diff --git a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml index 2a3c2b3981..0c2963cf1d 100644 --- a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml +++ b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml @@ -1,7 +1,7 @@ name: Windows Service Initiation on Remote Endpoint id: 3f519894-4276-11ec-ab02-3e22fbd008af -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -63,7 +63,6 @@ tags: - CISA AA23-347A asset_type: Endpoint mitre_attack_id: - - T1543 - T1543.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_soaphound_binary_execution.yml b/detections/endpoint/windows_soaphound_binary_execution.yml index cfe3f8ce09..0629cd8492 100644 --- a/detections/endpoint/windows_soaphound_binary_execution.yml +++ b/detections/endpoint/windows_soaphound_binary_execution.yml @@ -1,7 +1,7 @@ name: Windows SOAPHound Binary Execution id: 8e53f839-e127-4d6d-a54d-a2f67044a57f -version: 6 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -70,13 +70,11 @@ tags: asset_type: Endpoint atomic_guid: [] mitre_attack_id: - - T1087.002 - T1069.001 - - T1482 - - T1087.001 - - T1087 - T1069.002 - - T1069 + - T1087.001 + - T1087.002 + - T1482 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml b/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml index 9da99670ce..b59cd135c2 100644 --- a/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml +++ b/detections/endpoint/windows_spearphishing_attachment_connect_to_none_ms_office_domain.yml @@ -1,7 +1,7 @@ name: Windows Spearphishing Attachment Connect To None MS Office Domain id: 1cb40e15-cffa-45cc-abbd-e35884a49766 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -36,7 +36,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml b/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml index c11e520d5a..52b946ec39 100644 --- a/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml +++ b/detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml @@ -1,7 +1,7 @@ name: Windows Spearphishing Attachment Onenote Spawn Mshta id: 35aeb0e7-7de5-444a-ac45-24d6788796ec -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -68,7 +68,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1566.001 - - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_sql_spawning_certutil.yml b/detections/endpoint/windows_sql_spawning_certutil.yml index f2e58cc866..d612a17e7e 100644 --- a/detections/endpoint/windows_sql_spawning_certutil.yml +++ b/detections/endpoint/windows_sql_spawning_certutil.yml @@ -1,6 +1,6 @@ name: Windows SQL Spawning CertUtil id: dfc18a5a-946e-44ee-a373-c0f60d06e676 -version: 6 +version: 7 date: '2024-12-16' author: Michael Haag, Splunk status: experimental diff --git a/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml b/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml index f62cbf81c9..10ca564046 100644 --- a/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml +++ b/detections/endpoint/windows_steal_authentication_certificates___esc1_abuse.yml @@ -1,6 +1,6 @@ name: Windows Steal Authentication Certificates - ESC1 Abuse id: cbe761fc-d945-4c8c-a71d-e26d12255d32 -version: 5 +version: 6 date: '2024-11-13' author: Steven Dick status: production diff --git a/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml b/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml index 725f04e04e..5fcaaba267 100644 --- a/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml +++ b/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml @@ -1,6 +1,6 @@ name: Windows Steal Authentication Certificates - ESC1 Authentication id: f0306acf-a6ab-437a-bbc6-8628f8d5c97e -version: 5 +version: 6 date: '2024-12-10' author: Steven Dick status: production diff --git a/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml b/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml index bf954e1d52..9e7ceb2759 100644 --- a/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml +++ b/detections/endpoint/windows_steal_authentication_certificates_certutil_backup.yml @@ -1,6 +1,6 @@ name: Windows Steal Authentication Certificates CertUtil Backup id: bac85b56-0b65-4ce5-aad5-d94880df0967 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml b/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml index d1a5eb3d7b..af44db774c 100644 --- a/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml +++ b/detections/endpoint/windows_steal_authentication_certificates_export_certificate.yml @@ -1,6 +1,6 @@ name: Windows Steal Authentication Certificates Export Certificate id: e39dc429-c2a5-4f1f-9c3c-6b211af6b332 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml b/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml index 459417802e..2e01886698 100644 --- a/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml +++ b/detections/endpoint/windows_steal_authentication_certificates_export_pfxcertificate.yml @@ -1,6 +1,6 @@ name: Windows Steal Authentication Certificates Export PfxCertificate id: 391329f3-c14b-4b8d-8b37-ac5012637360 -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml b/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml index 3b28765cce..b418e2f4d2 100644 --- a/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml +++ b/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml @@ -1,7 +1,7 @@ name: Windows Suspect Process With Authentication Traffic id: 953322db-128a-4ce9-8e89-56e039e33d98 -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -66,9 +66,7 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.002 - - T1204 - T1204.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml b/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml index 57257bec13..00bfe7a17b 100644 --- a/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml +++ b/detections/endpoint/windows_suspicious_child_process_spawned_from_webserver.yml @@ -1,7 +1,7 @@ name: Windows Suspicious Child Process Spawned From WebServer id: 2d4470ef-7158-4b47-b68b-1f7f16382156 -version: 1 -date: '2025-01-13' +version: 2 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -87,7 +87,6 @@ tags: - BlackByte Ransomware asset_type: Endpoint mitre_attack_id: - - T1505 - T1505.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_suspicious_driver_loaded_path.yml b/detections/endpoint/windows_suspicious_driver_loaded_path.yml new file mode 100644 index 0000000000..60383739c7 --- /dev/null +++ b/detections/endpoint/windows_suspicious_driver_loaded_path.yml @@ -0,0 +1,75 @@ +name: Windows Suspicious Driver Loaded Path +id: 2ca1c4a1-8342-4750-9363-905650e0c933 +version: 1 +date: '2025-02-03' +author: Teoderick Contreras, Splunk +status: production +type: TTP +description: The following analytic detects the loading of drivers from suspicious + paths, which is a technique often used by malicious software such as coin miners + (e.g., xmrig). It leverages Sysmon EventCode 6 to identify drivers loaded from non-standard + directories. This activity is significant because legitimate drivers typically reside + in specific system directories, and deviations may indicate malicious activity. + If confirmed malicious, this could allow an attacker to execute code at the kernel + level, potentially leading to privilege escalation, persistence, or further system + compromise. +data_source: +- Sysmon EventID 6 +search: '`sysmon` EventCode=6 ImageLoaded = "*.sys" NOT (ImageLoaded IN("*\\WINDOWS\\inf","*\\WINDOWS\\System32\\drivers\\*", + "*\\WINDOWS\\System32\\DriverStore\\FileRepository\\*","*:\Windows\\WinSxS\\*","*\\ProgramData\\Microsoft\\Windows Defender\\Definition Updates\\*")) | stats min(_time) as + firstTime max(_time) as lastTime count by dest ImageLoaded Hashes IMPHASH Signature + Signed| rename ImageLoaded as file_name | `security_content_ctime(firstTime)` | + `security_content_ctime(lastTime)` | `windows_suspicious_driver_loaded_path_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the driver loaded and Signature from your endpoints. If you are using + Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +known_false_positives: Limited false positives will be present. Some applications + do load drivers +references: +- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ +- https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Suspicious driver $file_name$ on $dest$ + risk_objects: + - field: dest + type: system + score: 60 + threat_objects: + - field: file_name + type: file_name +tags: + analytic_story: + - XMRig + - CISA AA22-320A + - AgentTesla + - BlackByte Ransomware + - Snake Keylogger + asset_type: Endpoint + mitre_attack_id: + - T1543.003 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_suspicious_process_file_path.yml b/detections/endpoint/windows_suspicious_process_file_path.yml new file mode 100644 index 0000000000..0675251a94 --- /dev/null +++ b/detections/endpoint/windows_suspicious_process_file_path.yml @@ -0,0 +1,121 @@ +name: Windows Suspicious Process File Path +id: ecddae4e-3d4b-41e2-b3df-e46a88b38521 +version: 7 +date: '2025-02-10' +author: Teoderick Contreras, Splunk +status: production +type: TTP +description: The following analytic identifies processes running from file paths not + typically associated with legitimate software. It leverages data from Endpoint Detection + and Response (EDR) agents, focusing on specific process paths within the Endpoint + data model. This activity is significant because adversaries often use unconventional + file paths to execute malicious code without requiring administrative privileges. + If confirmed malicious, this behavior could indicate an attempt to bypass security + controls, leading to unauthorized software execution, potential system compromise, + and further malicious activities within the environment. +data_source: +- Sysmon EventID 1 +- Windows Event Log Security 4688 +- CrowdStrike ProcessRollup2 +search: '| tstats `security_content_summariesonly` count values(Processes.process_name) + as process_name values(Processes.process) as process min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes + where Processes.process_path IN("*\\windows\\fonts\\*", "*\\users\\public\\*", "*\\windows\\debug\\*", "*\\Users\\Administrator\\Music\\*", "*Recycle.bin*", "*\\Windows\\Media\\*","\\Windows\\repair\\*", "*\\PerfLogs\\*", "*:\\Windows\\Prefetch\\*", "*:\\Windows\\Cursors\\*", "*:\\Windows\\INF\\*") AND NOT(Processes.process_path IN ("*\\temp\\*")) + by Processes.parent_process_name Processes.parent_process Processes.process_path Processes.dest Processes.user + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_suspicious_process_file_path_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: Administrators may allow execution of specific binaries in + non-standard paths. Filter as needed. +references: +- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://twitter.com/pr0xylife/status/1590394227758104576 +- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") + starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime + values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) + as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) + as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Suspicious process $process_name$ running from a suspicious process path- + $process_path$ on host- $dest$ + risk_objects: + - field: dest + type: system + score: 60 + threat_objects: + - field: process_path + type: process_name +tags: + analytic_story: + - Double Zero Destructor + - Graceful Wipe Out Attack + - AsyncRAT + - WhisperGate + - Prestige Ransomware + - DarkGate Malware + - AgentTesla + - Brute Ratel C4 + - RedLine Stealer + - Rhysida Ransomware + - Swift Slicer + - IcedID + - DarkCrystal RAT + - Chaos Ransomware + - PlugX + - Industroyer2 + - Azorult + - Remcos + - XMRig + - Qakbot + - Volt Typhoon + - Hermetic Wiper + - Warzone RAT + - Trickbot + - Amadey + - BlackByte Ransomware + - LockBit Ransomware + - CISA AA23-347A + - Data Destruction + - Phemedrone Stealer + - Handala Wiper + - MoonPeak + - ValleyRAT + - Meduza Stealer + asset_type: Endpoint + mitre_attack_id: + - T1543 + - T1036.005 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/suspicious_process_path/susp_path_sysmon1.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml b/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml index 115d30093e..54ade9f424 100644 --- a/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml +++ b/detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml @@ -1,7 +1,7 @@ name: Windows System Binary Proxy Execution Compiled HTML File Decompile id: 2acf0e19-4149-451c-a3f3-39cd3c77e37d -version: 6 -date: '2024-12-10' +version: 8 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -72,7 +72,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1218.001 - - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_system_remote_discovery_with_query.yml b/detections/endpoint/windows_system_remote_discovery_with_query.yml new file mode 100644 index 0000000000..58b97c3df7 --- /dev/null +++ b/detections/endpoint/windows_system_remote_discovery_with_query.yml @@ -0,0 +1,64 @@ +name: Windows System Remote Discovery With Query +id: 94859172-a521-474f-97ac-4cf4b09634a3 +version: 1 +date: '2025-02-05' +author: Steven Dick +status: production +type: Anomaly +description: The following analytic detects the execution of `query.exe` with command-line arguments aimed at discovering data on remote devices. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as adversaries may use `query.exe` to gain situational awareness and perform Active Directory discovery on compromised endpoints. If confirmed malicious, this behavior could allow attackers to identify various details about a system, aiding in further lateral movement and privilege escalation within the network. +data_source: +- Sysmon Event ID 1 +- Windows Security Event ID 4688 +- CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` values(Processes.process_current_directory) as Processes.process_current_directory values(Processes.process_id) as Processes.process_id values(Processes.process) as Processes.process values(Processes.parent_process_id) as Processes.parent_process_id values(Processes.parent_process) as Processes.parent_process count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe" OR Processes.original_file_name="query.exe") AND (Processes.process="*/server*") AND NOT Processes.process IN ("*/server:localhost*", "*/server:127.0.0.1*") by Processes.dest Processes.user Processes.process_name Processes.parent_process_name + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_system_remote_discovery_with_query_filter` +how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +known_false_positives: Administrators or power users may use this command for troubleshooting. +references: +- https://attack.mitre.org/techniques/T1033/ +drilldown_searches: +- name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$","$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate processes on $dest$ + search: '| from datamodel:Endpoint.Processes | search dest=$dest$ process_name = $process_name|s$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The user $user$ ran the Query command to enumerate the remote system $dest$ + risk_objects: + - field: user + type: user + score: 25 + - field: dest + type: system + score: 25 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Active Directory Discovery + asset_type: Endpoint + mitre_attack_id: + - T1033 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/query_remote_usage/query_remote_usage.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml b/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml index 40f299551f..151b86c366 100644 --- a/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml +++ b/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml @@ -1,6 +1,6 @@ name: Windows System Script Proxy Execution Syncappvpublishingserver id: 8dd73f89-682d-444c-8b41-8e679966ad3c -version: 5 +version: 6 date: '2024-11-13' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_terminating_lsass_process.yml b/detections/endpoint/windows_terminating_lsass_process.yml index 1010e55878..4ac22b6fea 100644 --- a/detections/endpoint/windows_terminating_lsass_process.yml +++ b/detections/endpoint/windows_terminating_lsass_process.yml @@ -1,7 +1,7 @@ name: Windows Terminating Lsass Process id: 7ab3c319-a4e7-4211-9e8c-40a049d0dba6 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -59,7 +59,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_time_based_evasion.yml b/detections/endpoint/windows_time_based_evasion.yml index a6e2eda7af..a7a30342b6 100644 --- a/detections/endpoint/windows_time_based_evasion.yml +++ b/detections/endpoint/windows_time_based_evasion.yml @@ -1,7 +1,7 @@ name: Windows Time Based Evasion id: 34502357-deb1-499a-8261-ffe144abf561 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,7 +61,6 @@ tags: - NjRAT asset_type: Endpoint mitre_attack_id: - - T1497 - T1497.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml b/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml index 69fcad7d31..5453cc7fef 100644 --- a/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml +++ b/detections/endpoint/windows_time_based_evasion_via_choice_exec.yml @@ -1,7 +1,7 @@ name: Windows Time Based Evasion via Choice Exec id: d5f54b38-10bf-4b3a-b6fc-85949862ed50 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1497.003 - - T1497 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml b/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml index ffd2829b98..ced7799775 100644 --- a/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml +++ b/detections/endpoint/windows_uac_bypass_suspicious_child_process.yml @@ -1,7 +1,7 @@ name: Windows UAC Bypass Suspicious Child Process id: 453a6b0f-b0ea-48fa-9cf4-20537ffdd22c -version: 4 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -69,7 +69,6 @@ tags: - Living Off The Land asset_type: Endpoint mitre_attack_id: - - T1548 - T1548.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml b/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml index 29e8eca705..e6c5b3452a 100644 --- a/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml +++ b/detections/endpoint/windows_uac_bypass_suspicious_escalation_behavior.yml @@ -1,7 +1,7 @@ name: Windows UAC Bypass Suspicious Escalation Behavior id: 00d050d3-a5b4-4565-a6a5-a31f69681dc3 -version: 5 -date: '2024-12-10' +version: 7 +date: '2025-02-10' author: Steven Dick status: production type: TTP @@ -86,7 +86,6 @@ tags: - Windows Defense Evasion Tactics asset_type: Endpoint mitre_attack_id: - - T1548 - T1548.002 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml b/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml index 08803a7cd9..b064f55c1f 100644 --- a/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml +++ b/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml @@ -1,7 +1,7 @@ name: Windows Unsigned DLL Side-Loading In Same Process Path id: 3cf85c02-f9d6-4186-bf3c-e70ee99fbc7f -version: 6 -date: '2025-01-27' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk data_source: - Sysmon EventID 7 @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1574.002 - - T1574 product: - Splunk Enterprise - Splunk Enterprise Security @@ -71,6 +70,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.002/unsigned_dll_loaded_same_process_path/unsigned_dll_process_path.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.002/unsigned_dll_loaded_same_process_path/unsigned_dll_process_path.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml index c2fca2d205..63b6bc6fe8 100644 --- a/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos id: f65aa026-b811-42ab-b4b9-d9088137648f -date: '2024-11-13' +date: '2025-02-10' type: Anomaly -version: 4 +version: 5 status: production author: Mauricio Velazco, Splunk data_source: @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml index 99987eef1c..3526b02f99 100644 --- a/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos id: f122cb2e-d773-4f11-8399-62a3572d8dd7 type: Anomaly -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' status: production author: Mauricio Velazco, Splunk data_source: @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml b/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml index 423d4f8f23..5dbcdccc4e 100644 --- a/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml +++ b/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml @@ -1,9 +1,9 @@ name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM id: 15603165-147d-4a6e-9778-bd0ff39e668f type: Anomaly -version: 5 +version: 6 status: production -date: '2024-11-13' +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4776 @@ -64,7 +64,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml b/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml index 44f94c13c8..8d72b7869c 100644 --- a/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml +++ b/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml @@ -1,9 +1,9 @@ name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials id: 14f414cf-3080-4b9b-aaf6-55a4ce947b93 type: Anomaly -version: 5 +version: 6 status: production -date: '2024-11-13' +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4648 @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml index 437f332a2f..8d4f21783d 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Users Failed To Auth Using Kerberos id: bc9cb715-08ba-40c3-9758-6e2b26e455cb -date: '2024-11-13' +date: '2025-02-10' type: Anomaly -version: 4 +version: 5 status: production author: Mauricio Velazco, Splunk data_source: @@ -62,7 +62,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml index e7fa32d047..4390ea59a9 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml @@ -1,9 +1,9 @@ name: Windows Unusual Count Of Users Failed To Authenticate From Process id: 25bdb6cb-2e49-4d34-a93c-d6c567c122fe type: Anomaly -version: 5 +version: 6 status: production -date: '2024-11-13' +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4625 @@ -65,7 +65,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml index 51d1787dea..851a0ac391 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml @@ -1,9 +1,9 @@ name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM id: 6f6c8fd7-6a6b-4af9-a0e9-57cfc47a58b4 type: Anomaly -version: 5 +version: 6 status: production -date: '2024-11-13' +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4776 @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml b/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml index f3cb730dff..602d834ebc 100644 --- a/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml +++ b/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml @@ -1,9 +1,9 @@ name: Windows Unusual Count Of Users Remotely Failed To Auth From Host id: cf06a0ee-ffa9-4ed3-be77-0670ed9bab52 type: Anomaly -version: 5 +version: 6 status: production -date: '2024-11-13' +date: '2025-02-10' author: Mauricio Velazco, Splunk data_source: - Windows Event Log Security 4625 @@ -61,7 +61,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1110.003 - - T1110 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml index 8a5066b1b8..dfe94f5f83 100644 --- a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml +++ b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_source.yml @@ -1,7 +1,7 @@ name: Windows Unusual NTLM Authentication Destinations By Source id: ae9b0df5-5fb0-477f-abc9-47faf42aa91d -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -63,7 +63,6 @@ tags: - Active Directory Password Spraying asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml index f9d5c01f64..d58eb04003 100644 --- a/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml +++ b/detections/endpoint/windows_unusual_ntlm_authentication_destinations_by_user.yml @@ -1,7 +1,7 @@ name: Windows Unusual NTLM Authentication Destinations By User id: a4d86702-402b-4a4f-8d06-9d61e6c39cad -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -63,7 +63,6 @@ tags: - Active Directory Password Spraying asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml index 7474361923..48f11d9078 100644 --- a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml +++ b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_destination.yml @@ -1,7 +1,7 @@ name: Windows Unusual NTLM Authentication Users By Destination id: 1120a204-8444-428b-8657-6ea4e1f3e840 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -65,7 +65,6 @@ tags: - Active Directory Password Spraying asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml index d6a3b2c0de..e55d1b5084 100644 --- a/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml +++ b/detections/endpoint/windows_unusual_ntlm_authentication_users_by_source.yml @@ -1,7 +1,7 @@ name: Windows Unusual NTLM Authentication Users By Source id: 80fcc4d4-fd90-488e-b55a-4e7190ae6ce2 -version: 3 -date: '2024-11-13' +version: 4 +date: '2025-02-10' author: Steven Dick status: production type: Anomaly @@ -63,7 +63,6 @@ tags: - Active Directory Password Spraying asset_type: Endpoint mitre_attack_id: - - T1110 - T1110.003 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_usbstor_registry_key_modification.yml b/detections/endpoint/windows_usbstor_registry_key_modification.yml new file mode 100644 index 0000000000..4ae1abf576 --- /dev/null +++ b/detections/endpoint/windows_usbstor_registry_key_modification.yml @@ -0,0 +1,67 @@ +name: Windows USBSTOR Registry Key Modification +id: a345980a-417d-4ed3-9fb4-cac30c9405a0 +version: 1 +date: '2025-01-17' +author: Steven Dick +status: production +type: Anomaly +description: This analytic is used to identify when a USB removable media device is attached to a Windows host. In this scenario we are querying the Endpoint Registry data model to look for modifications to the HKLM\System\CurrentControlSet\Enum\USBSTOR\ key. Adversaries and Insider Threats may use removable media devices for several malicious activities, including initial access, execution, and exfiltration. +data_source: +- Sysmon Event ID 12 +- Sysmon Event ID 13 +search: |- + | tstats `security_content_summariesonly` values(Registry.registry_value_data) as registry_value_data, values(Registry.registry_value_name) as registry_value_name, min(_time) as firstTime, max(_time) as lastTime, count from datamodel=Endpoint.Registry where Registry.registry_path IN ("HKLM\\System\\CurrentControlSet\\Enum\\USBSTOR\\*") AND Registry.registry_value_name ="FriendlyName" by Registry.dest,Registry.registry_value_data,Registry.registry_path + | `drop_dm_object_name(Registry)` + | eval object_name = registry_value_data, object_handle = split(mvindex(split(registry_path, "\\"),6),"&"), object_handle = mvindex(mvfilter(NOT len(object_handle)=1),0) + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_usbstor_registry_key_modification_filter` +how_to_implement: To successfully implement this search, you must ingest endpoint logging that tracks changes to the HKLM\System\CurrentControlSet\Enum\USBSTOR\ registry keys. Ensure that the field from the event logs is being mapped to the proper fields in the Endpoint.Registry data model. +known_false_positives: Legitimate USB activity will also be detected. Please verify and investigate as appropriate. +references: +- https://attack.mitre.org/techniques/T1200/ +- https://www.cisa.gov/news-events/news/using-caution-usb-drives +- https://www.bleepingcomputer.com/news/security/fbi-hackers-use-badusb-to-target-defense-firms-with-ransomware/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate USB events on $dest$ + search: '| from datamodel:Endpoint.Registry | search dest=$dest$ registry_path IN ("HKLM\\System\\CurrentControlSet\\Enum\\USBSTOR\\*")' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: A removable storage device named [$object_name$] with drive letter [$object_handle$] was attached to $dest$ + risk_objects: + - field: dest + type: system + score: 10 + threat_objects: + - field: object_name + type: registry_value_name + - field: object_handle + type: registry_value_text +tags: + analytic_story: + - Data Protection + asset_type: Endpoint + mitre_attack_id: + - T1200 + - T1025 + - T1091 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1200/sysmon_usb_use_execution/sysmon_usb_use_execution.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_user_deletion_via_net.yml b/detections/endpoint/windows_user_deletion_via_net.yml index 33ae19c5ea..32bb43dd91 100644 --- a/detections/endpoint/windows_user_deletion_via_net.yml +++ b/detections/endpoint/windows_user_deletion_via_net.yml @@ -1,6 +1,6 @@ name: Windows User Deletion Via Net id: b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e -version: 1 +version: 2 date: '2025-01-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/windows_user_disabled_via_net.yml b/detections/endpoint/windows_user_disabled_via_net.yml index dd390a4128..547248419e 100644 --- a/detections/endpoint/windows_user_disabled_via_net.yml +++ b/detections/endpoint/windows_user_disabled_via_net.yml @@ -1,6 +1,6 @@ name: Windows User Disabled Via Net id: b0359e05-c87b-4354-83d8-aee0d890243f -version: 1 +version: 2 date: '2025-01-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/endpoint/windows_user_discovery_via_net.yml b/detections/endpoint/windows_user_discovery_via_net.yml index 9f736b6b2d..670b59cbaa 100644 --- a/detections/endpoint/windows_user_discovery_via_net.yml +++ b/detections/endpoint/windows_user_discovery_via_net.yml @@ -1,7 +1,7 @@ name: Windows User Discovery Via Net id: 7742987e-88c1-476b-a626-a869e088ab72 -version: 1 -date: '2025-01-13' +version: 2 +date: '2025-02-10' author: Mauricio Velazco, Teoderick Contreras, Nasreddine Bencherchali, Splunk status: production type: Hunting @@ -17,8 +17,22 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` (Processes.process="*user" OR Processes.process="*users" OR Processes.process="*users *" OR Processes.process="*user *") AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_user_discovery_via_net_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_net` (Processes.process="*user" + OR Processes.process="*users" OR Processes.process="*users *" OR Processes.process="*user + *") AND NOT (Processes.process="*/add" OR Processes.process="*/delete") by Processes.dest + Processes.user Processes.parent_process Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_user_discovery_via_net_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. known_false_positives: Administrators or power users may use this command for troubleshooting. references: - https://attack.mitre.org/techniques/T1087/001/ @@ -28,7 +42,6 @@ tags: - Sandworm Tools asset_type: Endpoint mitre_attack_id: - - T1087 - T1087.001 product: - Splunk Enterprise diff --git a/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml b/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml index 0ee3bb1eaa..a9521c99f0 100644 --- a/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml +++ b/detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml @@ -1,7 +1,7 @@ name: Windows User Execution Malicious URL Shortcut File id: 5c7ee6ad-baf4-44fb-b2f0-0cfeddf82dbc -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1204.002 - - T1204 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/windows_windbg_spawning_autoit3.yml b/detections/endpoint/windows_windbg_spawning_autoit3.yml index ddf09e5373..323c29de1d 100644 --- a/detections/endpoint/windows_windbg_spawning_autoit3.yml +++ b/detections/endpoint/windows_windbg_spawning_autoit3.yml @@ -1,6 +1,6 @@ name: Windows WinDBG Spawning AutoIt3 id: 7aec015b-cd69-46c3-85ed-dac152056aa4 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_wpdbusenum_registry_key_modification.yml b/detections/endpoint/windows_wpdbusenum_registry_key_modification.yml new file mode 100644 index 0000000000..d87be77ae0 --- /dev/null +++ b/detections/endpoint/windows_wpdbusenum_registry_key_modification.yml @@ -0,0 +1,67 @@ +name: Windows WPDBusEnum Registry Key Modification +id: 52b48e8b-eb6e-48b0-b8f1-73273f6b134e +version: 1 +date: '2025-01-17' +author: Steven Dick +status: production +type: Anomaly +description: This analytic is used to identify when a USB removable media device is attached to a Windows host. In this scenario we are querying the Endpoint Registry data model to look for modifications to the Windows Portable Device keys HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices\ or HKLM\System\CurrentControlSet\Enum\SWD\WPDBUSENUM\ . Adversaries and Insider Threats may use removable media devices for several malicious activities, including initial access, execution, and exfiltration. +data_source: +- Sysmon Event ID 12 +- Sysmon Event ID 13 +search: |- + | tstats `security_content_summariesonly` latest(Registry.registry_path) as registry_path, values(Registry.registry_value_name) as registry_value_name, min(_time) as firstTime, max(_time) as lastTime, count from datamodel=Endpoint.Registry where Registry.registry_path IN ("HKLM\\SOFTWARE\\Microsoft\\Windows Portable Devices\\Devices\\*","HKLM\\System\\CurrentControlSet\\Enum\\SWD\\WPDBUSENUM\\*") AND Registry.registry_value_name ="FriendlyName" AND Registry.registry_path="*USBSTOR*" by Registry.dest,Registry.registry_value_data + | `drop_dm_object_name(Registry)` + | eval object_handle = registry_value_data, object_name = replace(mvindex(split(mvindex(split(registry_path, "??"),1),"&"),2),"PROD_","") + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_wpdbusenum_registry_key_modification_filter` +how_to_implement: To successfully implement this search, you must ingest endpoint logging that tracks changes to the HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices\ or HKLM\System\CurrentControlSet\Enum\SWD\WPDBUSENUM\ registry keys. Ensure that the field from the event logs is being mapped to the proper fields in the Endpoint.Registry data model. +known_false_positives: Legitimate USB activity will also be detected. Please verify and investigate as appropriate. +references: +- https://attack.mitre.org/techniques/T1200/ +- https://www.cisa.gov/news-events/news/using-caution-usb-drives +- https://www.bleepingcomputer.com/news/security/fbi-hackers-use-badusb-to-target-defense-firms-with-ransomware/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate USB events on $dest$ + search: '| from datamodel:Endpoint.Registry | search dest=$dest$ registry_path IN ("HKLM\\SOFTWARE\\Microsoft\\Windows Portable Devices\\Devices\\*","HKLM\\System\\CurrentControlSet\\Enum\\SWD\\WPDBUSENUM\\*")' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: A removable storage device named [$object_name$] with drive letter [$object_handle$] was attached to $dest$ + risk_objects: + - field: dest + type: system + score: 10 + threat_objects: + - field: object_name + type: registry_value_name + - field: object_handle + type: registry_value_text +tags: + analytic_story: + - Data Protection + asset_type: Endpoint + mitre_attack_id: + - T1200 + - T1025 + - T1091 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1200/sysmon_usb_use_execution/sysmon_usb_use_execution.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml index 690c5bffb5..36d6515acc 100644 --- a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml +++ b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml @@ -1,7 +1,7 @@ name: WinEvent Scheduled Task Created to Spawn Shell id: 203ef0ea-9bd8-11eb-8201-acde48001122 -version: 8 -date: '2025-01-27' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -67,7 +67,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security @@ -76,6 +75,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog diff --git a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml index 7c383641be..b7a530c00d 100644 --- a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml +++ b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml @@ -1,7 +1,7 @@ name: WinEvent Scheduled Task Created Within Public Path id: 5d9c6eee-988c-11eb-8253-acde48001122 -version: 8 -date: '2025-01-27' +version: 9 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1053.005 - - T1053 product: - Splunk Enterprise - Splunk Enterprise Security @@ -82,6 +81,7 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log + - data: + https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/winevent_scheduled_task_created_to_spawn_shell/windows-xml.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog diff --git a/detections/endpoint/winhlp32_spawning_a_process.yml b/detections/endpoint/winhlp32_spawning_a_process.yml index 97671e24f0..71018871f9 100644 --- a/detections/endpoint/winhlp32_spawning_a_process.yml +++ b/detections/endpoint/winhlp32_spawning_a_process.yml @@ -1,6 +1,6 @@ name: Winhlp32 Spawning a Process id: d17dae9e-2618-11ec-b9f5-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/winrar_spawning_shell_application.yml b/detections/endpoint/winrar_spawning_shell_application.yml index 9ef1be04ff..104bc4f1d3 100644 --- a/detections/endpoint/winrar_spawning_shell_application.yml +++ b/detections/endpoint/winrar_spawning_shell_application.yml @@ -1,6 +1,6 @@ name: WinRAR Spawning Shell Application id: d2f36034-37fa-4bd4-8801-26807c15540f -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml index e544a4480e..c21bc05de0 100644 --- a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml +++ b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml @@ -1,7 +1,7 @@ name: WMI Permanent Event Subscription - Sysmon id: ad05aae6-3b2a-4f73-af97-57bd26cee3b9 -version: 5 -date: '2024-11-13' +version: 6 +date: '2025-02-10' author: Rico Valdez, Michael Haag, Splunk status: production type: TTP @@ -58,7 +58,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1546.003 - - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/wmic_group_discovery.yml b/detections/endpoint/wmic_group_discovery.yml index 1387e90ee7..3d38511475 100644 --- a/detections/endpoint/wmic_group_discovery.yml +++ b/detections/endpoint/wmic_group_discovery.yml @@ -1,7 +1,7 @@ name: Wmic Group Discovery id: 83317b08-155b-11ec-8e00-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Hunting @@ -41,7 +41,6 @@ tags: - Active Directory Discovery asset_type: Endpoint mitre_attack_id: - - T1069 - T1069.001 product: - Splunk Enterprise diff --git a/detections/endpoint/wmic_noninteractive_app_uninstallation.yml b/detections/endpoint/wmic_noninteractive_app_uninstallation.yml index a45718c22e..cb48b0dacc 100644 --- a/detections/endpoint/wmic_noninteractive_app_uninstallation.yml +++ b/detections/endpoint/wmic_noninteractive_app_uninstallation.yml @@ -1,7 +1,7 @@ name: Wmic NonInteractive App Uninstallation id: bff0e7a0-317f-11ec-ab4e-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -44,7 +44,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1562.001 - - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/wmic_xsl_execution_via_url.yml b/detections/endpoint/wmic_xsl_execution_via_url.yml index b8efe7f1fc..a9fa113597 100644 --- a/detections/endpoint/wmic_xsl_execution_via_url.yml +++ b/detections/endpoint/wmic_xsl_execution_via_url.yml @@ -1,6 +1,6 @@ name: WMIC XSL Execution via URL id: 787e9dd0-4328-11ec-a029-acde48001122 -version: 6 +version: 7 date: '2024-12-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml index bdff837caf..931de61b80 100644 --- a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml +++ b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml @@ -1,7 +1,7 @@ name: Wscript Or Cscript Suspicious Child Process id: 1f35e1da-267b-11ec-90a9-acde48001122 -version: 5 -date: '2024-12-10' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -72,9 +72,8 @@ tags: asset_type: Endpoint mitre_attack_id: - T1055 - - T1543 - T1134.004 - - T1134 + - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml b/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml index 702bb0a66e..9ae72bafa1 100644 --- a/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml @@ -1,7 +1,7 @@ name: Wsmprovhost LOLBAS Execution Process Spawn id: 2eed004c-4c0d-11ec-93e8-3e22fbd008af -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Mauricio Velazco, Splunk status: production type: TTP @@ -75,7 +75,6 @@ tags: - CISA AA24-241A asset_type: Endpoint mitre_attack_id: - - T1021 - T1021.006 product: - Splunk Enterprise diff --git a/detections/endpoint/wsreset_uac_bypass.yml b/detections/endpoint/wsreset_uac_bypass.yml index 14b7aa39d9..1879fa36d4 100644 --- a/detections/endpoint/wsreset_uac_bypass.yml +++ b/detections/endpoint/wsreset_uac_bypass.yml @@ -1,7 +1,7 @@ name: WSReset UAC Bypass id: 8b5901bc-da63-11eb-be43-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-10' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -73,7 +73,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1548.002 - - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/xmrig_driver_loaded.yml b/detections/endpoint/xmrig_driver_loaded.yml index 475bc420de..2c08457e9e 100644 --- a/detections/endpoint/xmrig_driver_loaded.yml +++ b/detections/endpoint/xmrig_driver_loaded.yml @@ -1,7 +1,7 @@ name: XMRIG Driver Loaded id: 90080fa6-a8df-11eb-91e4-acde48001122 -version: 4 -date: '2024-11-13' +version: 5 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -54,7 +54,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1543.003 - - T1543 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/xsl_script_execution_with_wmic.yml b/detections/endpoint/xsl_script_execution_with_wmic.yml index 02f24699a2..28584c4d66 100644 --- a/detections/endpoint/xsl_script_execution_with_wmic.yml +++ b/detections/endpoint/xsl_script_execution_with_wmic.yml @@ -1,6 +1,6 @@ name: XSL Script Execution With WMIC id: 004e32e2-146d-11ec-a83f-acde48001122 -version: 5 +version: 6 date: '2024-11-13' author: Teoderick Contreras, Splunk status: production diff --git a/detections/network/detect_arp_poisoning.yml b/detections/network/detect_arp_poisoning.yml index 108276a3d7..1e3b9d8998 100644 --- a/detections/network/detect_arp_poisoning.yml +++ b/detections/network/detect_arp_poisoning.yml @@ -1,7 +1,7 @@ name: Detect ARP Poisoning id: b44bebd6-bd39-467b-9321-73971bcd1aac -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -44,7 +44,6 @@ tags: mitre_attack_id: - T1200 - T1498 - - T1557 - T1557.002 product: - Splunk Enterprise diff --git a/detections/network/detect_ipv6_network_infrastructure_threats.yml b/detections/network/detect_ipv6_network_infrastructure_threats.yml index a45007b944..5be89b972e 100644 --- a/detections/network/detect_ipv6_network_infrastructure_threats.yml +++ b/detections/network/detect_ipv6_network_infrastructure_threats.yml @@ -1,7 +1,7 @@ name: Detect IPv6 Network Infrastructure Threats id: c3be767e-7959-44c5-8976-0e9c12a91ad2 -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -52,7 +52,6 @@ tags: mitre_attack_id: - T1200 - T1498 - - T1557 - T1557.002 product: - Splunk Enterprise diff --git a/detections/network/detect_large_outbound_icmp_packets.yml b/detections/network/detect_large_outbound_icmp_packets.yml index e4bdf54ffc..9fa1a7f4b5 100644 --- a/detections/network/detect_large_outbound_icmp_packets.yml +++ b/detections/network/detect_large_outbound_icmp_packets.yml @@ -1,6 +1,6 @@ name: Detect Large Outbound ICMP Packets id: e9c102de-4d43-42a7-b1c8-8062ea297419 -version: 8 +version: 9 date: '2025-01-27' author: Rico Valdez, Dean Luxton, Splunk status: production diff --git a/detections/network/detect_outbound_smb_traffic.yml b/detections/network/detect_outbound_smb_traffic.yml index 3a2cbf6989..0e0acc3144 100644 --- a/detections/network/detect_outbound_smb_traffic.yml +++ b/detections/network/detect_outbound_smb_traffic.yml @@ -1,7 +1,7 @@ name: Detect Outbound SMB Traffic id: 1bed7774-304a-4e8f-9d72-d80e45ff492b -version: 7 -date: '2024-11-15' +version: 8 +date: '2025-02-10' author: Bhavin Patel, Stuart Hopkins, Patrick Bareiss status: experimental type: TTP @@ -30,10 +30,10 @@ how_to_implement: This search also requires you to be ingesting your network tra known_false_positives: It is likely that the outbound Server Message Block (SMB) traffic is legitimate, if the company's internal networks are not well-defined in the Assets and Identity Framework. Categorize the internal CIDR blocks as `internal` in the - lookup file to avoid creating findings for traffic destined to those CIDR - blocks. Any other network connection that is going out to the Internet should be - investigated and blocked. Best practices suggest preventing external communications - of all SMB versions and related protocols at the network boundary. + lookup file to avoid creating findings for traffic destined to those CIDR blocks. + Any other network connection that is going out to the Internet should be investigated + and blocked. Best practices suggest preventing external communications of all SMB + versions and related protocols at the network boundary. references: [] rba: message: An outbound SMB connection from $src_ip$ in your infrastructure connecting @@ -53,7 +53,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.002 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/detect_port_security_violation.yml b/detections/network/detect_port_security_violation.yml index 66a16461fd..0126710dbb 100644 --- a/detections/network/detect_port_security_violation.yml +++ b/detections/network/detect_port_security_violation.yml @@ -1,7 +1,7 @@ name: Detect Port Security Violation id: 2de3d5b8-a4fa-45c5-8540-6d071c194d24 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -44,7 +44,6 @@ tags: mitre_attack_id: - T1200 - T1498 - - T1557 - T1557.002 product: - Splunk Enterprise diff --git a/detections/network/detect_remote_access_software_usage_dns.yml b/detections/network/detect_remote_access_software_usage_dns.yml index e01bd31544..f7744a4f63 100644 --- a/detections/network/detect_remote_access_software_usage_dns.yml +++ b/detections/network/detect_remote_access_software_usage_dns.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage DNS id: a16b797d-e309-41bd-8ba0-5067dae2e4be -version: 5 +version: 6 date: '2024-11-15' author: Steven Dick status: production @@ -52,21 +52,28 @@ drilldown_searches: | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate traffic to $query$ + search: '| from datamodel:Network_Resolution.DNS | search src=$src$ query=$query$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: A domain for a known remote access software $query$ was contacted by $src$. risk_objects: - field: src type: system - score: 4 + score: 25 threat_objects: - field: query type: domain + - field: signature + type: signature tags: analytic_story: - Insider Threat - Command And Control - Ransomware - CISA AA24-241A + - Remote Monitoring and Management Software asset_type: Endpoint mitre_attack_id: - T1219 diff --git a/detections/network/detect_remote_access_software_usage_traffic.yml b/detections/network/detect_remote_access_software_usage_traffic.yml index aeb0b45f21..526fe6f906 100644 --- a/detections/network/detect_remote_access_software_usage_traffic.yml +++ b/detections/network/detect_remote_access_software_usage_traffic.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage Traffic id: 885ea672-07ee-475a-879e-60d28aa5dd42 -version: 5 +version: 6 date: '2024-11-15' author: Steven Dick status: production @@ -52,6 +52,10 @@ drilldown_searches: | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate application traffic for $app$ + search: '| from datamodel:Network_Traffic.All_Traffic | search src=$src$ app=$app$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: Application traffic for a known remote access software [$signature$] was detected from $src$. @@ -59,12 +63,18 @@ rba: - field: src type: system score: 25 - threat_objects: [] + - field: user + type: user + score: 25 + threat_objects: + - field: signature + type: signature tags: analytic_story: - Insider Threat - Command And Control - Ransomware + - Remote Monitoring and Management Software asset_type: Network mitre_attack_id: - T1219 diff --git a/detections/network/detect_software_download_to_network_device.yml b/detections/network/detect_software_download_to_network_device.yml index d11e5395c6..5f16395c2c 100644 --- a/detections/network/detect_software_download_to_network_device.yml +++ b/detections/network/detect_software_download_to_network_device.yml @@ -1,7 +1,7 @@ name: Detect Software Download To Network Device id: cc590c66-f65f-48f2-986a-4797244762f8 -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -44,7 +44,6 @@ tags: asset_type: Infrastructure mitre_attack_id: - T1542.005 - - T1542 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/detect_traffic_mirroring.yml b/detections/network/detect_traffic_mirroring.yml index a8121dd68b..b9982c9d34 100644 --- a/detections/network/detect_traffic_mirroring.yml +++ b/detections/network/detect_traffic_mirroring.yml @@ -1,7 +1,7 @@ name: Detect Traffic Mirroring id: 42b3b753-5925-49c5-9742-36fa40a73990 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Mikael Bjerkeland, Splunk status: experimental type: TTP @@ -41,10 +41,9 @@ tags: - Router and Infrastructure Security asset_type: Infrastructure mitre_attack_id: - - T1200 - - T1020 - - T1498 - T1020.001 + - T1200 + - T1498 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/dns_query_length_outliers___mltk.yml b/detections/network/dns_query_length_outliers___mltk.yml index 629215e272..2c4743e19d 100644 --- a/detections/network/dns_query_length_outliers___mltk.yml +++ b/detections/network/dns_query_length_outliers___mltk.yml @@ -1,7 +1,7 @@ name: DNS Query Length Outliers - MLTK id: 85fbcfe8-9718-4911-adf6-7000d077a3a9 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.004 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/dns_query_length_with_high_standard_deviation.yml b/detections/network/dns_query_length_with_high_standard_deviation.yml index 744203b569..686ce2e6d7 100644 --- a/detections/network/dns_query_length_with_high_standard_deviation.yml +++ b/detections/network/dns_query_length_with_high_standard_deviation.yml @@ -1,7 +1,7 @@ name: DNS Query Length With High Standard Deviation id: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f5 -version: 8 -date: '2024-11-15' +version: 9 +date: '2025-02-10' author: Bhavin Patel, Splunk status: production type: Anomaly @@ -56,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1048.003 - - T1048 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/excessive_dns_failures.yml b/detections/network/excessive_dns_failures.yml index 96cd124e74..b809df4dbf 100644 --- a/detections/network/excessive_dns_failures.yml +++ b/detections/network/excessive_dns_failures.yml @@ -1,7 +1,7 @@ name: Excessive DNS Failures id: 104658f4-afdc-499e-9719-17243f9826f1 -version: 6 -date: '2024-11-15' +version: 7 +date: '2025-02-10' author: bowesmana, Bhavin Patel, Splunk status: experimental type: Anomaly @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1071.004 - - T1071 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml b/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml index 16c268125d..86532055ed 100644 --- a/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml +++ b/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml @@ -1,7 +1,7 @@ name: Hosts receiving high volume of network traffic from email server id: 7f5fb3e1-4209-4914-90db-0ec21b556368 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Bhavin Patel, Splunk status: experimental type: Anomaly @@ -51,7 +51,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1114.002 - - T1114 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/large_volume_of_dns_any_queries.yml b/detections/network/large_volume_of_dns_any_queries.yml index b73ca41645..1be208ea08 100644 --- a/detections/network/large_volume_of_dns_any_queries.yml +++ b/detections/network/large_volume_of_dns_any_queries.yml @@ -1,7 +1,7 @@ name: Large Volume of DNS ANY Queries id: 8fa891f7-a533-4b3c-af85-5aa2e7c1f1eb -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Bhavin Patel, Splunk status: experimental type: Anomaly @@ -35,7 +35,6 @@ tags: - DNS Amplification Attacks asset_type: DNS Servers mitre_attack_id: - - T1498 - T1498.002 product: - Splunk Enterprise diff --git a/detections/network/protocol_or_port_mismatch.yml b/detections/network/protocol_or_port_mismatch.yml index d935eff540..727748a951 100644 --- a/detections/network/protocol_or_port_mismatch.yml +++ b/detections/network/protocol_or_port_mismatch.yml @@ -1,7 +1,7 @@ name: Protocol or Port Mismatch id: 54dc1265-2f74-4b6d-b30d-49eb506a31b3 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Anomaly @@ -42,7 +42,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1048.003 - - T1048 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/remote_desktop_network_bruteforce.yml b/detections/network/remote_desktop_network_bruteforce.yml deleted file mode 100644 index 35dcd16a5c..0000000000 --- a/detections/network/remote_desktop_network_bruteforce.yml +++ /dev/null @@ -1,51 +0,0 @@ -name: Remote Desktop Network Bruteforce -id: a98727cc-286b-4ff2-b898-41df64695923 -version: 6 -date: '2024-11-15' -author: Jose Hernandez, Splunk -status: experimental -type: TTP -description: The following analytic identifies potential Remote Desktop Protocol (RDP) - brute force attacks by monitoring network traffic for RDP application activity. - It detects anomalies by filtering source and destination pairs that generate traffic - exceeding twice the standard deviation of the average traffic. This method leverages - the Network_Traffic data model to identify unusual patterns indicative of brute - force attempts. This activity is significant as it may indicate an attacker attempting - to gain unauthorized access to systems via RDP. If confirmed malicious, this could - lead to unauthorized access, data exfiltration, or further network compromise. -data_source: [] -search: >- - | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Network_Traffic where (All_Traffic.app=rdp OR All_Traffic.dest_port=3389) - AND All_Traffic.action=allowed by All_Traffic.src All_Traffic.dest All_Traffic.dest_port | - eventstats stdev(count) AS stdev avg(count) AS avg p50(count) AS p50 | where count>(avg - + stdev*2) | rename All_Traffic.src AS src All_Traffic.dest AS dest | table firstTime - lastTime src dest count avg p50 stdev | `remote_desktop_network_bruteforce_filter` -how_to_implement: You must ensure that your network traffic data is populating the - Network_Traffic data model. -known_false_positives: RDP gateways may have unusually high amounts of traffic from - all other hosts' RDP applications in the network. -references: [] -rba: - message: $dest$ may be the target of an RDP Bruteforce - risk_objects: - - field: dest - type: system - score: 25 - - field: src - type: system - score: 25 - threat_objects: [] -tags: - analytic_story: - - SamSam Ransomware - - Ryuk Ransomware - asset_type: Endpoint - mitre_attack_id: - - T1021.001 - - T1021 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - security_domain: network diff --git a/detections/network/remote_desktop_network_traffic.yml b/detections/network/remote_desktop_network_traffic.yml index dea3884a91..866c4cc5e4 100644 --- a/detections/network/remote_desktop_network_traffic.yml +++ b/detections/network/remote_desktop_network_traffic.yml @@ -1,7 +1,7 @@ name: Remote Desktop Network Traffic id: 272b8407-842d-4b3d-bead-a704584003d3 -version: 8 -date: '2024-11-15' +version: 9 +date: '2025-02-10' author: David Dorsey, Splunk status: production type: Anomaly @@ -63,7 +63,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.001 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/smb_traffic_spike.yml b/detections/network/smb_traffic_spike.yml index 7154a35162..122c6cb228 100644 --- a/detections/network/smb_traffic_spike.yml +++ b/detections/network/smb_traffic_spike.yml @@ -1,7 +1,7 @@ name: SMB Traffic Spike id: 7f5fb3e1-4209-4914-90db-0ec21b936378 -version: 6 -date: '2024-11-15' +version: 7 +date: '2025-02-10' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -43,7 +43,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.002 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/smb_traffic_spike___mltk.yml b/detections/network/smb_traffic_spike___mltk.yml index 0ec7d9fe16..38c6b024a6 100644 --- a/detections/network/smb_traffic_spike___mltk.yml +++ b/detections/network/smb_traffic_spike___mltk.yml @@ -1,7 +1,7 @@ name: SMB Traffic Spike - MLTK id: d25773ba-9ad8-48d1-858e-07ad0bbeb828 -version: 6 -date: '2024-11-15' +version: 7 +date: '2025-02-10' author: Rico Valdez, Splunk status: experimental type: Anomaly @@ -31,11 +31,10 @@ how_to_implement: "To successfully implement this search, you will need to ensur should periodically re-run the support search to rebuild the model with the latest data available in your environment.\nThis search produces a field (Number of events,count) that are not yet supported by ES Incident Review and therefore cannot be viewed - when a finding is raised. This field contributes additional context to the - finding. To see the additional metadata, add the following field, if not already - present, to Incident Review - Event Attributes (Configure > Incident Management - > Incident Review Settings > Add New Entry):\n* **Label:** Number of events, **Field:** - count" + when a finding is raised. This field contributes additional context to the finding. + To see the additional metadata, add the following field, if not already present, + to Incident Review - Event Attributes (Configure > Incident Management > Incident + Review Settings > Add New Entry):\n* **Label:** Number of events, **Field:** count" known_false_positives: If you are seeing more results than desired, you may consider reducing the value of the threshold in the search. You should also periodically re-run the support search to re-build the ML model on the latest data. Please update @@ -57,7 +56,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1021.002 - - T1021 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/network/tor_traffic.yml b/detections/network/tor_traffic.yml index 07c2e15ab9..4b1d821c41 100644 --- a/detections/network/tor_traffic.yml +++ b/detections/network/tor_traffic.yml @@ -1,7 +1,7 @@ name: TOR Traffic id: ea688274-9c06-4473-b951-e4cb7a5d7a45 -version: 6 -date: '2024-11-15' +version: 7 +date: '2025-02-10' author: David Dorsey, Bhavin Patel, Splunk status: production type: TTP @@ -59,7 +59,6 @@ tags: - Command And Control asset_type: Endpoint mitre_attack_id: - - T1090 - T1090.003 product: - Splunk Enterprise diff --git a/detections/network/windows_ad_replication_service_traffic.yml b/detections/network/windows_ad_replication_service_traffic.yml index 17845e1f82..59036dc908 100644 --- a/detections/network/windows_ad_replication_service_traffic.yml +++ b/detections/network/windows_ad_replication_service_traffic.yml @@ -1,7 +1,7 @@ name: Windows AD Replication Service Traffic id: c6e24183-a5f4-4b2a-ad01-2eb456d09b67 -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Steven Dick type: TTP status: experimental @@ -42,7 +42,6 @@ tags: - Sneaky Active Directory Persistence Tricks asset_type: Endpoint mitre_attack_id: - - T1003 - T1003.006 - T1207 product: diff --git a/detections/network/windows_remote_desktop_network_bruteforce_attempt.yml b/detections/network/windows_remote_desktop_network_bruteforce_attempt.yml new file mode 100644 index 0000000000..38f166c9d9 --- /dev/null +++ b/detections/network/windows_remote_desktop_network_bruteforce_attempt.yml @@ -0,0 +1,60 @@ +name: Windows Remote Desktop Network Bruteforce Attempt +id: 908bf0d5-0983-4afd-b6a4-e9eb5d361a7d +version: 2 +date: '2025-02-11' +author: Jose Hernandez, Bhavin Patel, Splunk +status: production +type: Anomaly +description: The following analytic identifies potential Remote Desktop Protocol (RDP) brute force attacks by monitoring network traffic for RDP application activity. This query detects potential RDP brute force attacks by identifying source IPs that have made more than 10 connection attempts to the same RDP port on a host within a one-hour window. The results are presented in a table that includes the source and destination IPs, destination port, number of attempts, and the times of the first and last connection attempts, helping to prioritize IPs based on the intensity of activity. +data_source: +- Sysmon EventID 3 +search: >- + | tstats `security_content_summariesonly` count, min(_time) as firstTime, max(_time) as lastTime values(Al_Traffic.action) as action from datamodel=Network_Traffic where (All_Traffic.app=rdp OR All_Traffic.dest_port=3389) by All_Traffic.src, All_Traffic.dest, All_Traffic.dest_port All_Traffic.user All_Traffic.vendor_product + | `drop_dm_object_name("All_Traffic")` + | eval duration=lastTime-firstTime + | where count > 10 AND duration < 3600 + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_remote_desktop_network_bruteforce_attempt_filter` +how_to_implement: You must ensure that your network traffic data is populating the Network_Traffic data model. Adjust the count and duration thresholds as necessary to tune the sensitivity of your detection. +known_false_positives: RDP gateways may have unusually high amounts of traffic from all other hosts' RDP applications in the network.Any legitimate RDP traffic using wrong/expired credentials will be also detected as a false positive. +references: +- https://www.zscaler.com/blogs/security-research/ransomware-delivered-using-rdp-brute-force-attack +- https://www.reliaquest.com/blog/rdp-brute-force-attacks/ +drilldown_searches: +- name: View the detection results for - "$dest$" + search: '%original_detection_search% | search dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: $dest$ may be the target of an RDP Bruteforce from $src$ + risk_objects: + - field: dest + type: system + score: 25 + threat_objects: + - field: src + type: ip_address +tags: + analytic_story: + - SamSam Ransomware + - Ryuk Ransomware + - Compromised User Account + asset_type: Endpoint + mitre_attack_id: + - T1110.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: network +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/rdp_brute_sysmon/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog diff --git a/detections/web/detect_remote_access_software_usage_url.yml b/detections/web/detect_remote_access_software_usage_url.yml index d60f2af086..6f186e9379 100644 --- a/detections/web/detect_remote_access_software_usage_url.yml +++ b/detections/web/detect_remote_access_software_usage_url.yml @@ -1,6 +1,6 @@ name: Detect Remote Access Software Usage URL id: 9296f515-073c-43a5-88ec-eda5a4626654 -version: 5 +version: 7 date: '2024-11-15' author: Steven Dick status: production @@ -52,6 +52,10 @@ drilldown_searches: by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ +- name: Investigate traffic to $url_domain$ + search: '| from datamodel:Web | search src=$src$ url_domain=$url_domain$' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: A domain for a known remote access software $url_domain$ was contacted by $src$. @@ -65,12 +69,15 @@ rba: threat_objects: - field: url_domain type: domain + - field: signature + type: signature tags: analytic_story: - Insider Threat - Command And Control - Ransomware - CISA AA24-241A + - Remote Monitoring and Management Software asset_type: Network mitre_attack_id: - T1219 diff --git a/detections/web/exploit_public_facing_application_via_apache_commons_text.yml b/detections/web/exploit_public_facing_application_via_apache_commons_text.yml index d9b87dfcf0..162db64b40 100644 --- a/detections/web/exploit_public_facing_application_via_apache_commons_text.yml +++ b/detections/web/exploit_public_facing_application_via_apache_commons_text.yml @@ -1,7 +1,7 @@ name: Exploit Public Facing Application via Apache Commons Text id: 19a481e0-c97c-4d14-b1db-75a708eb592e -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -72,10 +72,9 @@ tags: cve: - CVE-2022-42889 mitre_attack_id: - - T1505.003 - - T1505 - - T1190 - T1133 + - T1190 + - T1505.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/multiple_archive_files_http_post_traffic.yml b/detections/web/multiple_archive_files_http_post_traffic.yml index 725f31561f..7e4978a2c5 100644 --- a/detections/web/multiple_archive_files_http_post_traffic.yml +++ b/detections/web/multiple_archive_files_http_post_traffic.yml @@ -1,7 +1,7 @@ name: Multiple Archive Files Http Post Traffic id: 4477f3ea-a28f-11eb-b762-acde48001122 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -60,7 +60,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1048.003 - - T1048 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/plain_http_post_exfiltrated_data.yml b/detections/web/plain_http_post_exfiltrated_data.yml index f94dbe9139..1272c755a0 100644 --- a/detections/web/plain_http_post_exfiltrated_data.yml +++ b/detections/web/plain_http_post_exfiltrated_data.yml @@ -1,7 +1,7 @@ name: Plain HTTP POST Exfiltrated Data id: e2b36208-a364-11eb-8909-acde48001122 -version: 5 -date: '2024-11-15' +version: 6 +date: '2025-02-10' author: Teoderick Contreras, Splunk status: production type: TTP @@ -55,7 +55,6 @@ tags: asset_type: Endpoint mitre_attack_id: - T1048.003 - - T1048 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/spring4shell_payload_url_request.yml b/detections/web/spring4shell_payload_url_request.yml index 1ba92e50e9..adec62590e 100644 --- a/detections/web/spring4shell_payload_url_request.yml +++ b/detections/web/spring4shell_payload_url_request.yml @@ -1,7 +1,7 @@ name: Spring4Shell Payload URL Request id: 9d44d649-7d67-4559-95c1-8022ff49420b -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -57,10 +57,9 @@ tags: cve: - CVE-2022-22965 mitre_attack_id: - - T1505.003 - - T1505 - - T1190 - T1133 + - T1190 + - T1505.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/web_jsp_request_via_url.yml b/detections/web/web_jsp_request_via_url.yml index 3aea7b2a94..fbf4f4991c 100644 --- a/detections/web/web_jsp_request_via_url.yml +++ b/detections/web/web_jsp_request_via_url.yml @@ -1,7 +1,7 @@ name: Web JSP Request via URL id: 2850c734-2d44-4431-8139-1a56f6f54c01 -version: 4 -date: '2024-11-15' +version: 5 +date: '2025-02-10' author: Michael Haag, Splunk status: production type: TTP @@ -58,10 +58,9 @@ tags: cve: - CVE-2022-22965 mitre_attack_id: - - T1505.003 - - T1505 - - T1190 - T1133 + - T1190 + - T1505.003 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/web/zscaler_adware_activities_threat_blocked.yml b/detections/web/zscaler_adware_activities_threat_blocked.yml index f662cc0a16..c47abd8740 100644 --- a/detections/web/zscaler_adware_activities_threat_blocked.yml +++ b/detections/web/zscaler_adware_activities_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Adware Activities Threat Blocked id: 3407b250-345a-4d71-80db-c91e555a3ece -version: 4 +version: 5 date: '2024-11-15' author: Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/web/zscaler_behavior_analysis_threat_blocked.yml b/detections/web/zscaler_behavior_analysis_threat_blocked.yml index 8875d8762b..8a55d3f407 100644 --- a/detections/web/zscaler_behavior_analysis_threat_blocked.yml +++ b/detections/web/zscaler_behavior_analysis_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Behavior Analysis Threat Blocked id: 289ad59f-8939-4331-b805-f2bd51d36fb8 -version: 4 +version: 5 date: '2024-11-15' author: Rod Soto, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/web/zscaler_exploit_threat_blocked.yml b/detections/web/zscaler_exploit_threat_blocked.yml index 0da0906592..e88d087743 100644 --- a/detections/web/zscaler_exploit_threat_blocked.yml +++ b/detections/web/zscaler_exploit_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Exploit Threat Blocked id: 94665d8c-b841-4ff4-acb4-34d613e2cbfe -version: 4 +version: 5 date: '2024-11-15' author: Rod Soto, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/web/zscaler_malware_activity_threat_blocked.yml b/detections/web/zscaler_malware_activity_threat_blocked.yml index 3494bd9e23..34061dc5be 100644 --- a/detections/web/zscaler_malware_activity_threat_blocked.yml +++ b/detections/web/zscaler_malware_activity_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Malware Activity Threat Blocked id: ae874ad8-e353-40a7-87d4-420cdfb27d1a -version: 4 +version: 5 date: '2024-11-15' author: Rod Soto, Gowthamaraj Rajendran, Splunk status: production diff --git a/detections/web/zscaler_potentially_abused_file_download.yml b/detections/web/zscaler_potentially_abused_file_download.yml index 040b02ae71..f18bdfe4f0 100644 --- a/detections/web/zscaler_potentially_abused_file_download.yml +++ b/detections/web/zscaler_potentially_abused_file_download.yml @@ -1,6 +1,6 @@ name: Zscaler Potentially Abused File Download id: b0c21379-f4ba-4bac-a958-897e260f964a -version: 4 +version: 5 date: '2024-11-15' author: Gowthamaraj Rajendran, Rod Soto, Splunk status: production diff --git a/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml b/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml index cad5f20065..abf94751e3 100644 --- a/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml +++ b/detections/web/zscaler_privacy_risk_destinations_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Privacy Risk Destinations Threat Blocked id: 5456bdef-d765-4565-8e1f-61ca027bc50d -version: 4 +version: 5 date: '2024-11-15' author: Gowthamaraj Rajendran, Rod Soto, Splunk status: production diff --git a/detections/web/zscaler_scam_destinations_threat_blocked.yml b/detections/web/zscaler_scam_destinations_threat_blocked.yml index d91cf5e7e9..5c7281924b 100644 --- a/detections/web/zscaler_scam_destinations_threat_blocked.yml +++ b/detections/web/zscaler_scam_destinations_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Scam Destinations Threat Blocked id: a0c21379-f4ba-4bac-a958-897e260f964a -version: 4 +version: 5 date: '2024-11-15' author: Gowthamaraj Rajendran, Rod Soto, Splunk status: production diff --git a/detections/web/zscaler_virus_download_threat_blocked.yml b/detections/web/zscaler_virus_download_threat_blocked.yml index 656efd2fac..f0c094a07c 100644 --- a/detections/web/zscaler_virus_download_threat_blocked.yml +++ b/detections/web/zscaler_virus_download_threat_blocked.yml @@ -1,6 +1,6 @@ name: Zscaler Virus Download threat blocked id: aa19e627-d448-4a31-85cd-82068dec5691 -version: 4 +version: 5 date: '2024-11-15' author: Gowthamaraj Rajendran, Rod Soto, Splunk status: production From 590baee7429830dc91d15e8341a9ac4386a162c9 Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Tue, 25 Feb 2025 14:57:46 -0800 Subject: [PATCH 09/67] create new deprecation file --- .../deprecated_detection_mapping_updated.yml | 902 ++++++++++++++++++ 1 file changed, 902 insertions(+) create mode 100644 deprecated/deprecated_detection_mapping_updated.yml diff --git a/deprecated/deprecated_detection_mapping_updated.yml b/deprecated/deprecated_detection_mapping_updated.yml new file mode 100644 index 0000000000..db32b776a2 --- /dev/null +++ b/deprecated/deprecated_detection_mapping_updated.yml @@ -0,0 +1,902 @@ +detections: + - deprecated_content: ASL AWS Excessive Security Scanning + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen Region + - deprecated_content: First time seen command line argument + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Windows connhost exe started forcefully + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Detect Mimikatz Using Loaded Images + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes Azure detect sensitive role access + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Web Fraud - Anomalous User Clickspeed + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created With Previously Unseen Instance Type + - deprecated_content: EC2 Instance Started With Previously Unseen AMI + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created With Previously Unseen Image + - deprecated_content: Domain Group Discovery With Net + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Group Discovery Via Net + - deprecated_content: Kubernetes AWS detect sensitive role access + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Winword Spawning Windows Script Host + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: "The following analytics was deprecated in favour of a more generic approach. + Where instead of creating specific analytic for every potentially suspicious child + of an office product. We group them by threat level.\nThis would ease management + and false positives tuning." + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Winword Spawning PowerShell + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Attempted Credential Dump From Registry via Reg exe + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: This analytic had some overlap with another one, hence the deprecation. + It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry + Hive Dump Via CommandLine + replacement_content: + - Windows Sensitive Registry Hive Dump Via CommandLine + - deprecated_content: Detect processes used for System Network Configuration Discovery + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Potential System Network Configuration Discovery Activity + - deprecated_content: Execution of File With Spaces Before Extension + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Updated to a new detection name + replacement_content: + - Execution of File with Multiple Extensions + - deprecated_content: EC2 Instance Started In Previously Unseen Region + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created In Previously Unused Region + - deprecated_content: Office Document Spawned Child Process To Download + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned Child Process For Download + - deprecated_content: Detect new API calls from user roles + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud API Calls From Previously Unseen User Roles + - deprecated_content: Cmdline Tool Not Executed In CMD Shell + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Cmdline Tool Execution From Non-Shell Process + - deprecated_content: Linux Auditd Find Private Keys + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Linux Auditd Private Keys and Certificate Enumeration + - deprecated_content: Detect AWS API Activities From Unapproved Accounts + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Monitor DNS For Brand Abuse + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes GCP detect sensitive object access + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes Azure scan fingerprint + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: ASL AWS Password Policy Changes + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: O365 Suspicious Admin Email Forwarding + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - O365 Mailbox Email Forwarding Enabled + - deprecated_content: AWS Cloud Provisioning From Previously Unseen City + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen City + - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Osquery pack - ColdRoot detection + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Windows Modify Registry Reg Restore + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Registry Entries Restored Via Reg + - deprecated_content: Kubernetes GCP detect most active service accounts by pod + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Scheduled tasks used in BadRabbit ransomware + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Updated to a new detection name + replacement_content: + - Scheduled Task Deleted Or Created via CMD + - deprecated_content: Suspicious Rundll32 Rename + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Remote System Discovery with Net + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: "This analytic was focusing on 2 separate and unrelated type of threats + or actions. It was split into other analytics, namely:\r\n\r\nWindows Network + Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive + Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" + replacement_content: + - Windows Network Share Interaction With Net + - deprecated_content: Remote System Discovery with Net + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Sensitive Group Discovery With Net + - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Suspicious Changes to File Associations + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: GCP Detect high risk permissions by resource and account + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Office Product Writing cab or inf + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Dropped Cab or Inf File + - deprecated_content: Identify New User Accounts + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Office Product Spawn CMD Process + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Windows DLL Search Order Hijacking Hunt + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Windows DLL Search Order Hijacking Hunt with Sysmon + - deprecated_content: ASL AWS CreateAccessKey + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - ASL AWS Create Access Key + - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Detect Spike in Security Group Activity + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Security Group API Calls + - deprecated_content: Office Product Spawning BITSAdmin + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Create local admin accounts using net exe + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Create Local Administrator Account Via Net + - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Windows Office Product Spawning MSDT + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned MSDT + - deprecated_content: Detect Spike in AWS API Activity + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - '' + - deprecated_content: Office Product Spawning Windows Script Host + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Prohibited Software On Endpoint + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Attacker Tools On Endpoint + - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen Country + - deprecated_content: Detect Critical Alerts from Security Tools + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: As discussed internally, this analytic was too generic for an analyst to + do anything with it. It was deprecated in favor of the more specific approach + provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender + Incident Alerts. Going forward analytics from leveraging alerts from vendors will + have their specific analytics. + replacement_content: + - Microsoft Defender ATP Alerts + - deprecated_content: Detect Critical Alerts from Security Tools + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Microsoft Defender Incident Alerts + - deprecated_content: Excel Spawning PowerShell + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Office Application Spawn rundll32 process + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Excessive Usage Of Net App + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Excessive Usage Of Net App + - deprecated_content: Elevated Group Discovery With Net + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Sensitive Group Discovery With Net + - deprecated_content: Local Account Discovery with Net + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows User Discovery Via Net + - deprecated_content: Windows Command Shell Fetch Env Variables + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows List ENV Variables Via SET Command From Uncommon Parent + - deprecated_content: Suspicious Email - UBA Anomaly + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Detect web traffic to dynamic domain providers + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Updated to use a different log source + replacement_content: + - Detect hosts connecting to dynamic domain providers + - deprecated_content: Okta Failed SSO Attempts + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Unauthorized Access to Application + - deprecated_content: Kubernetes AWS detect RBAC authorization by account + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Remote Registry Key modifications + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: O365 Suspicious User Email Forwarding + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - O365 Mailbox Email Forwarding Enabled + - deprecated_content: Office Product Spawning MSHTA + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Kubernetes AWS detect most active service accounts by pod + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Correlation by Repository and Risk + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the datamodel + replacement_content: + - Risk Rule for Dev Sec Ops by Repository + - deprecated_content: Kubernetes Azure detect RBAC authorization by account + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Clients Connecting to Multiple DNS Servers + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Excessive Service Stop Attempt + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Excessive Service Stop Attempt + - deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Users Failing To Authenticate From Ip + - deprecated_content: Suspicious writes to System Volume Information + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Detect new user AWS Console Login + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Detect AWS Console Login by New User + - deprecated_content: Domain Account Discovery With Net App + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: "This analytic was a TTP that looked only for commands that tries to query + info about the users via net user /do. This had a couple of issues, such as triggering + on creation of users via the /add flag etc..\nIt was deprecated in favor of a + more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122" + replacement_content: + - Windows User Discovery Via Net + - deprecated_content: Detection of DNS Tunnels + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2 + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Office Document Creating Schedule Task + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Loading Taskschd DLL + - deprecated_content: Okta Account Locked Out + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Accounts Locked Out + - deprecated_content: Unsuccessful Netbackup backups + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703 + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Updated to a new detection name + replacement_content: + - Detect Mimikatz With PowerShell Script Block Logging + - deprecated_content: Winword Spawning Cmd + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: GCP Kubernetes cluster scan detection + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Kubernetes Scanning by Unauthenticated IP Address + - deprecated_content: Kubernetes GCP detect suspicious kubectl calls + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: gcp detect oauth token abuse + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Correlation by User and Risk + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the datamodel + replacement_content: + - Risk Rule for Dev Sec Ops by Repository + - deprecated_content: Processes created by netsh + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Updated to a new detection name + replacement_content: + - Processes launching netsh + - deprecated_content: Office Product Spawning Wmic + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Extraction of Registry Hives + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Sensitive Registry Hive Dump Via CommandLine + - deprecated_content: Attempt To Stop Security Service + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Attempt To Stop Security Service + - deprecated_content: Windows MSIExec With Network Connections + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows HTTP Network Communication From MSIExec + - deprecated_content: Windows Query Registry Reg Save + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Registry Entries Exported Via Reg + - deprecated_content: Cloud Network Access Control List Deleted + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - AWS Network Access Control List Deleted + - deprecated_content: O365 Suspicious Rights Delegation + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - O365 Elevated Mailbox Permission Assigned + - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Reg exe used to hide files directories via registry keys + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Detect Long DNS TXT Record Response + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Password Policy Discovery with Net + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Password Policy Discovery with Net + - deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen IP Address + - deprecated_content: Network Connection Discovery With Net + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Network Connection Discovery Via Net + - deprecated_content: Kubernetes Azure detect suspicious kubectl calls + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes GCP detect sensitive role access + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Detect Webshell Exploit Behavior + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Suspicious Child Process Spawned From WebServer + - deprecated_content: DNS record changed + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Unsigned Image Loaded by LSASS + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - '' + - deprecated_content: Detect USB device insertion + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Windows Network Share Interaction With Net + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Network Share Interaction Via Net + - deprecated_content: Account Discovery With Net App + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: This analytic was a TTP that focused on unrelated things and called account + discovery. Since there were other detection that overlapped with it. I choose + to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 + / Windows Excessive Usage Of Net App. + replacement_content: + - Windows Excessive Usage Of Net App + - deprecated_content: Change Default File Association + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows New Default File Association Value Set + - deprecated_content: Windows Lateral Tool Transfer RemCom + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Updated to a new detection name + replacement_content: + - Windows Service Execution RemCom + - deprecated_content: Office Document Executing Macro Code + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Loading VBE7 DLL + - deprecated_content: Okta Account Lockout Events + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Accounts Locked Out + - deprecated_content: Abnormally High AWS Instances Launched by User + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Instances Launched + - deprecated_content: EC2 Instance Modified With Previously Unseen User + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud API Calls From Previously Unseen User Roles + - deprecated_content: Windows Valid Account With Never Expires Password + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Set Account Password Policy To Unlimited Via Net + - deprecated_content: Windows hosts file modification + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: MSHTML Module Load in Office Product + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Loaded MSHTML Module + - deprecated_content: Abnormally High AWS Instances Terminated by User + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Instances Destroyed + - deprecated_content: Web Fraud - Account Harvesting + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Office Spawning Control + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned Control + - deprecated_content: Detect Activity Related to Pass the Hash Attacks + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Deleting Of Net Users + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows User Deletion Via Net + - deprecated_content: Suspicious File Write + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - '' + - deprecated_content: AWS EKS Kubernetes cluster sensitive object access + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Kubernetes Abuse of Secret by Unusual Location + - deprecated_content: Spectre and Meltdown Vulnerable Systems + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: EC2 Instance Started With Previously Unseen User + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created By Previously Unseen User + - deprecated_content: Office Product Spawning CertUtil + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Kubernetes GCP detect RBAC authorizations by account + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Office Application Drop Executable + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Dropped Uncommon File + - deprecated_content: Kubernetes Azure active service accounts by pod namespace + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes Azure pod scan fingerprint + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Detect Spike in Network ACL Activity + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Infrastructure API Calls + - deprecated_content: Suspicious Powershell Command-Line Arguments + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Malicious PowerShell Process - Encoded Command + - deprecated_content: Office Application Spawn Regsvr32 process + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Detect API activity from users without MFA + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - AWS Successful Single-Factor Authentication + - deprecated_content: Kubernetes Azure detect sensitive object access + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Web Fraud - Password Sharing Across Accounts + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Disabling Net User Account + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows User Disabled Via Net + - deprecated_content: GCP Detect accounts with high risk roles by project + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Extended Period Without Successful Netbackup Backups + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: [] + - deprecated_content: Office Product Spawning Rundll32 with no DLL + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned Rundll32 With No DLL + - deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta ThreatInsight Threat Detected + - deprecated_content: Net Localgroup Discovery + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 + / Windows Group Discovery Via Net + replacement_content: + - Windows Group Discovery Via Net + - deprecated_content: Uncommon Processes On Endpoint + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: '' + replacement_content: + - Attacker Tools On Endpoint + - deprecated_content: Dump LSASS via procdump Rename + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Updated to a new detection name + replacement_content: + - Dump LSASS via procdump + - deprecated_content: Okta Two or More Rejected Okta Pushes + deprecated_in_version: 5.0.2 + deprecated_date: '2025-03-07' + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Failed MFA Requests For User From 1bda87e60c635147b048d255c66743395d97f6c7 Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Tue, 25 Feb 2025 16:46:41 -0800 Subject: [PATCH 10/67] fix format of deprecated file again --- .../deprecated_detection_mapping_updated.yml | 616 +++++++++--------- 1 file changed, 308 insertions(+), 308 deletions(-) diff --git a/deprecated/deprecated_detection_mapping_updated.yml b/deprecated/deprecated_detection_mapping_updated.yml index db32b776a2..322dea112d 100644 --- a/deprecated/deprecated_detection_mapping_updated.yml +++ b/deprecated/deprecated_detection_mapping_updated.yml @@ -1,69 +1,69 @@ detections: - deprecated_content: ASL AWS Excessive Security Scanning - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen Region - deprecated_content: First time seen command line argument - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Windows connhost exe started forcefully - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Detect Mimikatz Using Loaded Images - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Kubernetes Azure detect sensitive role access - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Web Fraud - Anomalous User Clickspeed - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created With Previously Unseen Instance Type - deprecated_content: EC2 Instance Started With Previously Unseen AMI - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created With Previously Unseen Image - deprecated_content: Domain Group Discovery With Net - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Group Discovery Via Net - deprecated_content: Kubernetes AWS detect sensitive role access - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Winword Spawning Windows Script Host - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: "The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level.\nThis would ease management @@ -71,137 +71,137 @@ detections: replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Winword Spawning PowerShell - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Attempted Credential Dump From Registry via Reg exe - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine replacement_content: - Windows Sensitive Registry Hive Dump Via CommandLine - deprecated_content: Detect processes used for System Network Configuration Discovery - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Potential System Network Configuration Discovery Activity - deprecated_content: Execution of File With Spaces Before Extension - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Execution of File with Multiple Extensions - deprecated_content: EC2 Instance Started In Previously Unseen Region - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created In Previously Unused Region - deprecated_content: Office Document Spawned Child Process To Download - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Child Process For Download - deprecated_content: Detect new API calls from user roles - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud API Calls From Previously Unseen User Roles - deprecated_content: Cmdline Tool Not Executed In CMD Shell - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Cmdline Tool Execution From Non-Shell Process - deprecated_content: Linux Auditd Find Private Keys - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Linux Auditd Private Keys and Certificate Enumeration - deprecated_content: Detect AWS API Activities From Unapproved Accounts - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Monitor DNS For Brand Abuse - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Kubernetes GCP detect sensitive object access - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Kubernetes Azure scan fingerprint - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: ASL AWS Password Policy Changes - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: O365 Suspicious Admin Email Forwarding - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Mailbox Email Forwarding Enabled - deprecated_content: AWS Cloud Provisioning From Previously Unseen City - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen City - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Osquery pack - ColdRoot detection - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Windows Modify Registry Reg Restore - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Registry Entries Restored Via Reg - deprecated_content: Kubernetes GCP detect most active service accounts by pod - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Scheduled tasks used in BadRabbit ransomware - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Scheduled Task Deleted Or Created via CMD - deprecated_content: Suspicious Rundll32 Rename - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Remote System Discovery with Net - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: "This analytic was focusing on 2 separate and unrelated type of threats or actions. It was split into other analytics, namely:\r\n\r\nWindows Network Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive @@ -209,120 +209,119 @@ detections: replacement_content: - Windows Network Share Interaction With Net - deprecated_content: Remote System Discovery with Net - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Sensitive Group Discovery With Net - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Suspicious Changes to File Associations - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: GCP Detect high risk permissions by resource and account - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Office Product Writing cab or inf - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Dropped Cab or Inf File - deprecated_content: Identify New User Accounts - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Office Product Spawn CMD Process - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Windows DLL Search Order Hijacking Hunt - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Windows DLL Search Order Hijacking Hunt with Sysmon - deprecated_content: ASL AWS CreateAccessKey - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - ASL AWS Create Access Key - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Detect Spike in Security Group Activity - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Security Group API Calls - deprecated_content: Office Product Spawning BITSAdmin - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Create local admin accounts using net exe - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Create Local Administrator Account Via Net - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Windows Office Product Spawning MSDT - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned MSDT - deprecated_content: Detect Spike in AWS API Activity - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' - replacement_content: - - '' + replacement_content: [] - deprecated_content: Office Product Spawning Windows Script Host - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Prohibited Software On Endpoint - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Attacker Tools On Endpoint - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen Country - deprecated_content: Detect Critical Alerts from Security Tools - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender @@ -331,142 +330,142 @@ detections: replacement_content: - Microsoft Defender ATP Alerts - deprecated_content: Detect Critical Alerts from Security Tools - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Microsoft Defender Incident Alerts - deprecated_content: Excel Spawning PowerShell - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Office Application Spawn rundll32 process - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Excessive Usage Of Net App - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Excessive Usage Of Net App - deprecated_content: Elevated Group Discovery With Net - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Sensitive Group Discovery With Net - deprecated_content: Local Account Discovery with Net - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows User Discovery Via Net - deprecated_content: Windows Command Shell Fetch Env Variables - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows List ENV Variables Via SET Command From Uncommon Parent - deprecated_content: Suspicious Email - UBA Anomaly - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Detect web traffic to dynamic domain providers - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Updated to use a different log source replacement_content: - Detect hosts connecting to dynamic domain providers - deprecated_content: Okta Failed SSO Attempts - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Unauthorized Access to Application - deprecated_content: Kubernetes AWS detect RBAC authorization by account - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Remote Registry Key modifications - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: O365 Suspicious User Email Forwarding - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Mailbox Email Forwarding Enabled - deprecated_content: Office Product Spawning MSHTA - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Kubernetes AWS detect most active service accounts by pod - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Correlation by Repository and Risk - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the datamodel replacement_content: - Risk Rule for Dev Sec Ops by Repository - deprecated_content: Kubernetes Azure detect RBAC authorization by account - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Clients Connecting to Multiple DNS Servers - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Excessive Service Stop Attempt - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Excessive Service Stop Attempt - deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Users Failing To Authenticate From Ip - deprecated_content: Suspicious writes to System Volume Information - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Detect new user AWS Console Login - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Detect AWS Console Login by New User - deprecated_content: Domain Account Discovery With Net App - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: "This analytic was a TTP that looked only for commands that tries to query info about the users via net user /do. This had a couple of issues, such as triggering on creation of users via the /add flag etc..\nIt was deprecated in favor of a @@ -474,193 +473,192 @@ detections: replacement_content: - Windows User Discovery Via Net - deprecated_content: Detection of DNS Tunnels - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2 - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Office Document Creating Schedule Task - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Loading Taskschd DLL - deprecated_content: Okta Account Locked Out - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Accounts Locked Out - deprecated_content: Unsuccessful Netbackup backups - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703 - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Detect Mimikatz With PowerShell Script Block Logging - deprecated_content: Winword Spawning Cmd - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: GCP Kubernetes cluster scan detection - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Kubernetes Scanning by Unauthenticated IP Address - deprecated_content: Kubernetes GCP detect suspicious kubectl calls - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: gcp detect oauth token abuse - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Correlation by User and Risk - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the datamodel replacement_content: - Risk Rule for Dev Sec Ops by Repository - deprecated_content: Processes created by netsh - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Processes launching netsh - deprecated_content: Office Product Spawning Wmic - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Extraction of Registry Hives - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Sensitive Registry Hive Dump Via CommandLine - deprecated_content: Attempt To Stop Security Service - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Attempt To Stop Security Service - deprecated_content: Windows MSIExec With Network Connections - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows HTTP Network Communication From MSIExec - deprecated_content: Windows Query Registry Reg Save - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Registry Entries Exported Via Reg - deprecated_content: Cloud Network Access Control List Deleted - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - AWS Network Access Control List Deleted - deprecated_content: O365 Suspicious Rights Delegation - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Elevated Mailbox Permission Assigned - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Reg exe used to hide files directories via registry keys - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Detect Long DNS TXT Record Response - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Password Policy Discovery with Net - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Password Policy Discovery with Net - deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen IP Address - deprecated_content: Network Connection Discovery With Net - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Network Connection Discovery Via Net - deprecated_content: Kubernetes Azure detect suspicious kubectl calls - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Kubernetes GCP detect sensitive role access - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Detect Webshell Exploit Behavior - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Suspicious Child Process Spawned From WebServer - deprecated_content: DNS record changed - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Unsigned Image Loaded by LSASS - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' - replacement_content: - - '' + replacement_content: [] - deprecated_content: Detect USB device insertion - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Windows Network Share Interaction With Net - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Network Share Interaction Via Net - deprecated_content: Account Discovery With Net App - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 @@ -668,235 +666,237 @@ detections: replacement_content: - Windows Excessive Usage Of Net App - deprecated_content: Change Default File Association - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows New Default File Association Value Set - deprecated_content: Windows Lateral Tool Transfer RemCom - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Windows Service Execution RemCom - deprecated_content: Office Document Executing Macro Code - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Loading VBE7 DLL - deprecated_content: Okta Account Lockout Events - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Accounts Locked Out - deprecated_content: Abnormally High AWS Instances Launched by User - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Instances Launched - deprecated_content: EC2 Instance Modified With Previously Unseen User - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud API Calls From Previously Unseen User Roles - deprecated_content: Windows Valid Account With Never Expires Password - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Set Account Password Policy To Unlimited Via Net - deprecated_content: Windows hosts file modification - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: MSHTML Module Load in Office Product - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Loaded MSHTML Module - deprecated_content: Abnormally High AWS Instances Terminated by User - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Instances Destroyed - deprecated_content: Web Fraud - Account Harvesting - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Office Spawning Control - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Control - deprecated_content: Detect Activity Related to Pass the Hash Attacks - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Deleting Of Net Users - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows User Deletion Via Net - deprecated_content: Suspicious File Write - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' - replacement_content: - - '' + replacement_content: [] - deprecated_content: AWS EKS Kubernetes cluster sensitive object access - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Kubernetes Abuse of Secret by Unusual Location - deprecated_content: Spectre and Meltdown Vulnerable Systems - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: EC2 Instance Started With Previously Unseen User - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created By Previously Unseen User - deprecated_content: Office Product Spawning CertUtil - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Kubernetes GCP detect RBAC authorizations by account - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Office Application Drop Executable - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Dropped Uncommon File - deprecated_content: Kubernetes Azure active service accounts by pod namespace - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Kubernetes Azure pod scan fingerprint - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Detect Spike in Network ACL Activity - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Infrastructure API Calls - deprecated_content: Suspicious Powershell Command-Line Arguments - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Malicious PowerShell Process - Encoded Command - deprecated_content: Office Application Spawn Regsvr32 process - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Detect API activity from users without MFA - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - AWS Successful Single-Factor Authentication - deprecated_content: Kubernetes Azure detect sensitive object access - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Web Fraud - Password Sharing Across Accounts - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Disabling Net User Account - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows User Disabled Via Net - deprecated_content: GCP Detect accounts with high risk roles by project - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Extended Period Without Successful Netbackup Backups - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: [] - deprecated_content: Office Product Spawning Rundll32 with no DLL - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Rundll32 With No DLL - deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta ThreatInsight Threat Detected - deprecated_content: Net Localgroup Discovery - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net replacement_content: - Windows Group Discovery Via Net - deprecated_content: Uncommon Processes On Endpoint - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: '' replacement_content: - Attacker Tools On Endpoint - deprecated_content: Dump LSASS via procdump Rename - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Dump LSASS via procdump - deprecated_content: Okta Two or More Rejected Okta Pushes - deprecated_in_version: 5.0.2 - deprecated_date: '2025-03-07' + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Failed MFA Requests For User +baselines: [] +investigations: [] +stories: [] \ No newline at end of file From 60b9b728c57cdd2f5ad3a14cca9e9d7e62de5e2e Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Tue, 25 Feb 2025 16:54:49 -0800 Subject: [PATCH 11/67] fix file names --- deprecated/deprecated_detection_mapping.yml | 2162 +++++++---------- .../deprecated_detection_mapping_updated.yml | 902 ------- 2 files changed, 902 insertions(+), 2162 deletions(-) delete mode 100644 deprecated/deprecated_detection_mapping_updated.yml diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index ca0e64dcb3..322dea112d 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -1,1260 +1,902 @@ -- deprecated_name: ASL AWS Excessive Security Scanning - deprecated_id: ff2bfdbc-65b7-4434-8f08-d55761d1d446 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: AWS Cloud Provisioning From Previously Unseen Region - deprecated_id: 7971d3df-da82-4648-a6e5-b5637bea5253 - replacement_name: Cloud Provisioning Activity From Previously Unseen Region - replacement_id: 5aba1860-9617-4af9-b19d-aecac16fe4f2 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: First time seen command line argument - deprecated_id: a1b6e73f-98d5-470f-99ac-77aacd578473 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Windows connhost exe started forcefully - deprecated_id: c114aaca-68ee-41c2-ad8c-32bf21db8769 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Detect Mimikatz Using Loaded Images - deprecated_id: 29e307ba-40af-4ab2-91b2-3c6b392bbba0 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Kubernetes Azure detect sensitive role access - deprecated_id: f27349e5-1641-4f6a-9e68-30402be0ad4c - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Web Fraud - Anomalous User Clickspeed - deprecated_id: 31337bbb-bc22-4752-b599-ef192df2dc7a - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: EC2 Instance Started With Previously Unseen Instance Type - deprecated_id: 65541c80-03c7-4e05-83c8-1dcd57a2e1ad - replacement_name: Cloud Compute Instance Created With Previously Unseen Instance - Type - replacement_id: c6ddbf53-9715-49f3-bb4c-fb2e8a309cda - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: EC2 Instance Started With Previously Unseen AMI - deprecated_id: 347ec301-601b-48b9-81aa-9ddf9c829dd3 - replacement_name: Cloud Compute Instance Created With Previously Unseen Image - replacement_id: bc24922d-987c-4645-b288-f8c73ec194c4 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Domain Group Discovery With Net - deprecated_id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349 - replacement_name: Windows Group Discovery Via Net - replacement_id: c5c8e0f3-147a-43da-bf04-4cfaec27dc44 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Kubernetes AWS detect sensitive role access - deprecated_id: b6013a7b-85e0-4a45-b051-10b252d69569 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Winword Spawning Windows Script Host - deprecated_id: 637e1b5c-9be1-11eb-9c32-acde48001122 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: 'The following analytics was deprecated in favour of a more generic approach. - Where instead of creating specific analytic for every potentially suspicious child - of an office product. We group them by threat level. - - This would ease management and false positives tuning.' -- deprecated_name: Winword Spawning PowerShell - deprecated_id: b2c950b8-9be2-11eb-8658-acde48001122 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Attempted Credential Dump From Registry via Reg exe - deprecated_id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911 - replacement_name: Windows Sensitive Registry Hive Dump Via CommandLine - replacement_id: 8bbb7d58-b360-11eb-ba21-acde48001122 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: This analytic had some overlap with another one, hence the deprecation. - It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry - Hive Dump Via CommandLine -- deprecated_name: Detect processes used for System Network Configuration Discovery - deprecated_id: a51bfe1a-94f0-48cc-b1e4-16ae10145893 - replacement_name: Potential System Network Configuration Discovery Activity - replacement_id: 3f0b95e3-3195-46ac-bea3-84fb59e7fac5 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Execution of File With Spaces Before Extension - deprecated_id: ab0353e6-a956-420b-b724-a8b4846d5d5a - replacement_name: Execution of File with Multiple Extensions - replacement_id: b06a555e-dce0-417d-a2eb-28a5d8d66ef7 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Updated to a new detection name -- deprecated_name: EC2 Instance Started In Previously Unseen Region - deprecated_id: ada0f478-84a8-4641-a3f3-d82362d6fd75 - replacement_name: Cloud Compute Instance Created In Previously Unused Region - replacement_id: fa4089e2-50e3-40f7-8469-d2cc1564ca59 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Office Document Spawned Child Process To Download - deprecated_id: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3 - replacement_name: Windows Office Product Spawned Child Process For Download - replacement_id: f02b64b8-cbea-4f75-bf77-7a05111566b1 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Detect new API calls from user roles - deprecated_id: 22773e84-bac0-4595-b086-20d3f335b4f1 - replacement_name: Cloud API Calls From Previously Unseen User Roles - replacement_id: 2181ad1f-1e73-4d0c-9780-e8880482a08f - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Cmdline Tool Not Executed In CMD Shell - deprecated_id: 6c3f7dd8-153c-11ec-ac2d-acde48001122 - replacement_name: Windows Cmdline Tool Execution From Non-Shell Process - replacement_id: 2afa393f-b88d-41b7-9793-623c93a2dfde - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Linux Auditd Find Private Keys - deprecated_id: 80bb9988-190b-4ee0-a3c3-509545a8f678 - replacement_name: Linux Auditd Private Keys and Certificate Enumeration - replacement_id: 892eb674-3344-4143-8e52-4775b1daf3f1 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Detect AWS API Activities From Unapproved Accounts - deprecated_id: ada0f478-84a8-4641-a3f1-d82362d4bd55 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Monitor DNS For Brand Abuse - deprecated_id: 24dd17b1-e2fb-4c31-878c-d4f746595bfa - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Kubernetes GCP detect sensitive object access - deprecated_id: bdb6d596-86a0-4aba-8369-418ae8b9963a - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Kubernetes Azure scan fingerprint - deprecated_id: c5e5bd5c-1013-4841-8b23-e7b3253c840a - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: ASL AWS Password Policy Changes - deprecated_id: 5ade5937-11a2-4363-ba6b-39a3ee8d5b1a - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: O365 Suspicious Admin Email Forwarding - deprecated_id: 7f398cfb-918d-41f4-8db8-2e2474e02c28 - replacement_name: O365 Mailbox Email Forwarding Enabled - replacement_id: 0b6bc75c-05d1-4101-9fc3-97e706168f24 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: AWS Cloud Provisioning From Previously Unseen City - deprecated_id: 344a1778-0b25-490c-adb1-de8beddf59cd - replacement_name: Cloud Provisioning Activity From Previously Unseen City - replacement_id: e7ecc5e0-88df-48b9-91af-51104c68f02f - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Kubernetes AWS detect service accounts forbidden failure access - deprecated_id: a6959c57-fa8f-4277-bb86-7c32fba579d5 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Osquery pack - ColdRoot detection - deprecated_id: a6fffe5e-05c3-4c04-badc-887607fbb8dc - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Windows Modify Registry Reg Restore - deprecated_id: d0072bd2-6d73-4c1b-bc77-ded6d2da3a4e - replacement_name: Windows Registry Entries Restored Via Reg - replacement_id: a17af481-e2ad-494c-9da6-afb4d243a019 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Kubernetes GCP detect most active service accounts by pod - deprecated_id: 7f5c2779-88a0-4824-9caa-0f606c8f260f - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Scheduled tasks used in BadRabbit ransomware - deprecated_id: 1297fb80-f42a-4b4a-9c8b-78c066437cf6 - replacement_name: Scheduled Task Deleted Or Created via CMD - replacement_id: d5af132c-7c17-439c-9d31-13d55340f36c - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Updated to a new detection name -- deprecated_name: Suspicious Rundll32 Rename - deprecated_id: 7360137f-abad-473e-8189-acbdaa34d114 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Remote System Discovery with Net - deprecated_id: 9df16706-04a2-41e2-bbfe-9b38b34409d3 - replacement_name: Windows Network Share Interaction With Net - replacement_id: 4dc3951f-b3f8-4f46-b412-76a483f72277 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: "This analytic was focusing on 2 separate and unrelated type of threats\ - \ or actions. It was split into other analytics, namely:\r\n\r\nWindows Network\ - \ Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows\ - \ Sensitive Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" -- deprecated_name: Remote System Discovery with Net - deprecated_id: 9df16706-04a2-41e2-bbfe-9b38b34409d3 - replacement_name: Windows Sensitive Group Discovery With Net - replacement_id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: DNS Query Requests Resolved by Unauthorized DNS Servers - deprecated_id: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f6 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Suspicious Changes to File Associations - deprecated_id: 1b989a0e-0129-4446-a695-f193a5b746fc - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: GCP Detect high risk permissions by resource and account - deprecated_id: 2e70ef35-2187-431f-aedc-4503dc9b06ba - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Office Product Writing cab or inf - deprecated_id: f48cd1d4-125a-11ec-a447-acde48001122 - replacement_name: Windows Office Product Dropped Cab or Inf File - replacement_id: dbdd251e-dd45-4ec9-a555-f5e151391746 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Identify New User Accounts - deprecated_id: 475b9e27-17e4-46e2-b7e2-648221be3b89 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Office Product Spawn CMD Process - deprecated_id: b8b19420-e892-11eb-9244-acde48001122 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Windows DLL Search Order Hijacking Hunt - deprecated_id: 79c7d0fc-60c7-41be-a616-ccda752efe89 - replacement_name: Windows DLL Search Order Hijacking Hunt with Sysmon - replacement_id: 79c7d1fc-64c7-91be-a616-ccda752efe81 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: ASL AWS CreateAccessKey - deprecated_id: ccb3e4af-23d6-407f-9842-a26212816c9e - replacement_name: ASL AWS Create Access Key - replacement_id: 81a9f2fe-1697-473c-af1d-086b0d8b63c8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Okta ThreatInsight Login Failure with High Unknown users - deprecated_id: 632663b0-4562-4aad-abe9-9f621a049738 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Detect Spike in Security Group Activity - deprecated_id: ada0f478-84a8-4641-a3f1-e32372d4bd53 - replacement_name: Abnormally High Number Of Cloud Security Group API Calls - replacement_id: d4dfb7f3-7a37-498a-b5df-f19334e871af - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Office Product Spawning BITSAdmin - deprecated_id: e8c591f4-a6d7-11eb-8cf7-acde48001122 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Create local admin accounts using net exe - deprecated_id: b89919ed-fe5f-492c-b139-151bb162040e - replacement_name: Windows Create Local Administrator Account Via Net - replacement_id: 2c568c34-bb57-4b43-9d75-19c605b98e70 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Abnormally High AWS Instances Terminated by User - MLTK - deprecated_id: 1c02b86a-cd85-473e-a50b-014a9ac8fe3e - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Windows Office Product Spawning MSDT - deprecated_id: 127eba64-c981-40bf-8589-1830638864a7 - replacement_name: Windows Office Product Spawned MSDT - replacement_id: a3148fad-3734-4b7f-9a71-62f08d39fab1 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Detect Spike in AWS API Activity - deprecated_id: ada0f478-84a8-4641-a3f1-d32362d4bd55 - replacement_name: '' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Office Product Spawning Windows Script Host - deprecated_id: b3628a5b-8d02-42fa-a891-eebf2351cbe1 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Prohibited Software On Endpoint - deprecated_id: a51bfe1a-94f0-48cc-b4e4-b6ae50145893 - replacement_name: Attacker Tools On Endpoint - replacement_id: a51bfe1a-94f0-48cc-b4e4-16a110145893 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: AWS Cloud Provisioning From Previously Unseen Country - deprecated_id: ceb8d3d8-06cb-49eb-beaf-829526e33ff0 - replacement_name: Cloud Provisioning Activity From Previously Unseen Country - replacement_id: 94994255-3acf-4213-9b3f-0494df03bb31 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Detect Critical Alerts from Security Tools - deprecated_id: 483e8a68-f2f7-45be-8fc9-bf725f0e22fd - replacement_name: Microsoft Defender ATP Alerts - replacement_id: 38f034ed-1598-46c8-95e8-14edf05fdf5d - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: As discussed internally, this analytic was too generic for an analyst to - do anything with it. It was deprecated in favor of the more specific approach - provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender - Incident Alerts. Going forward analytics from leveraging alerts from vendors will - have their specific analytics. -- deprecated_name: Detect Critical Alerts from Security Tools - deprecated_id: 483e8a68-f2f7-45be-8fc9-bf725f0e22fd - replacement_name: Microsoft Defender Incident Alerts - replacement_id: 13435b55-afd8-46d4-9045-7d5457f430a5 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Excel Spawning PowerShell - deprecated_id: 42d40a22-9be3-11eb-8f08-acde48001122 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Office Application Spawn rundll32 process - deprecated_id: 958751e4-9c5f-11eb-b103-acde48001122 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Excessive Usage Of Net App - deprecated_id: 45e52536-ae42-11eb-b5c6-acde48001122 - replacement_name: Windows Excessive Usage Of Net App - replacement_id: 355ba810-0a20-4215-8485-9ce3f87f2e38 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Elevated Group Discovery With Net - deprecated_id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a - replacement_name: Windows Sensitive Group Discovery With Net - replacement_id: d9eb7cda-5622-4722-bc88-7f2442f4b5af - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Local Account Discovery with Net - deprecated_id: 5d0d4830-0133-11ec-bae3-acde48001122 - replacement_name: Windows User Discovery Via Net - replacement_id: 7742987e-88c1-476b-a626-a869e088ab72 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Windows Command Shell Fetch Env Variables - deprecated_id: 048839e4-1eaa-43ff-8a22-86d17f6fcc13 - replacement_name: Windows List ENV Variables Via SET Command From Uncommon Parent - replacement_id: aec157f4-8783-4584-aca6-754c4dc7fba9 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Suspicious Email - UBA Anomaly - deprecated_id: 56e877a6-1455-4479-ad16-0550dc1e33f8 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Detect web traffic to dynamic domain providers - deprecated_id: 134da869-e264-4a8f-8d7e-fcd01c18f301 - replacement_name: Detect hosts connecting to dynamic domain providers - replacement_id: a1e761ac-1344-4dbd-88b2-3f34c912d359 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Updated to use a different log source -- deprecated_name: Okta Failed SSO Attempts - deprecated_id: 371a6545-2618-4032-ad84-93386b8698c5 - replacement_name: Okta Unauthorized Access to Application - replacement_id: 5f661629-9750-4cb9-897c-1f05d6db8727 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Kubernetes AWS detect RBAC authorization by account - deprecated_id: de7264ed-3ed9-4fef-bb01-6eefc87cefe8 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Kubernetes Azure detect service accounts forbidden failure access - deprecated_id: 019690d7-420f-4da0-b320-f27b09961514 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Remote Registry Key modifications - deprecated_id: c9f4b923-f8af-4155-b697-1354f5dcbc5e - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: O365 Suspicious User Email Forwarding - deprecated_id: f8dfe015-dbb3-4569-ba75-b13787e06aa4 - replacement_name: O365 Mailbox Email Forwarding Enabled - replacement_id: 0b6bc75c-05d1-4101-9fc3-97e706168f24 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Office Product Spawning MSHTA - deprecated_id: 6078fa20-a6d2-11eb-b662-acde48001122 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Kubernetes AWS detect most active service accounts by pod - deprecated_id: 5b30b25d-7d32-42d8-95ca-64dfcd9076e6 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Correlation by Repository and Risk - deprecated_id: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687 - replacement_name: Risk Rule for Dev Sec Ops by Repository - replacement_id: 161bc0ca-4651-4c13-9c27-27770660cf67 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the datamodel -- deprecated_name: Kubernetes Azure detect RBAC authorization by account - deprecated_id: 47af7d20-0607-4079-97d7-7a29af58b54e - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Clients Connecting to Multiple DNS Servers - deprecated_id: 74ec6f18-604b-4202-a567-86b2066be3ce - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Excessive Service Stop Attempt - deprecated_id: ae8d3f4a-acd7-11eb-8846-acde48001122 - replacement_name: Windows Excessive Service Stop Attempt - replacement_id: 8f3a614f-6b98-4f7d-82dd-d0df38452a8b - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Multiple Okta Users With Invalid Credentials From The Same IP - deprecated_id: 19cba45f-cad3-4032-8911-0c09e0444552 - replacement_name: Okta Multiple Users Failing To Authenticate From Ip - replacement_id: de365ffa-42f5-46b5-b43f-fa72290b8218 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Suspicious writes to System Volume Information - deprecated_id: cd6297cd-2bdd-4aa1-84aa-5d2f84228fac - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Detect new user AWS Console Login - deprecated_id: ada0f478-84a8-4641-a3f3-d82362dffd75 - replacement_name: Detect AWS Console Login by New User - replacement_id: bc91a8cd-35e7-4bb2-6140-e756cc46fd71 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Domain Account Discovery With Net App - deprecated_id: 98f6a534-04c2-11ec-96b2-acde48001122 - replacement_name: Windows User Discovery Via Net - replacement_id: 5d0d4830-0133-11ec-bae3-acde48001122 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: 'This analytic was a TTP that looked only for commands that tries to query - info about the users via net user /do. This had a couple of issues, such as triggering - on creation of users via the /add flag etc.. - - It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122' -- deprecated_name: Detection of DNS Tunnels - deprecated_id: 104658f4-afdc-499f-9719-17a43f9826f4 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Detect DNS requests to Phishing Sites leveraging EvilGinx2 - deprecated_id: 24dd17b1-e2fb-4c31-878c-d4f226595bfa - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Office Document Creating Schedule Task - deprecated_id: cc8b7b74-9d0f-11eb-8342-acde48001122 - replacement_name: Windows Office Product Loading Taskschd DLL - replacement_id: d7297cfa-1f04-4714-bfbe-3679e0666959 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Okta Account Locked Out - deprecated_id: d650c0ae-bdc5-400e-9f0f-f7aa0a010ef1 - replacement_name: Okta Multiple Accounts Locked Out - replacement_id: a511426e-184f-4de6-8711-cfd2af29d1e1 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Unsuccessful Netbackup backups - deprecated_id: a34aae96-ccf8-4aaa-952c-3ea21444444f - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Detect Mimikatz Via PowerShell And EventCode 4703 - deprecated_id: 98917be2-bfc8-475a-8618-a9bb06575188 - replacement_name: Detect Mimikatz With PowerShell Script Block Logging - replacement_id: 8148c29c-c952-11eb-9255-acde48001122 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Updated to a new detection name -- deprecated_name: Winword Spawning Cmd - deprecated_id: 6fcbaedc-a37b-11eb-956b-acde48001122 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: GCP Kubernetes cluster scan detection - deprecated_id: db5957ec-0144-4c56-b512-9dccbe7a2d26 - replacement_name: Kubernetes Scanning by Unauthenticated IP Address - replacement_id: f9cadf4e-df22-4f4e-a08f-9d3344c2165d - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Kubernetes GCP detect suspicious kubectl calls - deprecated_id: a5bed417-070a-41f2-a1e4-82b6aa281557 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: gcp detect oauth token abuse - deprecated_id: a7e9f7bb-8901-4ad0-8d88-0a4ab07b1972 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Correlation by User and Risk - deprecated_id: 610e12dc-b6fa-4541-825e-4a0b3b6f6773 - replacement_name: Risk Rule for Dev Sec Ops by Repository - replacement_id: 161bc0ca-4651-4c13-9c27-27770660cf67 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the datamodel -- deprecated_name: Processes created by netsh - deprecated_id: b89919ed-fe5f-492c-b139-95dbb162041e - replacement_name: Processes launching netsh - replacement_id: b89919ed-fe5f-492c-b139-95dbb162040e - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Updated to a new detection name -- deprecated_name: Office Product Spawning Wmic - deprecated_id: ffc236d6-a6c9-11eb-95f1-acde48001122 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Extraction of Registry Hives - deprecated_id: 8bbb7d58-b360-11eb-ba21-acde48001122 - replacement_name: Windows Sensitive Registry Hive Dump Via CommandLine - replacement_id: 5aaff29d-0cce-405b-9ee8-5d06b49d045e - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Attempt To Stop Security Service - deprecated_id: c8e349c6-b97c-486e-8949-bd7bcd1f3910 - replacement_name: Windows Attempt To Stop Security Service - replacement_id: 9ed27cea-4e27-4eff-b2c6-aac9e78a7517 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Windows MSIExec With Network Connections - deprecated_id: 827409a1-5393-4d8d-8da4-bbb297c262a7 - replacement_name: Windows HTTP Network Communication From MSIExec - replacement_id: b0fd38c7-f71a-43a2-870e-f3ca06bcdd99 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Windows Query Registry Reg Save - deprecated_id: cbee60c1-b776-456f-83c2-faa56bdbe6c6 - replacement_name: Windows Registry Entries Exported Via Reg - replacement_id: 466379bc-0f47-476c-8202-16ef38112e0d - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Cloud Network Access Control List Deleted - deprecated_id: 021abc51-1862-41dd-ad43-43c739c0a983 - replacement_name: AWS Network Access Control List Deleted - replacement_id: ada0f478-84a8-4641-a3f1-d82362d6fd75 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: O365 Suspicious Rights Delegation - deprecated_id: b25d2973-303e-47c8-bacd-52b61604c6a7 - replacement_name: O365 Elevated Mailbox Permission Assigned - replacement_id: 2246c142-a678-45f8-8546-aaed7e0efd30 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Abnormally High AWS Instances Launched by User - MLTK - deprecated_id: dec41ad5-d579-42cb-b4c6-f5dbb778bbe5 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Reg exe used to hide files directories via registry keys - deprecated_id: 61a7d1e6-f5d4-41d9-a9be-39a1ffe69459 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Detect Long DNS TXT Record Response - deprecated_id: 05437c07-62f5-452e-afdc-04dd44815bb9 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Password Policy Discovery with Net - deprecated_id: 09336538-065a-11ec-8665-acde48001122 - replacement_name: Windows Password Policy Discovery with Net - replacement_id: e52f7865-be78-46bf-b7ed-150fbe447613 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: AWS Cloud Provisioning From Previously Unseen IP Address - deprecated_id: 42e15012-ac14-4801-94f4-f1acbe64880b - replacement_name: Cloud Provisioning Activity From Previously Unseen IP Address - replacement_id: f86a8ec9-b042-45eb-92f4-e9ed1d781078 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Network Connection Discovery With Net - deprecated_id: 640337e5-6e41-4b7f-af06-9d9eab5e1e2d - replacement_name: Windows Network Connection Discovery Via Net - replacement_id: 86a5b949-679b-4197-8d4c-9c180a818c45 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Kubernetes Azure detect suspicious kubectl calls - deprecated_id: 4b6d1ba8-0000-4cec-87e6-6cbbd71651b5 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Kubernetes GCP detect sensitive role access - deprecated_id: a46923f6-36b9-4806-a681-31f314907c30 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Detect Webshell Exploit Behavior - deprecated_id: 22597426-6dbd-49bd-bcdc-4ec19857192f - replacement_name: Windows Suspicious Child Process Spawned From WebServer - replacement_id: 2d4470ef-7158-4b47-b68b-1f7f16382156 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: DNS record changed - deprecated_id: 44d3a43e-dcd5-49f7-8356-5209bb369065 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Unsigned Image Loaded by LSASS - deprecated_id: 56ef054c-76ef-45f9-af4a-a634695dcd65 - replacement_name: '' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Detect USB device insertion - deprecated_id: 104658f4-afdc-499f-9719-17a43f9826f5 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Windows Network Share Interaction With Net - deprecated_id: 4dc3951f-b3f8-4f46-b412-76a483f72277 - replacement_name: Windows Network Share Interaction Via Net - replacement_id: e51fbdb0-0be0-474f-92ea-d289f71a695e - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Account Discovery With Net App - deprecated_id: 339805ce-ac30-11eb-b87d-acde48001122 - replacement_name: Windows Excessive Usage Of Net App - replacement_id: 45e52536-ae42-11eb-b5c6-acde48001122 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: This analytic was a TTP that focused on unrelated things and called account - discovery. Since there were other detection that overlapped with it. I choose - to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 - / Windows Excessive Usage Of Net App. -- deprecated_name: Change Default File Association - deprecated_id: 462d17d8-1f71-11ec-ad07-acde48001122 - replacement_name: Windows New Default File Association Value Set - replacement_id: 7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Windows Lateral Tool Transfer RemCom - deprecated_id: e373a840-5bdc-47ef-b2fd-9cc7aaf387f0 - replacement_name: Windows Service Execution RemCom - replacement_id: 7e3d68db-ea4d-419b-adbd-e14a525ecf09 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Updated to a new detection name -- deprecated_name: Office Document Executing Macro Code - deprecated_id: b12c89bc-9d06-11eb-a592-acde48001122 - replacement_name: Windows Office Product Loading VBE7 DLL - replacement_id: 7cfec906-2697-43f7-898b-83634a051d9a - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Okta Account Lockout Events - deprecated_id: 62b70968-a0a5-4724-8ac4-67871e6f544d - replacement_name: Okta Multiple Accounts Locked Out - replacement_id: a511426e-184f-4de6-8711-cfd2af29d1e1 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Abnormally High AWS Instances Launched by User - deprecated_id: 2a9b80d3-6340-4345-b5ad-290bf5d0dac4 - replacement_name: Abnormally High Number Of Cloud Instances Launched - replacement_id: f2361e9f-3928-496c-a556-120cd4223a65 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: EC2 Instance Modified With Previously Unseen User - deprecated_id: 56f91724-cf3f-4666-84e1-e3712fb41e76 - replacement_name: Cloud API Calls From Previously Unseen User Roles - replacement_id: 2181ad1f-1e73-4d0c-9780-e8880482a08f - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Windows Valid Account With Never Expires Password - deprecated_id: 73a931db-1830-48b3-8296-cd9cfa09c3c8 - replacement_name: Windows Set Account Password Policy To Unlimited Via Net - replacement_id: 11f93009-8083-43fd-82a7-821fcbdc8342 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Windows hosts file modification - deprecated_id: 06a6fc63-a72d-41dc-8736-7e3dd9612116 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: MSHTML Module Load in Office Product - deprecated_id: 5f1c168e-118b-11ec-84ff-acde48001122 - replacement_name: Windows Office Product Loaded MSHTML Module - replacement_id: 4cc015c9-687c-40d2-adcc-46350f66e10c - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Abnormally High AWS Instances Terminated by User - deprecated_id: 8d301246-fccf-45e2-a8e7-3655fd14379c - replacement_name: Abnormally High Number Of Cloud Instances Destroyed - replacement_id: ef629fc9-1583-4590-b62a-f2247fbf7bbf - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Web Fraud - Account Harvesting - deprecated_id: bf1d7b5c-df2f-4249-a401-c09fdc221ddf - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Office Spawning Control - deprecated_id: 053e027c-10c7-11ec-8437-acde48001122 - replacement_name: Windows Office Product Spawned Control - replacement_id: 081c485d-ac8d-4bee-ad4c-525772fead4d - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Detect Activity Related to Pass the Hash Attacks - deprecated_id: f5939373-8054-40ad-8c64-cec478a22a4b - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Deleting Of Net Users - deprecated_id: 1c8c6f66-acce-11eb-aafb-acde48001122 - replacement_name: Windows User Deletion Via Net - replacement_id: b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Suspicious File Write - deprecated_id: 57f76b8a-32f0-42ed-b358-d9fa3ca7bac8 - replacement_name: '' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: AWS EKS Kubernetes cluster sensitive object access - deprecated_id: 7f227943-2196-4d4d-8d6a-ac8cb308e61c - replacement_name: Kubernetes Abuse of Secret by Unusual Location - replacement_id: 40a064c1-4ec1-4381-9e35-61192ba8ef82 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Spectre and Meltdown Vulnerable Systems - deprecated_id: 354be8e0-32cd-4da0-8c47-796de13b60ea - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: EC2 Instance Started With Previously Unseen User - deprecated_id: 22773e84-bac0-4595-b086-20d3f735b4f1 - replacement_name: Cloud Compute Instance Created By Previously Unseen User - replacement_id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Office Product Spawning CertUtil - deprecated_id: 6925fe72-a6d5-11eb-9e17-acde48001122 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Kubernetes GCP detect RBAC authorizations by account - deprecated_id: 99487de3-7192-4b41-939d-fbe9acfb1340 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Office Application Drop Executable - deprecated_id: 73ce70c4-146d-11ec-9184-acde48001122 - replacement_name: Windows Office Product Dropped Uncommon File - replacement_id: 7ac0fced-9eae-4381-a748-90dcd1aa9393 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Kubernetes Azure active service accounts by pod namespace - deprecated_id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Kubernetes Azure pod scan fingerprint - deprecated_id: 86aad3e0-732f-4f66-bbbc-70df448e461d - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Detect Spike in Network ACL Activity - deprecated_id: ada0f478-84a8-4641-a1f1-e32372d4bd53 - replacement_name: Abnormally High Number Of Cloud Infrastructure API Calls - replacement_id: 0840ddf1-8c89-46ff-b730-c8d6722478c0 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Suspicious Powershell Command-Line Arguments - deprecated_id: 2cdb91d2-542c-497f-b252-be495e71f38c - replacement_name: Malicious PowerShell Process - Encoded Command - replacement_id: c4db14d9-7909-48b4-a054-aa14d89dbb19 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Office Application Spawn Regsvr32 process - deprecated_id: 2d9fc90c-f11f-11eb-9300-acde48001122 - replacement_name: Windows Office Product Spawned Uncommon Process - replacement_id: 55d8741c-fa32-4692-8109-410304961eb8 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Detect API activity from users without MFA - deprecated_id: 4d46e8bd-4072-48e4-92db-0325889ef894 - replacement_name: AWS Successful Single-Factor Authentication - replacement_id: a520b1fe-cc9e-4f56-b762-18354594c52f - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Kubernetes Azure detect sensitive object access - deprecated_id: 1bba382b-07fd-4ffa-b390-8002739b76e8 - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Web Fraud - Password Sharing Across Accounts - deprecated_id: 31337a1a-53b9-4e05-96e9-55c934cb71d3 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Disabling Net User Account - deprecated_id: c0325326-acd6-11eb-98c2-acde48001122 - replacement_name: Windows User Disabled Via Net - replacement_id: b0359e05-c87b-4354-83d8-aee0d890243f - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: GCP Detect accounts with high risk roles by project - deprecated_id: 27af8c15-38b0-4408-b339-920170724adb - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Kubernetes GCP detect service accounts forbidden failure access - deprecated_id: 7094808d-432a-48e7-bb3c-77e96c894f3b - replacement_name: '- ' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Extended Period Without Successful Netbackup Backups - deprecated_id: a34aae96-ccf8-4aef-952c-3ea214444440 - replacement_name: '-' - replacement_id: '' - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Office Product Spawning Rundll32 with no DLL - deprecated_id: c661f6be-a38c-11eb-be57-acde48001122 - replacement_name: Windows Office Product Spawned Rundll32 With No DLL - replacement_id: f28e787e-69ca-480e-9f98-ab970e6d4bcc - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Renamed and updated logic -- deprecated_name: Okta ThreatInsight Suspected PasswordSpray Attack - deprecated_id: 25dbad05-6682-4dd5-9ce9-8adecf0d9ae2 - replacement_name: Okta ThreatInsight Threat Detected - replacement_id: 140504ae-5fe2-4d65-b2bc-a211813fbca6 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update -- deprecated_name: Net Localgroup Discovery - deprecated_id: 54f5201e-155b-11ec-a6e2-acde48001122 - replacement_name: Windows Group Discovery Via Net - replacement_id: c5c8e0f3-147a-43da-bf04-4cfaec27dc44 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 - / Windows Group Discovery Via Net -- deprecated_name: Uncommon Processes On Endpoint - deprecated_id: 29ccce64-a10c-4389-a45f-337cb29ba1f7 - replacement_name: Attacker Tools On Endpoint - replacement_id: a51bfe1a-94f0-48cc-b4e4-16a110145893 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: '' -- deprecated_name: Dump LSASS via procdump Rename - deprecated_id: 21276daa-663d-11eb-ae93-0242ac130002 - replacement_name: Dump LSASS via procdump - replacement_id: 3742ebfe-64c2-11eb-ae93-0242ac130002 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Updated to a new detection name -- deprecated_name: Okta Two or More Rejected Okta Pushes - deprecated_id: d93f785e-4c2c-4262-b8c7-12b77a13fd39 - replacement_name: Okta Multiple Failed MFA Requests For User - replacement_id: 826dbaae-a1e6-4c8c-b384-d16898956e73 - date: '2025-01-28' - escu_version: 5.0.0 - migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics - reason: Detections updated to use the new search logic and field names due to the - TA update +detections: + - deprecated_content: ASL AWS Excessive Security Scanning + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen Region + - deprecated_content: First time seen command line argument + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Windows connhost exe started forcefully + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Detect Mimikatz Using Loaded Images + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes Azure detect sensitive role access + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Web Fraud - Anomalous User Clickspeed + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created With Previously Unseen Instance Type + - deprecated_content: EC2 Instance Started With Previously Unseen AMI + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created With Previously Unseen Image + - deprecated_content: Domain Group Discovery With Net + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Group Discovery Via Net + - deprecated_content: Kubernetes AWS detect sensitive role access + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Winword Spawning Windows Script Host + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: "The following analytics was deprecated in favour of a more generic approach. + Where instead of creating specific analytic for every potentially suspicious child + of an office product. We group them by threat level.\nThis would ease management + and false positives tuning." + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Winword Spawning PowerShell + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Attempted Credential Dump From Registry via Reg exe + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: This analytic had some overlap with another one, hence the deprecation. + It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry + Hive Dump Via CommandLine + replacement_content: + - Windows Sensitive Registry Hive Dump Via CommandLine + - deprecated_content: Detect processes used for System Network Configuration Discovery + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Potential System Network Configuration Discovery Activity + - deprecated_content: Execution of File With Spaces Before Extension + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Updated to a new detection name + replacement_content: + - Execution of File with Multiple Extensions + - deprecated_content: EC2 Instance Started In Previously Unseen Region + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created In Previously Unused Region + - deprecated_content: Office Document Spawned Child Process To Download + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned Child Process For Download + - deprecated_content: Detect new API calls from user roles + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud API Calls From Previously Unseen User Roles + - deprecated_content: Cmdline Tool Not Executed In CMD Shell + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Cmdline Tool Execution From Non-Shell Process + - deprecated_content: Linux Auditd Find Private Keys + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Linux Auditd Private Keys and Certificate Enumeration + - deprecated_content: Detect AWS API Activities From Unapproved Accounts + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Monitor DNS For Brand Abuse + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes GCP detect sensitive object access + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes Azure scan fingerprint + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: ASL AWS Password Policy Changes + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: O365 Suspicious Admin Email Forwarding + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - O365 Mailbox Email Forwarding Enabled + - deprecated_content: AWS Cloud Provisioning From Previously Unseen City + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen City + - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Osquery pack - ColdRoot detection + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Windows Modify Registry Reg Restore + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Registry Entries Restored Via Reg + - deprecated_content: Kubernetes GCP detect most active service accounts by pod + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Scheduled tasks used in BadRabbit ransomware + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Updated to a new detection name + replacement_content: + - Scheduled Task Deleted Or Created via CMD + - deprecated_content: Suspicious Rundll32 Rename + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Remote System Discovery with Net + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: "This analytic was focusing on 2 separate and unrelated type of threats + or actions. It was split into other analytics, namely:\r\n\r\nWindows Network + Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive + Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" + replacement_content: + - Windows Network Share Interaction With Net + - deprecated_content: Remote System Discovery with Net + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Sensitive Group Discovery With Net + - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Suspicious Changes to File Associations + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: GCP Detect high risk permissions by resource and account + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Office Product Writing cab or inf + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Dropped Cab or Inf File + - deprecated_content: Identify New User Accounts + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Office Product Spawn CMD Process + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Windows DLL Search Order Hijacking Hunt + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Windows DLL Search Order Hijacking Hunt with Sysmon + - deprecated_content: ASL AWS CreateAccessKey + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - ASL AWS Create Access Key + - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Detect Spike in Security Group Activity + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Security Group API Calls + - deprecated_content: Office Product Spawning BITSAdmin + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Create local admin accounts using net exe + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Create Local Administrator Account Via Net + - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Windows Office Product Spawning MSDT + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned MSDT + - deprecated_content: Detect Spike in AWS API Activity + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Office Product Spawning Windows Script Host + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Prohibited Software On Endpoint + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Attacker Tools On Endpoint + - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen Country + - deprecated_content: Detect Critical Alerts from Security Tools + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: As discussed internally, this analytic was too generic for an analyst to + do anything with it. It was deprecated in favor of the more specific approach + provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender + Incident Alerts. Going forward analytics from leveraging alerts from vendors will + have their specific analytics. + replacement_content: + - Microsoft Defender ATP Alerts + - deprecated_content: Detect Critical Alerts from Security Tools + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Microsoft Defender Incident Alerts + - deprecated_content: Excel Spawning PowerShell + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Office Application Spawn rundll32 process + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Excessive Usage Of Net App + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Excessive Usage Of Net App + - deprecated_content: Elevated Group Discovery With Net + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Sensitive Group Discovery With Net + - deprecated_content: Local Account Discovery with Net + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows User Discovery Via Net + - deprecated_content: Windows Command Shell Fetch Env Variables + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows List ENV Variables Via SET Command From Uncommon Parent + - deprecated_content: Suspicious Email - UBA Anomaly + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Detect web traffic to dynamic domain providers + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Updated to use a different log source + replacement_content: + - Detect hosts connecting to dynamic domain providers + - deprecated_content: Okta Failed SSO Attempts + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Unauthorized Access to Application + - deprecated_content: Kubernetes AWS detect RBAC authorization by account + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Remote Registry Key modifications + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: O365 Suspicious User Email Forwarding + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - O365 Mailbox Email Forwarding Enabled + - deprecated_content: Office Product Spawning MSHTA + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Kubernetes AWS detect most active service accounts by pod + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Correlation by Repository and Risk + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the datamodel + replacement_content: + - Risk Rule for Dev Sec Ops by Repository + - deprecated_content: Kubernetes Azure detect RBAC authorization by account + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Clients Connecting to Multiple DNS Servers + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Excessive Service Stop Attempt + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Excessive Service Stop Attempt + - deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Users Failing To Authenticate From Ip + - deprecated_content: Suspicious writes to System Volume Information + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Detect new user AWS Console Login + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Detect AWS Console Login by New User + - deprecated_content: Domain Account Discovery With Net App + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: "This analytic was a TTP that looked only for commands that tries to query + info about the users via net user /do. This had a couple of issues, such as triggering + on creation of users via the /add flag etc..\nIt was deprecated in favor of a + more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122" + replacement_content: + - Windows User Discovery Via Net + - deprecated_content: Detection of DNS Tunnels + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2 + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Office Document Creating Schedule Task + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Loading Taskschd DLL + - deprecated_content: Okta Account Locked Out + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Accounts Locked Out + - deprecated_content: Unsuccessful Netbackup backups + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703 + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Updated to a new detection name + replacement_content: + - Detect Mimikatz With PowerShell Script Block Logging + - deprecated_content: Winword Spawning Cmd + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: GCP Kubernetes cluster scan detection + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Kubernetes Scanning by Unauthenticated IP Address + - deprecated_content: Kubernetes GCP detect suspicious kubectl calls + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: gcp detect oauth token abuse + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Correlation by User and Risk + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the datamodel + replacement_content: + - Risk Rule for Dev Sec Ops by Repository + - deprecated_content: Processes created by netsh + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Updated to a new detection name + replacement_content: + - Processes launching netsh + - deprecated_content: Office Product Spawning Wmic + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Extraction of Registry Hives + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Sensitive Registry Hive Dump Via CommandLine + - deprecated_content: Attempt To Stop Security Service + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Attempt To Stop Security Service + - deprecated_content: Windows MSIExec With Network Connections + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows HTTP Network Communication From MSIExec + - deprecated_content: Windows Query Registry Reg Save + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Registry Entries Exported Via Reg + - deprecated_content: Cloud Network Access Control List Deleted + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - AWS Network Access Control List Deleted + - deprecated_content: O365 Suspicious Rights Delegation + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - O365 Elevated Mailbox Permission Assigned + - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Reg exe used to hide files directories via registry keys + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Detect Long DNS TXT Record Response + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Password Policy Discovery with Net + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Password Policy Discovery with Net + - deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Provisioning Activity From Previously Unseen IP Address + - deprecated_content: Network Connection Discovery With Net + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Network Connection Discovery Via Net + - deprecated_content: Kubernetes Azure detect suspicious kubectl calls + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes GCP detect sensitive role access + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Detect Webshell Exploit Behavior + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Suspicious Child Process Spawned From WebServer + - deprecated_content: DNS record changed + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Unsigned Image Loaded by LSASS + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Detect USB device insertion + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Windows Network Share Interaction With Net + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Network Share Interaction Via Net + - deprecated_content: Account Discovery With Net App + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: This analytic was a TTP that focused on unrelated things and called account + discovery. Since there were other detection that overlapped with it. I choose + to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 + / Windows Excessive Usage Of Net App. + replacement_content: + - Windows Excessive Usage Of Net App + - deprecated_content: Change Default File Association + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows New Default File Association Value Set + - deprecated_content: Windows Lateral Tool Transfer RemCom + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Updated to a new detection name + replacement_content: + - Windows Service Execution RemCom + - deprecated_content: Office Document Executing Macro Code + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Loading VBE7 DLL + - deprecated_content: Okta Account Lockout Events + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Accounts Locked Out + - deprecated_content: Abnormally High AWS Instances Launched by User + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Instances Launched + - deprecated_content: EC2 Instance Modified With Previously Unseen User + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud API Calls From Previously Unseen User Roles + - deprecated_content: Windows Valid Account With Never Expires Password + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Set Account Password Policy To Unlimited Via Net + - deprecated_content: Windows hosts file modification + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: MSHTML Module Load in Office Product + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Loaded MSHTML Module + - deprecated_content: Abnormally High AWS Instances Terminated by User + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Instances Destroyed + - deprecated_content: Web Fraud - Account Harvesting + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Office Spawning Control + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned Control + - deprecated_content: Detect Activity Related to Pass the Hash Attacks + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Deleting Of Net Users + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows User Deletion Via Net + - deprecated_content: Suspicious File Write + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: AWS EKS Kubernetes cluster sensitive object access + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Kubernetes Abuse of Secret by Unusual Location + - deprecated_content: Spectre and Meltdown Vulnerable Systems + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: EC2 Instance Started With Previously Unseen User + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Cloud Compute Instance Created By Previously Unseen User + - deprecated_content: Office Product Spawning CertUtil + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Kubernetes GCP detect RBAC authorizations by account + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Office Application Drop Executable + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Dropped Uncommon File + - deprecated_content: Kubernetes Azure active service accounts by pod namespace + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes Azure pod scan fingerprint + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Detect Spike in Network ACL Activity + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Abnormally High Number Of Cloud Infrastructure API Calls + - deprecated_content: Suspicious Powershell Command-Line Arguments + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Malicious PowerShell Process - Encoded Command + - deprecated_content: Office Application Spawn Regsvr32 process + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Windows Office Product Spawned Uncommon Process + - deprecated_content: Detect API activity from users without MFA + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - AWS Successful Single-Factor Authentication + - deprecated_content: Kubernetes Azure detect sensitive object access + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Web Fraud - Password Sharing Across Accounts + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Disabling Net User Account + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows User Disabled Via Net + - deprecated_content: GCP Detect accounts with high risk roles by project + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Extended Period Without Successful Netbackup Backups + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Office Product Spawning Rundll32 with no DLL + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Renamed and updated logic + replacement_content: + - Windows Office Product Spawned Rundll32 With No DLL + - deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta ThreatInsight Threat Detected + - deprecated_content: Net Localgroup Discovery + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 + / Windows Group Discovery Via Net + replacement_content: + - Windows Group Discovery Via Net + - deprecated_content: Uncommon Processes On Endpoint + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: + - Attacker Tools On Endpoint + - deprecated_content: Dump LSASS via procdump Rename + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Updated to a new detection name + replacement_content: + - Dump LSASS via procdump + - deprecated_content: Okta Two or More Rejected Okta Pushes + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Detections updated to use the new search logic and field names due to the + TA update + replacement_content: + - Okta Multiple Failed MFA Requests For User +baselines: [] +investigations: [] +stories: [] \ No newline at end of file diff --git a/deprecated/deprecated_detection_mapping_updated.yml b/deprecated/deprecated_detection_mapping_updated.yml deleted file mode 100644 index 322dea112d..0000000000 --- a/deprecated/deprecated_detection_mapping_updated.yml +++ /dev/null @@ -1,902 +0,0 @@ -detections: - - deprecated_content: ASL AWS Excessive Security Scanning - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Provisioning Activity From Previously Unseen Region - - deprecated_content: First time seen command line argument - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Windows connhost exe started forcefully - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Detect Mimikatz Using Loaded Images - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Kubernetes Azure detect sensitive role access - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Web Fraud - Anomalous User Clickspeed - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Compute Instance Created With Previously Unseen Instance Type - - deprecated_content: EC2 Instance Started With Previously Unseen AMI - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Compute Instance Created With Previously Unseen Image - - deprecated_content: Domain Group Discovery With Net - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Group Discovery Via Net - - deprecated_content: Kubernetes AWS detect sensitive role access - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Winword Spawning Windows Script Host - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: "The following analytics was deprecated in favour of a more generic approach. - Where instead of creating specific analytic for every potentially suspicious child - of an office product. We group them by threat level.\nThis would ease management - and false positives tuning." - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: Winword Spawning PowerShell - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: Attempted Credential Dump From Registry via Reg exe - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: This analytic had some overlap with another one, hence the deprecation. - It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry - Hive Dump Via CommandLine - replacement_content: - - Windows Sensitive Registry Hive Dump Via CommandLine - - deprecated_content: Detect processes used for System Network Configuration Discovery - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Potential System Network Configuration Discovery Activity - - deprecated_content: Execution of File With Spaces Before Extension - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Updated to a new detection name - replacement_content: - - Execution of File with Multiple Extensions - - deprecated_content: EC2 Instance Started In Previously Unseen Region - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Compute Instance Created In Previously Unused Region - - deprecated_content: Office Document Spawned Child Process To Download - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Spawned Child Process For Download - - deprecated_content: Detect new API calls from user roles - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud API Calls From Previously Unseen User Roles - - deprecated_content: Cmdline Tool Not Executed In CMD Shell - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Cmdline Tool Execution From Non-Shell Process - - deprecated_content: Linux Auditd Find Private Keys - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Linux Auditd Private Keys and Certificate Enumeration - - deprecated_content: Detect AWS API Activities From Unapproved Accounts - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Monitor DNS For Brand Abuse - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Kubernetes GCP detect sensitive object access - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Kubernetes Azure scan fingerprint - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: ASL AWS Password Policy Changes - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: O365 Suspicious Admin Email Forwarding - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - O365 Mailbox Email Forwarding Enabled - - deprecated_content: AWS Cloud Provisioning From Previously Unseen City - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Provisioning Activity From Previously Unseen City - - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Osquery pack - ColdRoot detection - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Windows Modify Registry Reg Restore - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Registry Entries Restored Via Reg - - deprecated_content: Kubernetes GCP detect most active service accounts by pod - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Scheduled tasks used in BadRabbit ransomware - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Updated to a new detection name - replacement_content: - - Scheduled Task Deleted Or Created via CMD - - deprecated_content: Suspicious Rundll32 Rename - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Remote System Discovery with Net - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: "This analytic was focusing on 2 separate and unrelated type of threats - or actions. It was split into other analytics, namely:\r\n\r\nWindows Network - Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive - Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" - replacement_content: - - Windows Network Share Interaction With Net - - deprecated_content: Remote System Discovery with Net - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Sensitive Group Discovery With Net - - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Suspicious Changes to File Associations - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: GCP Detect high risk permissions by resource and account - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Office Product Writing cab or inf - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Dropped Cab or Inf File - - deprecated_content: Identify New User Accounts - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Office Product Spawn CMD Process - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: Windows DLL Search Order Hijacking Hunt - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Windows DLL Search Order Hijacking Hunt with Sysmon - - deprecated_content: ASL AWS CreateAccessKey - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - ASL AWS Create Access Key - - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Detect Spike in Security Group Activity - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Abnormally High Number Of Cloud Security Group API Calls - - deprecated_content: Office Product Spawning BITSAdmin - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: Create local admin accounts using net exe - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Create Local Administrator Account Via Net - - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Windows Office Product Spawning MSDT - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Spawned MSDT - - deprecated_content: Detect Spike in AWS API Activity - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Office Product Spawning Windows Script Host - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: Prohibited Software On Endpoint - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Attacker Tools On Endpoint - - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Provisioning Activity From Previously Unseen Country - - deprecated_content: Detect Critical Alerts from Security Tools - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: As discussed internally, this analytic was too generic for an analyst to - do anything with it. It was deprecated in favor of the more specific approach - provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender - Incident Alerts. Going forward analytics from leveraging alerts from vendors will - have their specific analytics. - replacement_content: - - Microsoft Defender ATP Alerts - - deprecated_content: Detect Critical Alerts from Security Tools - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Microsoft Defender Incident Alerts - - deprecated_content: Excel Spawning PowerShell - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: Office Application Spawn rundll32 process - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: Excessive Usage Of Net App - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Excessive Usage Of Net App - - deprecated_content: Elevated Group Discovery With Net - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Sensitive Group Discovery With Net - - deprecated_content: Local Account Discovery with Net - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows User Discovery Via Net - - deprecated_content: Windows Command Shell Fetch Env Variables - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows List ENV Variables Via SET Command From Uncommon Parent - - deprecated_content: Suspicious Email - UBA Anomaly - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Detect web traffic to dynamic domain providers - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Updated to use a different log source - replacement_content: - - Detect hosts connecting to dynamic domain providers - - deprecated_content: Okta Failed SSO Attempts - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta Unauthorized Access to Application - - deprecated_content: Kubernetes AWS detect RBAC authorization by account - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Remote Registry Key modifications - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: O365 Suspicious User Email Forwarding - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - O365 Mailbox Email Forwarding Enabled - - deprecated_content: Office Product Spawning MSHTA - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: Kubernetes AWS detect most active service accounts by pod - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Correlation by Repository and Risk - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the datamodel - replacement_content: - - Risk Rule for Dev Sec Ops by Repository - - deprecated_content: Kubernetes Azure detect RBAC authorization by account - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Clients Connecting to Multiple DNS Servers - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Excessive Service Stop Attempt - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Excessive Service Stop Attempt - - deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta Multiple Users Failing To Authenticate From Ip - - deprecated_content: Suspicious writes to System Volume Information - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Detect new user AWS Console Login - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Detect AWS Console Login by New User - - deprecated_content: Domain Account Discovery With Net App - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: "This analytic was a TTP that looked only for commands that tries to query - info about the users via net user /do. This had a couple of issues, such as triggering - on creation of users via the /add flag etc..\nIt was deprecated in favor of a - more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122" - replacement_content: - - Windows User Discovery Via Net - - deprecated_content: Detection of DNS Tunnels - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2 - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Office Document Creating Schedule Task - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Loading Taskschd DLL - - deprecated_content: Okta Account Locked Out - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta Multiple Accounts Locked Out - - deprecated_content: Unsuccessful Netbackup backups - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703 - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Updated to a new detection name - replacement_content: - - Detect Mimikatz With PowerShell Script Block Logging - - deprecated_content: Winword Spawning Cmd - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: GCP Kubernetes cluster scan detection - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Kubernetes Scanning by Unauthenticated IP Address - - deprecated_content: Kubernetes GCP detect suspicious kubectl calls - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: gcp detect oauth token abuse - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Correlation by User and Risk - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the datamodel - replacement_content: - - Risk Rule for Dev Sec Ops by Repository - - deprecated_content: Processes created by netsh - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Updated to a new detection name - replacement_content: - - Processes launching netsh - - deprecated_content: Office Product Spawning Wmic - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: Extraction of Registry Hives - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Sensitive Registry Hive Dump Via CommandLine - - deprecated_content: Attempt To Stop Security Service - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Attempt To Stop Security Service - - deprecated_content: Windows MSIExec With Network Connections - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows HTTP Network Communication From MSIExec - - deprecated_content: Windows Query Registry Reg Save - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Registry Entries Exported Via Reg - - deprecated_content: Cloud Network Access Control List Deleted - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - AWS Network Access Control List Deleted - - deprecated_content: O365 Suspicious Rights Delegation - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - O365 Elevated Mailbox Permission Assigned - - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Reg exe used to hide files directories via registry keys - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Detect Long DNS TXT Record Response - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Password Policy Discovery with Net - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Password Policy Discovery with Net - - deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Provisioning Activity From Previously Unseen IP Address - - deprecated_content: Network Connection Discovery With Net - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Network Connection Discovery Via Net - - deprecated_content: Kubernetes Azure detect suspicious kubectl calls - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Kubernetes GCP detect sensitive role access - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Detect Webshell Exploit Behavior - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Suspicious Child Process Spawned From WebServer - - deprecated_content: DNS record changed - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Unsigned Image Loaded by LSASS - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Detect USB device insertion - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Windows Network Share Interaction With Net - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Network Share Interaction Via Net - - deprecated_content: Account Discovery With Net App - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: This analytic was a TTP that focused on unrelated things and called account - discovery. Since there were other detection that overlapped with it. I choose - to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 - / Windows Excessive Usage Of Net App. - replacement_content: - - Windows Excessive Usage Of Net App - - deprecated_content: Change Default File Association - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows New Default File Association Value Set - - deprecated_content: Windows Lateral Tool Transfer RemCom - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Updated to a new detection name - replacement_content: - - Windows Service Execution RemCom - - deprecated_content: Office Document Executing Macro Code - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Loading VBE7 DLL - - deprecated_content: Okta Account Lockout Events - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta Multiple Accounts Locked Out - - deprecated_content: Abnormally High AWS Instances Launched by User - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Abnormally High Number Of Cloud Instances Launched - - deprecated_content: EC2 Instance Modified With Previously Unseen User - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud API Calls From Previously Unseen User Roles - - deprecated_content: Windows Valid Account With Never Expires Password - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Set Account Password Policy To Unlimited Via Net - - deprecated_content: Windows hosts file modification - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: MSHTML Module Load in Office Product - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Loaded MSHTML Module - - deprecated_content: Abnormally High AWS Instances Terminated by User - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Abnormally High Number Of Cloud Instances Destroyed - - deprecated_content: Web Fraud - Account Harvesting - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Office Spawning Control - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Spawned Control - - deprecated_content: Detect Activity Related to Pass the Hash Attacks - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Deleting Of Net Users - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows User Deletion Via Net - - deprecated_content: Suspicious File Write - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: AWS EKS Kubernetes cluster sensitive object access - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Kubernetes Abuse of Secret by Unusual Location - - deprecated_content: Spectre and Meltdown Vulnerable Systems - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: EC2 Instance Started With Previously Unseen User - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Cloud Compute Instance Created By Previously Unseen User - - deprecated_content: Office Product Spawning CertUtil - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: Kubernetes GCP detect RBAC authorizations by account - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Office Application Drop Executable - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Dropped Uncommon File - - deprecated_content: Kubernetes Azure active service accounts by pod namespace - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Kubernetes Azure pod scan fingerprint - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Detect Spike in Network ACL Activity - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Abnormally High Number Of Cloud Infrastructure API Calls - - deprecated_content: Suspicious Powershell Command-Line Arguments - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Malicious PowerShell Process - Encoded Command - - deprecated_content: Office Application Spawn Regsvr32 process - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Windows Office Product Spawned Uncommon Process - - deprecated_content: Detect API activity from users without MFA - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - AWS Successful Single-Factor Authentication - - deprecated_content: Kubernetes Azure detect sensitive object access - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Web Fraud - Password Sharing Across Accounts - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Disabling Net User Account - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows User Disabled Via Net - - deprecated_content: GCP Detect accounts with high risk roles by project - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Extended Period Without Successful Netbackup Backups - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Office Product Spawning Rundll32 with no DLL - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Renamed and updated logic - replacement_content: - - Windows Office Product Spawned Rundll32 With No DLL - - deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta ThreatInsight Threat Detected - - deprecated_content: Net Localgroup Discovery - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 - / Windows Group Discovery Via Net - replacement_content: - - Windows Group Discovery Via Net - - deprecated_content: Uncommon Processes On Endpoint - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: - - Attacker Tools On Endpoint - - deprecated_content: Dump LSASS via procdump Rename - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Updated to a new detection name - replacement_content: - - Dump LSASS via procdump - - deprecated_content: Okta Two or More Rejected Okta Pushes - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Detections updated to use the new search logic and field names due to the - TA update - replacement_content: - - Okta Multiple Failed MFA Requests For User -baselines: [] -investigations: [] -stories: [] \ No newline at end of file From 2fe8bc5638a8078fce5a9b1a08bbfad99148b9a5 Mon Sep 17 00:00:00 2001 From: research-bot Date: Wed, 26 Feb 2025 10:39:51 -0800 Subject: [PATCH 12/67] remove 152 public detections --- .../abnormally_high_aws_instances_launched_by_user.yml | 0 .../abnormally_high_aws_instances_launched_by_user___mltk.yml | 0 .../abnormally_high_aws_instances_terminated_by_user.yml | 0 .../abnormally_high_aws_instances_terminated_by_user___mltk.yml | 0 .../detections}/account_discovery_with_net_app.yml | 0 .../detections}/asl_aws_createaccesskey.yml | 0 .../detections}/asl_aws_excessive_security_scanning.yml | 0 .../detections}/asl_aws_password_policy_changes.yml | 0 .../detections}/attempt_to_stop_security_service.yml | 0 .../attempted_credential_dump_from_registry_via_reg_exe.yml | 0 .../aws_cloud_provisioning_from_previously_unseen_city.yml | 0 .../aws_cloud_provisioning_from_previously_unseen_country.yml | 0 .../aws_cloud_provisioning_from_previously_unseen_ip_address.yml | 0 .../aws_cloud_provisioning_from_previously_unseen_region.yml | 0 .../aws_eks_kubernetes_cluster_sensitive_object_access.yml | 0 .../detections}/change_default_file_association.yml | 0 .../detections}/clients_connecting_to_multiple_dns_servers.yml | 0 .../detections}/cloud_network_access_control_list_deleted.yml | 0 .../detections}/cmdline_tool_not_executed_in_cmd_shell.yml | 0 .../detections}/correlation_by_repository_and_risk.yml | 0 .../detections}/correlation_by_user_and_risk.yml | 0 .../detections}/create_local_admin_accounts_using_net_exe.yml | 0 .../detections}/deleting_of_net_users.yml | 0 .../detect_activity_related_to_pass_the_hash_attacks.yml | 0 .../detections}/detect_api_activity_from_users_without_mfa.yml | 0 .../detect_aws_api_activities_from_unapproved_accounts.yml | 0 .../detections}/detect_critical_alerts_from_security_tools.yml | 0 ...detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml | 0 .../detections}/detect_long_dns_txt_record_response.yml | 0 .../detections}/detect_mimikatz_using_loaded_images.yml | 0 .../detect_mimikatz_via_powershell_and_eventcode_4703.yml | 0 .../detections}/detect_new_api_calls_from_user_roles.yml | 0 .../detections}/detect_new_user_aws_console_login.yml | 0 ..._processes_used_for_system_network_configuration_discovery.yml | 0 .../detections}/detect_spike_in_aws_api_activity.yml | 0 .../detections}/detect_spike_in_network_acl_activity.yml | 0 .../detections}/detect_spike_in_security_group_activity.yml | 0 .../detections}/detect_usb_device_insertion.yml | 0 .../detect_web_traffic_to_dynamic_domain_providers.yml | 0 .../detections}/detect_webshell_exploit_behavior.yml | 0 .../detections}/detection_of_dns_tunnels.yml | 0 .../detections}/disabling_net_user_account.yml | 0 .../dns_query_requests_resolved_by_unauthorized_dns_servers.yml | 0 .../deprecated => deprecated/detections}/dns_record_changed.yml | 0 .../detections}/domain_account_discovery_with_net_app.yml | 0 .../detections}/domain_group_discovery_with_net.yml | 0 .../detections}/dump_lsass_via_procdump_rename.yml | 0 .../ec2_instance_modified_with_previously_unseen_user.yml | 0 .../ec2_instance_started_in_previously_unseen_region.yml | 0 .../ec2_instance_started_with_previously_unseen_ami.yml | 0 .../ec2_instance_started_with_previously_unseen_instance_type.yml | 0 .../ec2_instance_started_with_previously_unseen_user.yml | 0 .../detections}/elevated_group_discovery_with_net.yml | 0 .../detections}/excel_spawning_powershell.yml | 0 .../detections}/excel_spawning_windows_script_host.yml | 0 .../detections}/excessive_service_stop_attempt.yml | 0 .../detections}/excessive_usage_of_net_app.yml | 0 .../execution_of_file_with_spaces_before_extension.yml | 0 .../extended_period_without_successful_netbackup_backups.yml | 0 .../detections}/extraction_of_registry_hives.yml | 0 .../detections}/first_time_seen_command_line_argument.yml | 0 .../gcp_detect_accounts_with_high_risk_roles_by_project.yml | 0 .../gcp_detect_high_risk_permissions_by_resource_and_account.yml | 0 .../detections}/gcp_detect_oauth_token_abuse.yml | 0 .../detections}/gcp_kubernetes_cluster_scan_detection.yml | 0 .../detections}/identify_new_user_accounts.yml | 0 .../kubernetes_aws_detect_most_active_service_accounts_by_pod.yml | 0 .../kubernetes_aws_detect_rbac_authorization_by_account.yml | 0 .../detections}/kubernetes_aws_detect_sensitive_role_access.yml | 0 ...netes_aws_detect_service_accounts_forbidden_failure_access.yml | 0 .../kubernetes_azure_active_service_accounts_by_pod_namespace.yml | 0 .../kubernetes_azure_detect_rbac_authorization_by_account.yml | 0 .../kubernetes_azure_detect_sensitive_object_access.yml | 0 .../detections}/kubernetes_azure_detect_sensitive_role_access.yml | 0 ...tes_azure_detect_service_accounts_forbidden_failure_access.yml | 0 .../kubernetes_azure_detect_suspicious_kubectl_calls.yml | 0 .../detections}/kubernetes_azure_pod_scan_fingerprint.yml | 0 .../detections}/kubernetes_azure_scan_fingerprint.yml | 0 .../kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml | 0 .../kubernetes_gcp_detect_rbac_authorizations_by_account.yml | 0 .../detections}/kubernetes_gcp_detect_sensitive_object_access.yml | 0 .../detections}/kubernetes_gcp_detect_sensitive_role_access.yml | 0 ...netes_gcp_detect_service_accounts_forbidden_failure_access.yml | 0 .../kubernetes_gcp_detect_suspicious_kubectl_calls.yml | 0 .../detections}/linux_auditd_find_private_keys.yml | 0 .../detections}/local_account_discovery_with_net.yml | 0 .../detections}/monitor_dns_for_brand_abuse.yml | 0 .../detections}/mshtml_module_load_in_office_product.yml | 0 ...tiple_okta_users_with_invalid_credentials_from_the_same_ip.yml | 0 .../detections}/net_localgroup_discovery.yml | 0 .../detections}/network_connection_discovery_with_net.yml | 0 .../detections}/o365_suspicious_admin_email_forwarding.yml | 0 .../detections}/o365_suspicious_rights_delegation.yml | 0 .../detections}/o365_suspicious_user_email_forwarding.yml | 0 .../detections}/office_application_drop_executable.yml | 0 .../detections}/office_application_spawn_regsvr32_process.yml | 0 .../detections}/office_application_spawn_rundll32_process.yml | 0 .../detections}/office_document_creating_schedule_task.yml | 0 .../detections}/office_document_executing_macro_code.yml | 0 .../office_document_spawned_child_process_to_download.yml | 0 .../detections}/office_product_spawn_cmd_process.yml | 0 .../detections}/office_product_spawning_bitsadmin.yml | 0 .../detections}/office_product_spawning_certutil.yml | 0 .../detections}/office_product_spawning_mshta.yml | 0 .../detections}/office_product_spawning_rundll32_with_no_dll.yml | 0 .../detections}/office_product_spawning_windows_script_host.yml | 0 .../detections}/office_product_spawning_wmic.yml | 0 .../detections}/office_product_writing_cab_or_inf.yml | 0 .../detections}/office_spawning_control.yml | 0 .../detections}/okta_account_locked_out.yml | 0 .../detections}/okta_account_lockout_events.yml | 0 .../detections}/okta_failed_sso_attempts.yml | 0 .../okta_threatinsight_login_failure_with_high_unknown_users.yml | 0 .../okta_threatinsight_suspected_passwordspray_attack.yml | 0 .../detections}/okta_two_or_more_rejected_okta_pushes.yml | 0 .../detections}/osquery_pack___coldroot_detection.yml | 0 .../detections}/password_policy_discovery_with_net.yml | 0 .../detections}/processes_created_by_netsh.yml | 0 .../detections}/prohibited_software_on_endpoint.yml | 0 .../reg_exe_used_to_hide_files_directories_via_registry_keys.yml | 0 .../detections}/remote_registry_key_modifications.yml | 0 .../detections}/remote_system_discovery_with_net.yml | 0 .../detections}/scheduled_tasks_used_in_badrabbit_ransomware.yml | 0 .../detections}/spectre_and_meltdown_vulnerable_systems.yml | 0 .../detections}/suspicious_changes_to_file_associations.yml | 0 .../detections}/suspicious_email___uba_anomaly.yml | 0 .../detections}/suspicious_file_write.yml | 0 .../detections}/suspicious_powershell_command_line_arguments.yml | 0 .../detections}/suspicious_rundll32_rename.yml | 0 .../suspicious_writes_to_system_volume_information.yml | 0 .../detections}/uncommon_processes_on_endpoint.yml | 0 .../detections}/unsigned_image_loaded_by_lsass.yml | 0 .../detections}/unsuccessful_netbackup_backups.yml | 0 .../detections}/web_fraud___account_harvesting.yml | 0 .../detections}/web_fraud___anomalous_user_clickspeed.yml | 0 .../detections}/web_fraud___password_sharing_across_accounts.yml | 0 .../detections}/windows_command_shell_fetch_env_variables.yml | 0 .../detections}/windows_connhost_exe_started_forcefully.yml | 0 .../detections}/windows_dll_search_order_hijacking_hunt.yml | 0 .../detections}/windows_hosts_file_modification.yml | 0 .../detections}/windows_lateral_tool_transfer_remcom.yml | 0 .../detections}/windows_modify_registry_reg_restore.yml | 0 .../detections}/windows_msiexec_with_network_connections.yml | 0 .../detections}/windows_network_share_interaction_with_net.yml | 0 .../detections}/windows_office_product_spawning_msdt.yml | 0 .../detections}/windows_query_registry_reg_save.yml | 0 .../windows_service_stop_via_net__and_sc_application.yml | 0 .../windows_valid_account_with_never_expires_password.yml | 0 .../deprecated => deprecated/detections}/winword_spawning_cmd.yml | 0 .../detections}/winword_spawning_powershell.yml | 0 .../detections}/winword_spawning_windows_script_host.yml | 0 151 files changed, 0 insertions(+), 0 deletions(-) rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_launched_by_user.yml (100%) rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_launched_by_user___mltk.yml (100%) rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_terminated_by_user.yml (100%) rename {detections/deprecated => deprecated/detections}/abnormally_high_aws_instances_terminated_by_user___mltk.yml (100%) rename {detections/deprecated => deprecated/detections}/account_discovery_with_net_app.yml (100%) rename {detections/deprecated => deprecated/detections}/asl_aws_createaccesskey.yml (100%) rename {detections/deprecated => deprecated/detections}/asl_aws_excessive_security_scanning.yml (100%) rename {detections/deprecated => deprecated/detections}/asl_aws_password_policy_changes.yml (100%) rename {detections/deprecated => deprecated/detections}/attempt_to_stop_security_service.yml (100%) rename {detections/deprecated => deprecated/detections}/attempted_credential_dump_from_registry_via_reg_exe.yml (100%) rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_city.yml (100%) rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_country.yml (100%) rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_ip_address.yml (100%) rename {detections/deprecated => deprecated/detections}/aws_cloud_provisioning_from_previously_unseen_region.yml (100%) rename {detections/deprecated => deprecated/detections}/aws_eks_kubernetes_cluster_sensitive_object_access.yml (100%) rename {detections/deprecated => deprecated/detections}/change_default_file_association.yml (100%) rename {detections/deprecated => deprecated/detections}/clients_connecting_to_multiple_dns_servers.yml (100%) rename {detections/deprecated => deprecated/detections}/cloud_network_access_control_list_deleted.yml (100%) rename {detections/deprecated => deprecated/detections}/cmdline_tool_not_executed_in_cmd_shell.yml (100%) rename {detections/deprecated => deprecated/detections}/correlation_by_repository_and_risk.yml (100%) rename {detections/deprecated => deprecated/detections}/correlation_by_user_and_risk.yml (100%) rename {detections/deprecated => deprecated/detections}/create_local_admin_accounts_using_net_exe.yml (100%) rename {detections/deprecated => deprecated/detections}/deleting_of_net_users.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_activity_related_to_pass_the_hash_attacks.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_api_activity_from_users_without_mfa.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_aws_api_activities_from_unapproved_accounts.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_critical_alerts_from_security_tools.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_long_dns_txt_record_response.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_mimikatz_using_loaded_images.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_mimikatz_via_powershell_and_eventcode_4703.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_new_api_calls_from_user_roles.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_new_user_aws_console_login.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_processes_used_for_system_network_configuration_discovery.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_spike_in_aws_api_activity.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_spike_in_network_acl_activity.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_spike_in_security_group_activity.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_usb_device_insertion.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_web_traffic_to_dynamic_domain_providers.yml (100%) rename {detections/deprecated => deprecated/detections}/detect_webshell_exploit_behavior.yml (100%) rename {detections/deprecated => deprecated/detections}/detection_of_dns_tunnels.yml (100%) rename {detections/deprecated => deprecated/detections}/disabling_net_user_account.yml (100%) rename {detections/deprecated => deprecated/detections}/dns_query_requests_resolved_by_unauthorized_dns_servers.yml (100%) rename {detections/deprecated => deprecated/detections}/dns_record_changed.yml (100%) rename {detections/deprecated => deprecated/detections}/domain_account_discovery_with_net_app.yml (100%) rename {detections/deprecated => deprecated/detections}/domain_group_discovery_with_net.yml (100%) rename {detections/deprecated => deprecated/detections}/dump_lsass_via_procdump_rename.yml (100%) rename {detections/deprecated => deprecated/detections}/ec2_instance_modified_with_previously_unseen_user.yml (100%) rename {detections/deprecated => deprecated/detections}/ec2_instance_started_in_previously_unseen_region.yml (100%) rename {detections/deprecated => deprecated/detections}/ec2_instance_started_with_previously_unseen_ami.yml (100%) rename {detections/deprecated => deprecated/detections}/ec2_instance_started_with_previously_unseen_instance_type.yml (100%) rename {detections/deprecated => deprecated/detections}/ec2_instance_started_with_previously_unseen_user.yml (100%) rename {detections/deprecated => deprecated/detections}/elevated_group_discovery_with_net.yml (100%) rename {detections/deprecated => deprecated/detections}/excel_spawning_powershell.yml (100%) rename {detections/deprecated => deprecated/detections}/excel_spawning_windows_script_host.yml (100%) rename {detections/deprecated => deprecated/detections}/excessive_service_stop_attempt.yml (100%) rename {detections/deprecated => deprecated/detections}/excessive_usage_of_net_app.yml (100%) rename {detections/deprecated => deprecated/detections}/execution_of_file_with_spaces_before_extension.yml (100%) rename {detections/deprecated => deprecated/detections}/extended_period_without_successful_netbackup_backups.yml (100%) rename {detections/deprecated => deprecated/detections}/extraction_of_registry_hives.yml (100%) rename {detections/deprecated => deprecated/detections}/first_time_seen_command_line_argument.yml (100%) rename {detections/deprecated => deprecated/detections}/gcp_detect_accounts_with_high_risk_roles_by_project.yml (100%) rename {detections/deprecated => deprecated/detections}/gcp_detect_high_risk_permissions_by_resource_and_account.yml (100%) rename {detections/deprecated => deprecated/detections}/gcp_detect_oauth_token_abuse.yml (100%) rename {detections/deprecated => deprecated/detections}/gcp_kubernetes_cluster_scan_detection.yml (100%) rename {detections/deprecated => deprecated/detections}/identify_new_user_accounts.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_rbac_authorization_by_account.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_sensitive_role_access.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_active_service_accounts_by_pod_namespace.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_rbac_authorization_by_account.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_sensitive_object_access.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_sensitive_role_access.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_detect_suspicious_kubectl_calls.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_pod_scan_fingerprint.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_azure_scan_fingerprint.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_rbac_authorizations_by_account.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_sensitive_object_access.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_sensitive_role_access.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml (100%) rename {detections/deprecated => deprecated/detections}/kubernetes_gcp_detect_suspicious_kubectl_calls.yml (100%) rename {detections/deprecated => deprecated/detections}/linux_auditd_find_private_keys.yml (100%) rename {detections/deprecated => deprecated/detections}/local_account_discovery_with_net.yml (100%) rename {detections/deprecated => deprecated/detections}/monitor_dns_for_brand_abuse.yml (100%) rename {detections/deprecated => deprecated/detections}/mshtml_module_load_in_office_product.yml (100%) rename {detections/deprecated => deprecated/detections}/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml (100%) rename {detections/deprecated => deprecated/detections}/net_localgroup_discovery.yml (100%) rename {detections/deprecated => deprecated/detections}/network_connection_discovery_with_net.yml (100%) rename {detections/deprecated => deprecated/detections}/o365_suspicious_admin_email_forwarding.yml (100%) rename {detections/deprecated => deprecated/detections}/o365_suspicious_rights_delegation.yml (100%) rename {detections/deprecated => deprecated/detections}/o365_suspicious_user_email_forwarding.yml (100%) rename {detections/deprecated => deprecated/detections}/office_application_drop_executable.yml (100%) rename {detections/deprecated => deprecated/detections}/office_application_spawn_regsvr32_process.yml (100%) rename {detections/deprecated => deprecated/detections}/office_application_spawn_rundll32_process.yml (100%) rename {detections/deprecated => deprecated/detections}/office_document_creating_schedule_task.yml (100%) rename {detections/deprecated => deprecated/detections}/office_document_executing_macro_code.yml (100%) rename {detections/deprecated => deprecated/detections}/office_document_spawned_child_process_to_download.yml (100%) rename {detections/deprecated => deprecated/detections}/office_product_spawn_cmd_process.yml (100%) rename {detections/deprecated => deprecated/detections}/office_product_spawning_bitsadmin.yml (100%) rename {detections/deprecated => deprecated/detections}/office_product_spawning_certutil.yml (100%) rename {detections/deprecated => deprecated/detections}/office_product_spawning_mshta.yml (100%) rename {detections/deprecated => deprecated/detections}/office_product_spawning_rundll32_with_no_dll.yml (100%) rename {detections/deprecated => deprecated/detections}/office_product_spawning_windows_script_host.yml (100%) rename {detections/deprecated => deprecated/detections}/office_product_spawning_wmic.yml (100%) rename {detections/deprecated => deprecated/detections}/office_product_writing_cab_or_inf.yml (100%) rename {detections/deprecated => deprecated/detections}/office_spawning_control.yml (100%) rename {detections/deprecated => deprecated/detections}/okta_account_locked_out.yml (100%) rename {detections/deprecated => deprecated/detections}/okta_account_lockout_events.yml (100%) rename {detections/deprecated => deprecated/detections}/okta_failed_sso_attempts.yml (100%) rename {detections/deprecated => deprecated/detections}/okta_threatinsight_login_failure_with_high_unknown_users.yml (100%) rename {detections/deprecated => deprecated/detections}/okta_threatinsight_suspected_passwordspray_attack.yml (100%) rename {detections/deprecated => deprecated/detections}/okta_two_or_more_rejected_okta_pushes.yml (100%) rename {detections/deprecated => deprecated/detections}/osquery_pack___coldroot_detection.yml (100%) rename {detections/deprecated => deprecated/detections}/password_policy_discovery_with_net.yml (100%) rename {detections/deprecated => deprecated/detections}/processes_created_by_netsh.yml (100%) rename {detections/deprecated => deprecated/detections}/prohibited_software_on_endpoint.yml (100%) rename {detections/deprecated => deprecated/detections}/reg_exe_used_to_hide_files_directories_via_registry_keys.yml (100%) rename {detections/deprecated => deprecated/detections}/remote_registry_key_modifications.yml (100%) rename {detections/deprecated => deprecated/detections}/remote_system_discovery_with_net.yml (100%) rename {detections/deprecated => deprecated/detections}/scheduled_tasks_used_in_badrabbit_ransomware.yml (100%) rename {detections/deprecated => deprecated/detections}/spectre_and_meltdown_vulnerable_systems.yml (100%) rename {detections/deprecated => deprecated/detections}/suspicious_changes_to_file_associations.yml (100%) rename {detections/deprecated => deprecated/detections}/suspicious_email___uba_anomaly.yml (100%) rename {detections/deprecated => deprecated/detections}/suspicious_file_write.yml (100%) rename {detections/deprecated => deprecated/detections}/suspicious_powershell_command_line_arguments.yml (100%) rename {detections/deprecated => deprecated/detections}/suspicious_rundll32_rename.yml (100%) rename {detections/deprecated => deprecated/detections}/suspicious_writes_to_system_volume_information.yml (100%) rename {detections/deprecated => deprecated/detections}/uncommon_processes_on_endpoint.yml (100%) rename {detections/deprecated => deprecated/detections}/unsigned_image_loaded_by_lsass.yml (100%) rename {detections/deprecated => deprecated/detections}/unsuccessful_netbackup_backups.yml (100%) rename {detections/deprecated => deprecated/detections}/web_fraud___account_harvesting.yml (100%) rename {detections/deprecated => deprecated/detections}/web_fraud___anomalous_user_clickspeed.yml (100%) rename {detections/deprecated => deprecated/detections}/web_fraud___password_sharing_across_accounts.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_command_shell_fetch_env_variables.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_connhost_exe_started_forcefully.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_dll_search_order_hijacking_hunt.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_hosts_file_modification.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_lateral_tool_transfer_remcom.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_modify_registry_reg_restore.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_msiexec_with_network_connections.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_network_share_interaction_with_net.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_office_product_spawning_msdt.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_query_registry_reg_save.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_service_stop_via_net__and_sc_application.yml (100%) rename {detections/deprecated => deprecated/detections}/windows_valid_account_with_never_expires_password.yml (100%) rename {detections/deprecated => deprecated/detections}/winword_spawning_cmd.yml (100%) rename {detections/deprecated => deprecated/detections}/winword_spawning_powershell.yml (100%) rename {detections/deprecated => deprecated/detections}/winword_spawning_windows_script_host.yml (100%) diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml b/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml similarity index 100% rename from detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml rename to deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml b/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml similarity index 100% rename from detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml rename to deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml similarity index 100% rename from detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml rename to deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml similarity index 100% rename from detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml rename to deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml diff --git a/detections/deprecated/account_discovery_with_net_app.yml b/deprecated/detections/account_discovery_with_net_app.yml similarity index 100% rename from detections/deprecated/account_discovery_with_net_app.yml rename to deprecated/detections/account_discovery_with_net_app.yml diff --git a/detections/deprecated/asl_aws_createaccesskey.yml b/deprecated/detections/asl_aws_createaccesskey.yml similarity index 100% rename from detections/deprecated/asl_aws_createaccesskey.yml rename to deprecated/detections/asl_aws_createaccesskey.yml diff --git a/detections/deprecated/asl_aws_excessive_security_scanning.yml b/deprecated/detections/asl_aws_excessive_security_scanning.yml similarity index 100% rename from detections/deprecated/asl_aws_excessive_security_scanning.yml rename to deprecated/detections/asl_aws_excessive_security_scanning.yml diff --git a/detections/deprecated/asl_aws_password_policy_changes.yml b/deprecated/detections/asl_aws_password_policy_changes.yml similarity index 100% rename from detections/deprecated/asl_aws_password_policy_changes.yml rename to deprecated/detections/asl_aws_password_policy_changes.yml diff --git a/detections/deprecated/attempt_to_stop_security_service.yml b/deprecated/detections/attempt_to_stop_security_service.yml similarity index 100% rename from detections/deprecated/attempt_to_stop_security_service.yml rename to deprecated/detections/attempt_to_stop_security_service.yml diff --git a/detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml b/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml similarity index 100% rename from detections/deprecated/attempted_credential_dump_from_registry_via_reg_exe.yml rename to deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml similarity index 100% rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml similarity index 100% rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml similarity index 100% rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml similarity index 100% rename from detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml rename to deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml diff --git a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml similarity index 100% rename from detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml rename to deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml diff --git a/detections/deprecated/change_default_file_association.yml b/deprecated/detections/change_default_file_association.yml similarity index 100% rename from detections/deprecated/change_default_file_association.yml rename to deprecated/detections/change_default_file_association.yml diff --git a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml b/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml similarity index 100% rename from detections/deprecated/clients_connecting_to_multiple_dns_servers.yml rename to deprecated/detections/clients_connecting_to_multiple_dns_servers.yml diff --git a/detections/deprecated/cloud_network_access_control_list_deleted.yml b/deprecated/detections/cloud_network_access_control_list_deleted.yml similarity index 100% rename from detections/deprecated/cloud_network_access_control_list_deleted.yml rename to deprecated/detections/cloud_network_access_control_list_deleted.yml diff --git a/detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml b/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml similarity index 100% rename from detections/deprecated/cmdline_tool_not_executed_in_cmd_shell.yml rename to deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml diff --git a/detections/deprecated/correlation_by_repository_and_risk.yml b/deprecated/detections/correlation_by_repository_and_risk.yml similarity index 100% rename from detections/deprecated/correlation_by_repository_and_risk.yml rename to deprecated/detections/correlation_by_repository_and_risk.yml diff --git a/detections/deprecated/correlation_by_user_and_risk.yml b/deprecated/detections/correlation_by_user_and_risk.yml similarity index 100% rename from detections/deprecated/correlation_by_user_and_risk.yml rename to deprecated/detections/correlation_by_user_and_risk.yml diff --git a/detections/deprecated/create_local_admin_accounts_using_net_exe.yml b/deprecated/detections/create_local_admin_accounts_using_net_exe.yml similarity index 100% rename from detections/deprecated/create_local_admin_accounts_using_net_exe.yml rename to deprecated/detections/create_local_admin_accounts_using_net_exe.yml diff --git a/detections/deprecated/deleting_of_net_users.yml b/deprecated/detections/deleting_of_net_users.yml similarity index 100% rename from detections/deprecated/deleting_of_net_users.yml rename to deprecated/detections/deleting_of_net_users.yml diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml similarity index 100% rename from detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml rename to deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml diff --git a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml b/deprecated/detections/detect_api_activity_from_users_without_mfa.yml similarity index 100% rename from detections/deprecated/detect_api_activity_from_users_without_mfa.yml rename to deprecated/detections/detect_api_activity_from_users_without_mfa.yml diff --git a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml b/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml similarity index 100% rename from detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml rename to deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml diff --git a/detections/deprecated/detect_critical_alerts_from_security_tools.yml b/deprecated/detections/detect_critical_alerts_from_security_tools.yml similarity index 100% rename from detections/deprecated/detect_critical_alerts_from_security_tools.yml rename to deprecated/detections/detect_critical_alerts_from_security_tools.yml diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml similarity index 100% rename from detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml rename to deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml diff --git a/detections/deprecated/detect_long_dns_txt_record_response.yml b/deprecated/detections/detect_long_dns_txt_record_response.yml similarity index 100% rename from detections/deprecated/detect_long_dns_txt_record_response.yml rename to deprecated/detections/detect_long_dns_txt_record_response.yml diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/deprecated/detections/detect_mimikatz_using_loaded_images.yml similarity index 100% rename from detections/deprecated/detect_mimikatz_using_loaded_images.yml rename to deprecated/detections/detect_mimikatz_using_loaded_images.yml diff --git a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml similarity index 100% rename from detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml rename to deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/deprecated/detections/detect_new_api_calls_from_user_roles.yml similarity index 100% rename from detections/deprecated/detect_new_api_calls_from_user_roles.yml rename to deprecated/detections/detect_new_api_calls_from_user_roles.yml diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/deprecated/detections/detect_new_user_aws_console_login.yml similarity index 100% rename from detections/deprecated/detect_new_user_aws_console_login.yml rename to deprecated/detections/detect_new_user_aws_console_login.yml diff --git a/detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml b/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml similarity index 100% rename from detections/deprecated/detect_processes_used_for_system_network_configuration_discovery.yml rename to deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml diff --git a/detections/deprecated/detect_spike_in_aws_api_activity.yml b/deprecated/detections/detect_spike_in_aws_api_activity.yml similarity index 100% rename from detections/deprecated/detect_spike_in_aws_api_activity.yml rename to deprecated/detections/detect_spike_in_aws_api_activity.yml diff --git a/detections/deprecated/detect_spike_in_network_acl_activity.yml b/deprecated/detections/detect_spike_in_network_acl_activity.yml similarity index 100% rename from detections/deprecated/detect_spike_in_network_acl_activity.yml rename to deprecated/detections/detect_spike_in_network_acl_activity.yml diff --git a/detections/deprecated/detect_spike_in_security_group_activity.yml b/deprecated/detections/detect_spike_in_security_group_activity.yml similarity index 100% rename from detections/deprecated/detect_spike_in_security_group_activity.yml rename to deprecated/detections/detect_spike_in_security_group_activity.yml diff --git a/detections/deprecated/detect_usb_device_insertion.yml b/deprecated/detections/detect_usb_device_insertion.yml similarity index 100% rename from detections/deprecated/detect_usb_device_insertion.yml rename to deprecated/detections/detect_usb_device_insertion.yml diff --git a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml b/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml similarity index 100% rename from detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml rename to deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml diff --git a/detections/deprecated/detect_webshell_exploit_behavior.yml b/deprecated/detections/detect_webshell_exploit_behavior.yml similarity index 100% rename from detections/deprecated/detect_webshell_exploit_behavior.yml rename to deprecated/detections/detect_webshell_exploit_behavior.yml diff --git a/detections/deprecated/detection_of_dns_tunnels.yml b/deprecated/detections/detection_of_dns_tunnels.yml similarity index 100% rename from detections/deprecated/detection_of_dns_tunnels.yml rename to deprecated/detections/detection_of_dns_tunnels.yml diff --git a/detections/deprecated/disabling_net_user_account.yml b/deprecated/detections/disabling_net_user_account.yml similarity index 100% rename from detections/deprecated/disabling_net_user_account.yml rename to deprecated/detections/disabling_net_user_account.yml diff --git a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml similarity index 100% rename from detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml rename to deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml diff --git a/detections/deprecated/dns_record_changed.yml b/deprecated/detections/dns_record_changed.yml similarity index 100% rename from detections/deprecated/dns_record_changed.yml rename to deprecated/detections/dns_record_changed.yml diff --git a/detections/deprecated/domain_account_discovery_with_net_app.yml b/deprecated/detections/domain_account_discovery_with_net_app.yml similarity index 100% rename from detections/deprecated/domain_account_discovery_with_net_app.yml rename to deprecated/detections/domain_account_discovery_with_net_app.yml diff --git a/detections/deprecated/domain_group_discovery_with_net.yml b/deprecated/detections/domain_group_discovery_with_net.yml similarity index 100% rename from detections/deprecated/domain_group_discovery_with_net.yml rename to deprecated/detections/domain_group_discovery_with_net.yml diff --git a/detections/deprecated/dump_lsass_via_procdump_rename.yml b/deprecated/detections/dump_lsass_via_procdump_rename.yml similarity index 100% rename from detections/deprecated/dump_lsass_via_procdump_rename.yml rename to deprecated/detections/dump_lsass_via_procdump_rename.yml diff --git a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml b/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml similarity index 100% rename from detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml rename to deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml diff --git a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml b/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml similarity index 100% rename from detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml rename to deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml similarity index 100% rename from detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml rename to deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml similarity index 100% rename from detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml rename to deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml similarity index 100% rename from detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml rename to deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml diff --git a/detections/deprecated/elevated_group_discovery_with_net.yml b/deprecated/detections/elevated_group_discovery_with_net.yml similarity index 100% rename from detections/deprecated/elevated_group_discovery_with_net.yml rename to deprecated/detections/elevated_group_discovery_with_net.yml diff --git a/detections/deprecated/excel_spawning_powershell.yml b/deprecated/detections/excel_spawning_powershell.yml similarity index 100% rename from detections/deprecated/excel_spawning_powershell.yml rename to deprecated/detections/excel_spawning_powershell.yml diff --git a/detections/deprecated/excel_spawning_windows_script_host.yml b/deprecated/detections/excel_spawning_windows_script_host.yml similarity index 100% rename from detections/deprecated/excel_spawning_windows_script_host.yml rename to deprecated/detections/excel_spawning_windows_script_host.yml diff --git a/detections/deprecated/excessive_service_stop_attempt.yml b/deprecated/detections/excessive_service_stop_attempt.yml similarity index 100% rename from detections/deprecated/excessive_service_stop_attempt.yml rename to deprecated/detections/excessive_service_stop_attempt.yml diff --git a/detections/deprecated/excessive_usage_of_net_app.yml b/deprecated/detections/excessive_usage_of_net_app.yml similarity index 100% rename from detections/deprecated/excessive_usage_of_net_app.yml rename to deprecated/detections/excessive_usage_of_net_app.yml diff --git a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml b/deprecated/detections/execution_of_file_with_spaces_before_extension.yml similarity index 100% rename from detections/deprecated/execution_of_file_with_spaces_before_extension.yml rename to deprecated/detections/execution_of_file_with_spaces_before_extension.yml diff --git a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml b/deprecated/detections/extended_period_without_successful_netbackup_backups.yml similarity index 100% rename from detections/deprecated/extended_period_without_successful_netbackup_backups.yml rename to deprecated/detections/extended_period_without_successful_netbackup_backups.yml diff --git a/detections/deprecated/extraction_of_registry_hives.yml b/deprecated/detections/extraction_of_registry_hives.yml similarity index 100% rename from detections/deprecated/extraction_of_registry_hives.yml rename to deprecated/detections/extraction_of_registry_hives.yml diff --git a/detections/deprecated/first_time_seen_command_line_argument.yml b/deprecated/detections/first_time_seen_command_line_argument.yml similarity index 100% rename from detections/deprecated/first_time_seen_command_line_argument.yml rename to deprecated/detections/first_time_seen_command_line_argument.yml diff --git a/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml similarity index 100% rename from detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml rename to deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml diff --git a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml similarity index 100% rename from detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml rename to deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml diff --git a/detections/deprecated/gcp_detect_oauth_token_abuse.yml b/deprecated/detections/gcp_detect_oauth_token_abuse.yml similarity index 100% rename from detections/deprecated/gcp_detect_oauth_token_abuse.yml rename to deprecated/detections/gcp_detect_oauth_token_abuse.yml diff --git a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml b/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml similarity index 100% rename from detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml rename to deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml diff --git a/detections/deprecated/identify_new_user_accounts.yml b/deprecated/detections/identify_new_user_accounts.yml similarity index 100% rename from detections/deprecated/identify_new_user_accounts.yml rename to deprecated/detections/identify_new_user_accounts.yml diff --git a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml similarity index 100% rename from detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml rename to deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml diff --git a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml b/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml similarity index 100% rename from detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml rename to deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml diff --git a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml similarity index 100% rename from detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml rename to deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml diff --git a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml similarity index 100% rename from detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml rename to deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml diff --git a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml similarity index 100% rename from detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml rename to deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml diff --git a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml b/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml similarity index 100% rename from detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml rename to deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml b/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml similarity index 100% rename from detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml rename to deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml similarity index 100% rename from detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml rename to deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml diff --git a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml similarity index 100% rename from detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml rename to deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml diff --git a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml similarity index 100% rename from detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml rename to deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml diff --git a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml b/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml similarity index 100% rename from detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml rename to deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml diff --git a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml b/deprecated/detections/kubernetes_azure_scan_fingerprint.yml similarity index 100% rename from detections/deprecated/kubernetes_azure_scan_fingerprint.yml rename to deprecated/detections/kubernetes_azure_scan_fingerprint.yml diff --git a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml similarity index 100% rename from detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml rename to deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml diff --git a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml similarity index 100% rename from detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml rename to deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml b/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml similarity index 100% rename from detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml rename to deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml similarity index 100% rename from detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml rename to deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml diff --git a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml similarity index 100% rename from detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml rename to deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml diff --git a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml similarity index 100% rename from detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml rename to deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml diff --git a/detections/deprecated/linux_auditd_find_private_keys.yml b/deprecated/detections/linux_auditd_find_private_keys.yml similarity index 100% rename from detections/deprecated/linux_auditd_find_private_keys.yml rename to deprecated/detections/linux_auditd_find_private_keys.yml diff --git a/detections/deprecated/local_account_discovery_with_net.yml b/deprecated/detections/local_account_discovery_with_net.yml similarity index 100% rename from detections/deprecated/local_account_discovery_with_net.yml rename to deprecated/detections/local_account_discovery_with_net.yml diff --git a/detections/deprecated/monitor_dns_for_brand_abuse.yml b/deprecated/detections/monitor_dns_for_brand_abuse.yml similarity index 100% rename from detections/deprecated/monitor_dns_for_brand_abuse.yml rename to deprecated/detections/monitor_dns_for_brand_abuse.yml diff --git a/detections/deprecated/mshtml_module_load_in_office_product.yml b/deprecated/detections/mshtml_module_load_in_office_product.yml similarity index 100% rename from detections/deprecated/mshtml_module_load_in_office_product.yml rename to deprecated/detections/mshtml_module_load_in_office_product.yml diff --git a/detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml similarity index 100% rename from detections/deprecated/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml rename to deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml diff --git a/detections/deprecated/net_localgroup_discovery.yml b/deprecated/detections/net_localgroup_discovery.yml similarity index 100% rename from detections/deprecated/net_localgroup_discovery.yml rename to deprecated/detections/net_localgroup_discovery.yml diff --git a/detections/deprecated/network_connection_discovery_with_net.yml b/deprecated/detections/network_connection_discovery_with_net.yml similarity index 100% rename from detections/deprecated/network_connection_discovery_with_net.yml rename to deprecated/detections/network_connection_discovery_with_net.yml diff --git a/detections/deprecated/o365_suspicious_admin_email_forwarding.yml b/deprecated/detections/o365_suspicious_admin_email_forwarding.yml similarity index 100% rename from detections/deprecated/o365_suspicious_admin_email_forwarding.yml rename to deprecated/detections/o365_suspicious_admin_email_forwarding.yml diff --git a/detections/deprecated/o365_suspicious_rights_delegation.yml b/deprecated/detections/o365_suspicious_rights_delegation.yml similarity index 100% rename from detections/deprecated/o365_suspicious_rights_delegation.yml rename to deprecated/detections/o365_suspicious_rights_delegation.yml diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/deprecated/detections/o365_suspicious_user_email_forwarding.yml similarity index 100% rename from detections/deprecated/o365_suspicious_user_email_forwarding.yml rename to deprecated/detections/o365_suspicious_user_email_forwarding.yml diff --git a/detections/deprecated/office_application_drop_executable.yml b/deprecated/detections/office_application_drop_executable.yml similarity index 100% rename from detections/deprecated/office_application_drop_executable.yml rename to deprecated/detections/office_application_drop_executable.yml diff --git a/detections/deprecated/office_application_spawn_regsvr32_process.yml b/deprecated/detections/office_application_spawn_regsvr32_process.yml similarity index 100% rename from detections/deprecated/office_application_spawn_regsvr32_process.yml rename to deprecated/detections/office_application_spawn_regsvr32_process.yml diff --git a/detections/deprecated/office_application_spawn_rundll32_process.yml b/deprecated/detections/office_application_spawn_rundll32_process.yml similarity index 100% rename from detections/deprecated/office_application_spawn_rundll32_process.yml rename to deprecated/detections/office_application_spawn_rundll32_process.yml diff --git a/detections/deprecated/office_document_creating_schedule_task.yml b/deprecated/detections/office_document_creating_schedule_task.yml similarity index 100% rename from detections/deprecated/office_document_creating_schedule_task.yml rename to deprecated/detections/office_document_creating_schedule_task.yml diff --git a/detections/deprecated/office_document_executing_macro_code.yml b/deprecated/detections/office_document_executing_macro_code.yml similarity index 100% rename from detections/deprecated/office_document_executing_macro_code.yml rename to deprecated/detections/office_document_executing_macro_code.yml diff --git a/detections/deprecated/office_document_spawned_child_process_to_download.yml b/deprecated/detections/office_document_spawned_child_process_to_download.yml similarity index 100% rename from detections/deprecated/office_document_spawned_child_process_to_download.yml rename to deprecated/detections/office_document_spawned_child_process_to_download.yml diff --git a/detections/deprecated/office_product_spawn_cmd_process.yml b/deprecated/detections/office_product_spawn_cmd_process.yml similarity index 100% rename from detections/deprecated/office_product_spawn_cmd_process.yml rename to deprecated/detections/office_product_spawn_cmd_process.yml diff --git a/detections/deprecated/office_product_spawning_bitsadmin.yml b/deprecated/detections/office_product_spawning_bitsadmin.yml similarity index 100% rename from detections/deprecated/office_product_spawning_bitsadmin.yml rename to deprecated/detections/office_product_spawning_bitsadmin.yml diff --git a/detections/deprecated/office_product_spawning_certutil.yml b/deprecated/detections/office_product_spawning_certutil.yml similarity index 100% rename from detections/deprecated/office_product_spawning_certutil.yml rename to deprecated/detections/office_product_spawning_certutil.yml diff --git a/detections/deprecated/office_product_spawning_mshta.yml b/deprecated/detections/office_product_spawning_mshta.yml similarity index 100% rename from detections/deprecated/office_product_spawning_mshta.yml rename to deprecated/detections/office_product_spawning_mshta.yml diff --git a/detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml b/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml similarity index 100% rename from detections/deprecated/office_product_spawning_rundll32_with_no_dll.yml rename to deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml diff --git a/detections/deprecated/office_product_spawning_windows_script_host.yml b/deprecated/detections/office_product_spawning_windows_script_host.yml similarity index 100% rename from detections/deprecated/office_product_spawning_windows_script_host.yml rename to deprecated/detections/office_product_spawning_windows_script_host.yml diff --git a/detections/deprecated/office_product_spawning_wmic.yml b/deprecated/detections/office_product_spawning_wmic.yml similarity index 100% rename from detections/deprecated/office_product_spawning_wmic.yml rename to deprecated/detections/office_product_spawning_wmic.yml diff --git a/detections/deprecated/office_product_writing_cab_or_inf.yml b/deprecated/detections/office_product_writing_cab_or_inf.yml similarity index 100% rename from detections/deprecated/office_product_writing_cab_or_inf.yml rename to deprecated/detections/office_product_writing_cab_or_inf.yml diff --git a/detections/deprecated/office_spawning_control.yml b/deprecated/detections/office_spawning_control.yml similarity index 100% rename from detections/deprecated/office_spawning_control.yml rename to deprecated/detections/office_spawning_control.yml diff --git a/detections/deprecated/okta_account_locked_out.yml b/deprecated/detections/okta_account_locked_out.yml similarity index 100% rename from detections/deprecated/okta_account_locked_out.yml rename to deprecated/detections/okta_account_locked_out.yml diff --git a/detections/deprecated/okta_account_lockout_events.yml b/deprecated/detections/okta_account_lockout_events.yml similarity index 100% rename from detections/deprecated/okta_account_lockout_events.yml rename to deprecated/detections/okta_account_lockout_events.yml diff --git a/detections/deprecated/okta_failed_sso_attempts.yml b/deprecated/detections/okta_failed_sso_attempts.yml similarity index 100% rename from detections/deprecated/okta_failed_sso_attempts.yml rename to deprecated/detections/okta_failed_sso_attempts.yml diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml similarity index 100% rename from detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml rename to deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml similarity index 100% rename from detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml rename to deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml diff --git a/detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml b/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml similarity index 100% rename from detections/deprecated/okta_two_or_more_rejected_okta_pushes.yml rename to deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/deprecated/detections/osquery_pack___coldroot_detection.yml similarity index 100% rename from detections/deprecated/osquery_pack___coldroot_detection.yml rename to deprecated/detections/osquery_pack___coldroot_detection.yml diff --git a/detections/deprecated/password_policy_discovery_with_net.yml b/deprecated/detections/password_policy_discovery_with_net.yml similarity index 100% rename from detections/deprecated/password_policy_discovery_with_net.yml rename to deprecated/detections/password_policy_discovery_with_net.yml diff --git a/detections/deprecated/processes_created_by_netsh.yml b/deprecated/detections/processes_created_by_netsh.yml similarity index 100% rename from detections/deprecated/processes_created_by_netsh.yml rename to deprecated/detections/processes_created_by_netsh.yml diff --git a/detections/deprecated/prohibited_software_on_endpoint.yml b/deprecated/detections/prohibited_software_on_endpoint.yml similarity index 100% rename from detections/deprecated/prohibited_software_on_endpoint.yml rename to deprecated/detections/prohibited_software_on_endpoint.yml diff --git a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml similarity index 100% rename from detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml rename to deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml diff --git a/detections/deprecated/remote_registry_key_modifications.yml b/deprecated/detections/remote_registry_key_modifications.yml similarity index 100% rename from detections/deprecated/remote_registry_key_modifications.yml rename to deprecated/detections/remote_registry_key_modifications.yml diff --git a/detections/deprecated/remote_system_discovery_with_net.yml b/deprecated/detections/remote_system_discovery_with_net.yml similarity index 100% rename from detections/deprecated/remote_system_discovery_with_net.yml rename to deprecated/detections/remote_system_discovery_with_net.yml diff --git a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml b/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml similarity index 100% rename from detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml rename to deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml diff --git a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml b/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml similarity index 100% rename from detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml rename to deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml diff --git a/detections/deprecated/suspicious_changes_to_file_associations.yml b/deprecated/detections/suspicious_changes_to_file_associations.yml similarity index 100% rename from detections/deprecated/suspicious_changes_to_file_associations.yml rename to deprecated/detections/suspicious_changes_to_file_associations.yml diff --git a/detections/deprecated/suspicious_email___uba_anomaly.yml b/deprecated/detections/suspicious_email___uba_anomaly.yml similarity index 100% rename from detections/deprecated/suspicious_email___uba_anomaly.yml rename to deprecated/detections/suspicious_email___uba_anomaly.yml diff --git a/detections/deprecated/suspicious_file_write.yml b/deprecated/detections/suspicious_file_write.yml similarity index 100% rename from detections/deprecated/suspicious_file_write.yml rename to deprecated/detections/suspicious_file_write.yml diff --git a/detections/deprecated/suspicious_powershell_command_line_arguments.yml b/deprecated/detections/suspicious_powershell_command_line_arguments.yml similarity index 100% rename from detections/deprecated/suspicious_powershell_command_line_arguments.yml rename to deprecated/detections/suspicious_powershell_command_line_arguments.yml diff --git a/detections/deprecated/suspicious_rundll32_rename.yml b/deprecated/detections/suspicious_rundll32_rename.yml similarity index 100% rename from detections/deprecated/suspicious_rundll32_rename.yml rename to deprecated/detections/suspicious_rundll32_rename.yml diff --git a/detections/deprecated/suspicious_writes_to_system_volume_information.yml b/deprecated/detections/suspicious_writes_to_system_volume_information.yml similarity index 100% rename from detections/deprecated/suspicious_writes_to_system_volume_information.yml rename to deprecated/detections/suspicious_writes_to_system_volume_information.yml diff --git a/detections/deprecated/uncommon_processes_on_endpoint.yml b/deprecated/detections/uncommon_processes_on_endpoint.yml similarity index 100% rename from detections/deprecated/uncommon_processes_on_endpoint.yml rename to deprecated/detections/uncommon_processes_on_endpoint.yml diff --git a/detections/deprecated/unsigned_image_loaded_by_lsass.yml b/deprecated/detections/unsigned_image_loaded_by_lsass.yml similarity index 100% rename from detections/deprecated/unsigned_image_loaded_by_lsass.yml rename to deprecated/detections/unsigned_image_loaded_by_lsass.yml diff --git a/detections/deprecated/unsuccessful_netbackup_backups.yml b/deprecated/detections/unsuccessful_netbackup_backups.yml similarity index 100% rename from detections/deprecated/unsuccessful_netbackup_backups.yml rename to deprecated/detections/unsuccessful_netbackup_backups.yml diff --git a/detections/deprecated/web_fraud___account_harvesting.yml b/deprecated/detections/web_fraud___account_harvesting.yml similarity index 100% rename from detections/deprecated/web_fraud___account_harvesting.yml rename to deprecated/detections/web_fraud___account_harvesting.yml diff --git a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml b/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml similarity index 100% rename from detections/deprecated/web_fraud___anomalous_user_clickspeed.yml rename to deprecated/detections/web_fraud___anomalous_user_clickspeed.yml diff --git a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml b/deprecated/detections/web_fraud___password_sharing_across_accounts.yml similarity index 100% rename from detections/deprecated/web_fraud___password_sharing_across_accounts.yml rename to deprecated/detections/web_fraud___password_sharing_across_accounts.yml diff --git a/detections/deprecated/windows_command_shell_fetch_env_variables.yml b/deprecated/detections/windows_command_shell_fetch_env_variables.yml similarity index 100% rename from detections/deprecated/windows_command_shell_fetch_env_variables.yml rename to deprecated/detections/windows_command_shell_fetch_env_variables.yml diff --git a/detections/deprecated/windows_connhost_exe_started_forcefully.yml b/deprecated/detections/windows_connhost_exe_started_forcefully.yml similarity index 100% rename from detections/deprecated/windows_connhost_exe_started_forcefully.yml rename to deprecated/detections/windows_connhost_exe_started_forcefully.yml diff --git a/detections/deprecated/windows_dll_search_order_hijacking_hunt.yml b/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml similarity index 100% rename from detections/deprecated/windows_dll_search_order_hijacking_hunt.yml rename to deprecated/detections/windows_dll_search_order_hijacking_hunt.yml diff --git a/detections/deprecated/windows_hosts_file_modification.yml b/deprecated/detections/windows_hosts_file_modification.yml similarity index 100% rename from detections/deprecated/windows_hosts_file_modification.yml rename to deprecated/detections/windows_hosts_file_modification.yml diff --git a/detections/deprecated/windows_lateral_tool_transfer_remcom.yml b/deprecated/detections/windows_lateral_tool_transfer_remcom.yml similarity index 100% rename from detections/deprecated/windows_lateral_tool_transfer_remcom.yml rename to deprecated/detections/windows_lateral_tool_transfer_remcom.yml diff --git a/detections/deprecated/windows_modify_registry_reg_restore.yml b/deprecated/detections/windows_modify_registry_reg_restore.yml similarity index 100% rename from detections/deprecated/windows_modify_registry_reg_restore.yml rename to deprecated/detections/windows_modify_registry_reg_restore.yml diff --git a/detections/deprecated/windows_msiexec_with_network_connections.yml b/deprecated/detections/windows_msiexec_with_network_connections.yml similarity index 100% rename from detections/deprecated/windows_msiexec_with_network_connections.yml rename to deprecated/detections/windows_msiexec_with_network_connections.yml diff --git a/detections/deprecated/windows_network_share_interaction_with_net.yml b/deprecated/detections/windows_network_share_interaction_with_net.yml similarity index 100% rename from detections/deprecated/windows_network_share_interaction_with_net.yml rename to deprecated/detections/windows_network_share_interaction_with_net.yml diff --git a/detections/deprecated/windows_office_product_spawning_msdt.yml b/deprecated/detections/windows_office_product_spawning_msdt.yml similarity index 100% rename from detections/deprecated/windows_office_product_spawning_msdt.yml rename to deprecated/detections/windows_office_product_spawning_msdt.yml diff --git a/detections/deprecated/windows_query_registry_reg_save.yml b/deprecated/detections/windows_query_registry_reg_save.yml similarity index 100% rename from detections/deprecated/windows_query_registry_reg_save.yml rename to deprecated/detections/windows_query_registry_reg_save.yml diff --git a/detections/deprecated/windows_service_stop_via_net__and_sc_application.yml b/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml similarity index 100% rename from detections/deprecated/windows_service_stop_via_net__and_sc_application.yml rename to deprecated/detections/windows_service_stop_via_net__and_sc_application.yml diff --git a/detections/deprecated/windows_valid_account_with_never_expires_password.yml b/deprecated/detections/windows_valid_account_with_never_expires_password.yml similarity index 100% rename from detections/deprecated/windows_valid_account_with_never_expires_password.yml rename to deprecated/detections/windows_valid_account_with_never_expires_password.yml diff --git a/detections/deprecated/winword_spawning_cmd.yml b/deprecated/detections/winword_spawning_cmd.yml similarity index 100% rename from detections/deprecated/winword_spawning_cmd.yml rename to deprecated/detections/winword_spawning_cmd.yml diff --git a/detections/deprecated/winword_spawning_powershell.yml b/deprecated/detections/winword_spawning_powershell.yml similarity index 100% rename from detections/deprecated/winword_spawning_powershell.yml rename to deprecated/detections/winword_spawning_powershell.yml diff --git a/detections/deprecated/winword_spawning_windows_script_host.yml b/deprecated/detections/winword_spawning_windows_script_host.yml similarity index 100% rename from detections/deprecated/winword_spawning_windows_script_host.yml rename to deprecated/detections/winword_spawning_windows_script_host.yml From d99e6ef75b7c1b311d0b89e606e470bbd474c1fa Mon Sep 17 00:00:00 2001 From: research-bot Date: Wed, 26 Feb 2025 11:06:36 -0800 Subject: [PATCH 13/67] other objects --- .../add_prohibited_processes_to_enterprise_security.yml | 0 .../baselines}/baseline_of_api_calls_per_user_arn.yml | 0 ...aseline_of_excessive_aws_instances_launched_by_user___mltk.yml | 0 ...eline_of_excessive_aws_instances_terminated_by_user___mltk.yml | 0 .../previously_seen_api_call_per_user_roles_in_cloudtrail.yml | 0 .../previously_seen_aws_provisioning_activity_sources.yml | 0 .../baselines}/previously_seen_ec2_amis.yml | 0 .../baselines}/previously_seen_ec2_instance_types.yml | 0 .../baselines}/previously_seen_ec2_launches_by_user.yml | 0 .../baselines}/previously_seen_users_in_cloudtrail.yml | 0 .../baselines}/update_previously_seen_users_in_cloudtrail.yml | 0 .../investigations}/all_backup_logs_for_host.yml | 0 .../investigations}/amazon_eks_kubernetes_activity_by_src_ip.yml | 0 .../aws_investigate_security_hub_alerts_by_dest.yml | 0 .../aws_investigate_user_activities_by_accesskeyid.yml | 0 .../investigations}/aws_investigate_user_activities_by_arn.yml | 0 .../investigations}/aws_network_acl_details_from_id.yml | 0 .../aws_network_interface_details_via_resourceid.yml | 0 .../investigations}/aws_s3_bucket_details_via_bucketname.yml | 0 .../investigations}/gcp_kubernetes_activity_by_src_ip.yml | 0 .../investigations}/get_all_aws_activity_from_city.yml | 0 .../investigations}/get_all_aws_activity_from_country.yml | 0 .../investigations}/get_all_aws_activity_from_ip_address.yml | 0 .../investigations}/get_all_aws_activity_from_region.yml | 0 .../investigations}/get_backup_logs_for_endpoint.yml | 0 .../investigations}/get_certificate_logs_for_a_domain.yml | 0 .../investigations}/get_dns_server_history_for_a_host.yml | 0 .../investigations}/get_dns_traffic_ratio.yml | 0 .../investigations}/get_ec2_instance_details_by_instanceid.yml | 0 .../investigations}/get_ec2_launch_details.yml | 0 {investigations => deprecated/investigations}/get_email_info.yml | 0 .../investigations}/get_emails_from_specific_sender.yml | 0 .../get_first_occurrence_and_last_occurrence_of_a_mac_address.yml | 0 .../investigations}/get_history_of_email_sources.yml | 0 .../get_logon_rights_modifications_for_endpoint.yml | 0 .../investigations}/get_logon_rights_modifications_for_user.yml | 0 .../investigations}/get_notable_history.yml | 0 .../get_outbound_emails_to_hidden_cobra_threat_actors.yml | 0 .../investigations}/get_parent_process_info.yml | 0 .../investigations}/get_process_file_activity.yml | 0 .../investigations}/get_process_info.yml | 0 .../investigations}/get_process_information_for_port_activity.yml | 0 .../get_process_responsible_for_the_dns_traffic.yml | 0 .../investigations}/get_sysmon_wmi_activity_for_host.yml | 0 .../get_web_session_information_via_session_id.yml | 0 .../investigate_aws_activities_via_region_name.yml | 0 .../investigate_aws_user_activities_by_user_field.yml | 0 .../investigate_failed_logins_for_multiple_destinations.yml | 0 .../investigations}/investigate_network_traffic_from_src_ip.yml | 0 .../investigations}/investigate_okta_activity_by_app.yml | 0 .../investigations}/investigate_okta_activity_by_ip_address.yml | 0 .../investigations}/investigate_pass_the_hash_attempts.yml | 0 .../investigations}/investigate_pass_the_ticket_attempts.yml | 0 .../investigations}/investigate_previous_unseen_user.yml | 0 .../investigate_successful_remote_desktop_authentications.yml | 0 .../investigate_suspicious_strings_in_http_header.yml | 0 .../investigations}/investigate_user_activities_in_okta.yml | 0 .../investigations}/investigate_web_posts_from_src.yml | 0 58 files changed, 0 insertions(+), 0 deletions(-) rename {baselines/deprecated => deprecated/baselines}/add_prohibited_processes_to_enterprise_security.yml (100%) rename {baselines/deprecated => deprecated/baselines}/baseline_of_api_calls_per_user_arn.yml (100%) rename {baselines/deprecated => deprecated/baselines}/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml (100%) rename {baselines/deprecated => deprecated/baselines}/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_api_call_per_user_roles_in_cloudtrail.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_aws_provisioning_activity_sources.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_ec2_amis.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_ec2_instance_types.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_ec2_launches_by_user.yml (100%) rename {baselines/deprecated => deprecated/baselines}/previously_seen_users_in_cloudtrail.yml (100%) rename {baselines/deprecated => deprecated/baselines}/update_previously_seen_users_in_cloudtrail.yml (100%) rename {investigations => deprecated/investigations}/all_backup_logs_for_host.yml (100%) rename {investigations => deprecated/investigations}/amazon_eks_kubernetes_activity_by_src_ip.yml (100%) rename {investigations => deprecated/investigations}/aws_investigate_security_hub_alerts_by_dest.yml (100%) rename {investigations => deprecated/investigations}/aws_investigate_user_activities_by_accesskeyid.yml (100%) rename {investigations => deprecated/investigations}/aws_investigate_user_activities_by_arn.yml (100%) rename {investigations => deprecated/investigations}/aws_network_acl_details_from_id.yml (100%) rename {investigations => deprecated/investigations}/aws_network_interface_details_via_resourceid.yml (100%) rename {investigations => deprecated/investigations}/aws_s3_bucket_details_via_bucketname.yml (100%) rename {investigations => deprecated/investigations}/gcp_kubernetes_activity_by_src_ip.yml (100%) rename {investigations => deprecated/investigations}/get_all_aws_activity_from_city.yml (100%) rename {investigations => deprecated/investigations}/get_all_aws_activity_from_country.yml (100%) rename {investigations => deprecated/investigations}/get_all_aws_activity_from_ip_address.yml (100%) rename {investigations => deprecated/investigations}/get_all_aws_activity_from_region.yml (100%) rename {investigations => deprecated/investigations}/get_backup_logs_for_endpoint.yml (100%) rename {investigations => deprecated/investigations}/get_certificate_logs_for_a_domain.yml (100%) rename {investigations => deprecated/investigations}/get_dns_server_history_for_a_host.yml (100%) rename {investigations => deprecated/investigations}/get_dns_traffic_ratio.yml (100%) rename {investigations => deprecated/investigations}/get_ec2_instance_details_by_instanceid.yml (100%) rename {investigations => deprecated/investigations}/get_ec2_launch_details.yml (100%) rename {investigations => deprecated/investigations}/get_email_info.yml (100%) rename {investigations => deprecated/investigations}/get_emails_from_specific_sender.yml (100%) rename {investigations => deprecated/investigations}/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml (100%) rename {investigations => deprecated/investigations}/get_history_of_email_sources.yml (100%) rename {investigations => deprecated/investigations}/get_logon_rights_modifications_for_endpoint.yml (100%) rename {investigations => deprecated/investigations}/get_logon_rights_modifications_for_user.yml (100%) rename {investigations => deprecated/investigations}/get_notable_history.yml (100%) rename {investigations => deprecated/investigations}/get_outbound_emails_to_hidden_cobra_threat_actors.yml (100%) rename {investigations => deprecated/investigations}/get_parent_process_info.yml (100%) rename {investigations => deprecated/investigations}/get_process_file_activity.yml (100%) rename {investigations => deprecated/investigations}/get_process_info.yml (100%) rename {investigations => deprecated/investigations}/get_process_information_for_port_activity.yml (100%) rename {investigations => deprecated/investigations}/get_process_responsible_for_the_dns_traffic.yml (100%) rename {investigations => deprecated/investigations}/get_sysmon_wmi_activity_for_host.yml (100%) rename {investigations => deprecated/investigations}/get_web_session_information_via_session_id.yml (100%) rename {investigations => deprecated/investigations}/investigate_aws_activities_via_region_name.yml (100%) rename {investigations => deprecated/investigations}/investigate_aws_user_activities_by_user_field.yml (100%) rename {investigations => deprecated/investigations}/investigate_failed_logins_for_multiple_destinations.yml (100%) rename {investigations => deprecated/investigations}/investigate_network_traffic_from_src_ip.yml (100%) rename {investigations => deprecated/investigations}/investigate_okta_activity_by_app.yml (100%) rename {investigations => deprecated/investigations}/investigate_okta_activity_by_ip_address.yml (100%) rename {investigations => deprecated/investigations}/investigate_pass_the_hash_attempts.yml (100%) rename {investigations => deprecated/investigations}/investigate_pass_the_ticket_attempts.yml (100%) rename {investigations => deprecated/investigations}/investigate_previous_unseen_user.yml (100%) rename {investigations => deprecated/investigations}/investigate_successful_remote_desktop_authentications.yml (100%) rename {investigations => deprecated/investigations}/investigate_suspicious_strings_in_http_header.yml (100%) rename {investigations => deprecated/investigations}/investigate_user_activities_in_okta.yml (100%) rename {investigations => deprecated/investigations}/investigate_web_posts_from_src.yml (100%) diff --git a/baselines/deprecated/add_prohibited_processes_to_enterprise_security.yml b/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml similarity index 100% rename from baselines/deprecated/add_prohibited_processes_to_enterprise_security.yml rename to deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml diff --git a/baselines/deprecated/baseline_of_api_calls_per_user_arn.yml b/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml similarity index 100% rename from baselines/deprecated/baseline_of_api_calls_per_user_arn.yml rename to deprecated/baselines/baseline_of_api_calls_per_user_arn.yml diff --git a/baselines/deprecated/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml b/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml similarity index 100% rename from baselines/deprecated/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml rename to deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml diff --git a/baselines/deprecated/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml b/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml similarity index 100% rename from baselines/deprecated/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml rename to deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml diff --git a/baselines/deprecated/previously_seen_api_call_per_user_roles_in_cloudtrail.yml b/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml similarity index 100% rename from baselines/deprecated/previously_seen_api_call_per_user_roles_in_cloudtrail.yml rename to deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml diff --git a/baselines/deprecated/previously_seen_aws_provisioning_activity_sources.yml b/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml similarity index 100% rename from baselines/deprecated/previously_seen_aws_provisioning_activity_sources.yml rename to deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml diff --git a/baselines/deprecated/previously_seen_ec2_amis.yml b/deprecated/baselines/previously_seen_ec2_amis.yml similarity index 100% rename from baselines/deprecated/previously_seen_ec2_amis.yml rename to deprecated/baselines/previously_seen_ec2_amis.yml diff --git a/baselines/deprecated/previously_seen_ec2_instance_types.yml b/deprecated/baselines/previously_seen_ec2_instance_types.yml similarity index 100% rename from baselines/deprecated/previously_seen_ec2_instance_types.yml rename to deprecated/baselines/previously_seen_ec2_instance_types.yml diff --git a/baselines/deprecated/previously_seen_ec2_launches_by_user.yml b/deprecated/baselines/previously_seen_ec2_launches_by_user.yml similarity index 100% rename from baselines/deprecated/previously_seen_ec2_launches_by_user.yml rename to deprecated/baselines/previously_seen_ec2_launches_by_user.yml diff --git a/baselines/deprecated/previously_seen_users_in_cloudtrail.yml b/deprecated/baselines/previously_seen_users_in_cloudtrail.yml similarity index 100% rename from baselines/deprecated/previously_seen_users_in_cloudtrail.yml rename to deprecated/baselines/previously_seen_users_in_cloudtrail.yml diff --git a/baselines/deprecated/update_previously_seen_users_in_cloudtrail.yml b/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml similarity index 100% rename from baselines/deprecated/update_previously_seen_users_in_cloudtrail.yml rename to deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml diff --git a/investigations/all_backup_logs_for_host.yml b/deprecated/investigations/all_backup_logs_for_host.yml similarity index 100% rename from investigations/all_backup_logs_for_host.yml rename to deprecated/investigations/all_backup_logs_for_host.yml diff --git a/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml b/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml similarity index 100% rename from investigations/amazon_eks_kubernetes_activity_by_src_ip.yml rename to deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml diff --git a/investigations/aws_investigate_security_hub_alerts_by_dest.yml b/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml similarity index 100% rename from investigations/aws_investigate_security_hub_alerts_by_dest.yml rename to deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml diff --git a/investigations/aws_investigate_user_activities_by_accesskeyid.yml b/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml similarity index 100% rename from investigations/aws_investigate_user_activities_by_accesskeyid.yml rename to deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml diff --git a/investigations/aws_investigate_user_activities_by_arn.yml b/deprecated/investigations/aws_investigate_user_activities_by_arn.yml similarity index 100% rename from investigations/aws_investigate_user_activities_by_arn.yml rename to deprecated/investigations/aws_investigate_user_activities_by_arn.yml diff --git a/investigations/aws_network_acl_details_from_id.yml b/deprecated/investigations/aws_network_acl_details_from_id.yml similarity index 100% rename from investigations/aws_network_acl_details_from_id.yml rename to deprecated/investigations/aws_network_acl_details_from_id.yml diff --git a/investigations/aws_network_interface_details_via_resourceid.yml b/deprecated/investigations/aws_network_interface_details_via_resourceid.yml similarity index 100% rename from investigations/aws_network_interface_details_via_resourceid.yml rename to deprecated/investigations/aws_network_interface_details_via_resourceid.yml diff --git a/investigations/aws_s3_bucket_details_via_bucketname.yml b/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml similarity index 100% rename from investigations/aws_s3_bucket_details_via_bucketname.yml rename to deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml diff --git a/investigations/gcp_kubernetes_activity_by_src_ip.yml b/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml similarity index 100% rename from investigations/gcp_kubernetes_activity_by_src_ip.yml rename to deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml diff --git a/investigations/get_all_aws_activity_from_city.yml b/deprecated/investigations/get_all_aws_activity_from_city.yml similarity index 100% rename from investigations/get_all_aws_activity_from_city.yml rename to deprecated/investigations/get_all_aws_activity_from_city.yml diff --git a/investigations/get_all_aws_activity_from_country.yml b/deprecated/investigations/get_all_aws_activity_from_country.yml similarity index 100% rename from investigations/get_all_aws_activity_from_country.yml rename to deprecated/investigations/get_all_aws_activity_from_country.yml diff --git a/investigations/get_all_aws_activity_from_ip_address.yml b/deprecated/investigations/get_all_aws_activity_from_ip_address.yml similarity index 100% rename from investigations/get_all_aws_activity_from_ip_address.yml rename to deprecated/investigations/get_all_aws_activity_from_ip_address.yml diff --git a/investigations/get_all_aws_activity_from_region.yml b/deprecated/investigations/get_all_aws_activity_from_region.yml similarity index 100% rename from investigations/get_all_aws_activity_from_region.yml rename to deprecated/investigations/get_all_aws_activity_from_region.yml diff --git a/investigations/get_backup_logs_for_endpoint.yml b/deprecated/investigations/get_backup_logs_for_endpoint.yml similarity index 100% rename from investigations/get_backup_logs_for_endpoint.yml rename to deprecated/investigations/get_backup_logs_for_endpoint.yml diff --git a/investigations/get_certificate_logs_for_a_domain.yml b/deprecated/investigations/get_certificate_logs_for_a_domain.yml similarity index 100% rename from investigations/get_certificate_logs_for_a_domain.yml rename to deprecated/investigations/get_certificate_logs_for_a_domain.yml diff --git a/investigations/get_dns_server_history_for_a_host.yml b/deprecated/investigations/get_dns_server_history_for_a_host.yml similarity index 100% rename from investigations/get_dns_server_history_for_a_host.yml rename to deprecated/investigations/get_dns_server_history_for_a_host.yml diff --git a/investigations/get_dns_traffic_ratio.yml b/deprecated/investigations/get_dns_traffic_ratio.yml similarity index 100% rename from investigations/get_dns_traffic_ratio.yml rename to deprecated/investigations/get_dns_traffic_ratio.yml diff --git a/investigations/get_ec2_instance_details_by_instanceid.yml b/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml similarity index 100% rename from investigations/get_ec2_instance_details_by_instanceid.yml rename to deprecated/investigations/get_ec2_instance_details_by_instanceid.yml diff --git a/investigations/get_ec2_launch_details.yml b/deprecated/investigations/get_ec2_launch_details.yml similarity index 100% rename from investigations/get_ec2_launch_details.yml rename to deprecated/investigations/get_ec2_launch_details.yml diff --git a/investigations/get_email_info.yml b/deprecated/investigations/get_email_info.yml similarity index 100% rename from investigations/get_email_info.yml rename to deprecated/investigations/get_email_info.yml diff --git a/investigations/get_emails_from_specific_sender.yml b/deprecated/investigations/get_emails_from_specific_sender.yml similarity index 100% rename from investigations/get_emails_from_specific_sender.yml rename to deprecated/investigations/get_emails_from_specific_sender.yml diff --git a/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml b/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml similarity index 100% rename from investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml rename to deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml diff --git a/investigations/get_history_of_email_sources.yml b/deprecated/investigations/get_history_of_email_sources.yml similarity index 100% rename from investigations/get_history_of_email_sources.yml rename to deprecated/investigations/get_history_of_email_sources.yml diff --git a/investigations/get_logon_rights_modifications_for_endpoint.yml b/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml similarity index 100% rename from investigations/get_logon_rights_modifications_for_endpoint.yml rename to deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml diff --git a/investigations/get_logon_rights_modifications_for_user.yml b/deprecated/investigations/get_logon_rights_modifications_for_user.yml similarity index 100% rename from investigations/get_logon_rights_modifications_for_user.yml rename to deprecated/investigations/get_logon_rights_modifications_for_user.yml diff --git a/investigations/get_notable_history.yml b/deprecated/investigations/get_notable_history.yml similarity index 100% rename from investigations/get_notable_history.yml rename to deprecated/investigations/get_notable_history.yml diff --git a/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml b/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml similarity index 100% rename from investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml rename to deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml diff --git a/investigations/get_parent_process_info.yml b/deprecated/investigations/get_parent_process_info.yml similarity index 100% rename from investigations/get_parent_process_info.yml rename to deprecated/investigations/get_parent_process_info.yml diff --git a/investigations/get_process_file_activity.yml b/deprecated/investigations/get_process_file_activity.yml similarity index 100% rename from investigations/get_process_file_activity.yml rename to deprecated/investigations/get_process_file_activity.yml diff --git a/investigations/get_process_info.yml b/deprecated/investigations/get_process_info.yml similarity index 100% rename from investigations/get_process_info.yml rename to deprecated/investigations/get_process_info.yml diff --git a/investigations/get_process_information_for_port_activity.yml b/deprecated/investigations/get_process_information_for_port_activity.yml similarity index 100% rename from investigations/get_process_information_for_port_activity.yml rename to deprecated/investigations/get_process_information_for_port_activity.yml diff --git a/investigations/get_process_responsible_for_the_dns_traffic.yml b/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml similarity index 100% rename from investigations/get_process_responsible_for_the_dns_traffic.yml rename to deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml diff --git a/investigations/get_sysmon_wmi_activity_for_host.yml b/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml similarity index 100% rename from investigations/get_sysmon_wmi_activity_for_host.yml rename to deprecated/investigations/get_sysmon_wmi_activity_for_host.yml diff --git a/investigations/get_web_session_information_via_session_id.yml b/deprecated/investigations/get_web_session_information_via_session_id.yml similarity index 100% rename from investigations/get_web_session_information_via_session_id.yml rename to deprecated/investigations/get_web_session_information_via_session_id.yml diff --git a/investigations/investigate_aws_activities_via_region_name.yml b/deprecated/investigations/investigate_aws_activities_via_region_name.yml similarity index 100% rename from investigations/investigate_aws_activities_via_region_name.yml rename to deprecated/investigations/investigate_aws_activities_via_region_name.yml diff --git a/investigations/investigate_aws_user_activities_by_user_field.yml b/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml similarity index 100% rename from investigations/investigate_aws_user_activities_by_user_field.yml rename to deprecated/investigations/investigate_aws_user_activities_by_user_field.yml diff --git a/investigations/investigate_failed_logins_for_multiple_destinations.yml b/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml similarity index 100% rename from investigations/investigate_failed_logins_for_multiple_destinations.yml rename to deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml diff --git a/investigations/investigate_network_traffic_from_src_ip.yml b/deprecated/investigations/investigate_network_traffic_from_src_ip.yml similarity index 100% rename from investigations/investigate_network_traffic_from_src_ip.yml rename to deprecated/investigations/investigate_network_traffic_from_src_ip.yml diff --git a/investigations/investigate_okta_activity_by_app.yml b/deprecated/investigations/investigate_okta_activity_by_app.yml similarity index 100% rename from investigations/investigate_okta_activity_by_app.yml rename to deprecated/investigations/investigate_okta_activity_by_app.yml diff --git a/investigations/investigate_okta_activity_by_ip_address.yml b/deprecated/investigations/investigate_okta_activity_by_ip_address.yml similarity index 100% rename from investigations/investigate_okta_activity_by_ip_address.yml rename to deprecated/investigations/investigate_okta_activity_by_ip_address.yml diff --git a/investigations/investigate_pass_the_hash_attempts.yml b/deprecated/investigations/investigate_pass_the_hash_attempts.yml similarity index 100% rename from investigations/investigate_pass_the_hash_attempts.yml rename to deprecated/investigations/investigate_pass_the_hash_attempts.yml diff --git a/investigations/investigate_pass_the_ticket_attempts.yml b/deprecated/investigations/investigate_pass_the_ticket_attempts.yml similarity index 100% rename from investigations/investigate_pass_the_ticket_attempts.yml rename to deprecated/investigations/investigate_pass_the_ticket_attempts.yml diff --git a/investigations/investigate_previous_unseen_user.yml b/deprecated/investigations/investigate_previous_unseen_user.yml similarity index 100% rename from investigations/investigate_previous_unseen_user.yml rename to deprecated/investigations/investigate_previous_unseen_user.yml diff --git a/investigations/investigate_successful_remote_desktop_authentications.yml b/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml similarity index 100% rename from investigations/investigate_successful_remote_desktop_authentications.yml rename to deprecated/investigations/investigate_successful_remote_desktop_authentications.yml diff --git a/investigations/investigate_suspicious_strings_in_http_header.yml b/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml similarity index 100% rename from investigations/investigate_suspicious_strings_in_http_header.yml rename to deprecated/investigations/investigate_suspicious_strings_in_http_header.yml diff --git a/investigations/investigate_user_activities_in_okta.yml b/deprecated/investigations/investigate_user_activities_in_okta.yml similarity index 100% rename from investigations/investigate_user_activities_in_okta.yml rename to deprecated/investigations/investigate_user_activities_in_okta.yml diff --git a/investigations/investigate_web_posts_from_src.yml b/deprecated/investigations/investigate_web_posts_from_src.yml similarity index 100% rename from investigations/investigate_web_posts_from_src.yml rename to deprecated/investigations/investigate_web_posts_from_src.yml From 0ef5bfc0d26fb3452dddb4d57fa6817b895d2053 Mon Sep 17 00:00:00 2001 From: research-bot Date: Wed, 26 Feb 2025 11:36:09 -0800 Subject: [PATCH 14/67] updating files after vaslidate --- .../baselines}/monitor_successful_backups.yml | 6 +++--- .../baselines}/monitor_unsuccessful_backups.yml | 6 +++--- .../baselines}/previously_seen_aws_regions.yml | 6 +++--- .../previously_seen_ec2_modifications_by_user.yml | 6 +++--- .../systems_ready_for_spectre_meltdown_windows_patch.yml | 6 +++--- .../deprecated => deprecated/stories}/aws_cryptomining.yml | 0 .../stories}/aws_suspicious_provisioning_activities.yml | 0 .../stories}/common_phishing_frameworks.yml | 0 .../container_implantation_monitoring_and_investigation.yml | 0 .../deprecated => deprecated/stories}/host_redirection.yml | 0 .../stories}/kubernetes_sensitive_role_activity.yml | 0 .../deprecated => deprecated/stories}/lateral_movement.yml | 0 .../stories}/monitor_backup_solution.yml | 0 .../stories}/monitor_for_unauthorized_software.yml | 0 .../stories}/office_365_detections.yml | 0 .../stories}/spectre_and_meltdown_vulnerabilities.yml | 0 .../stories}/suspicious_aws_ec2_activities.yml | 0 .../stories}/unusual_aws_ec2_modifications.yml | 0 .../stories}/web_fraud_detection.yml | 0 detections/endpoint/attacker_tools_on_endpoint.yml | 3 +-- 20 files changed, 16 insertions(+), 17 deletions(-) rename {baselines => deprecated/baselines}/monitor_successful_backups.yml (94%) rename {baselines => deprecated/baselines}/monitor_unsuccessful_backups.yml (94%) rename {baselines => deprecated/baselines}/previously_seen_aws_regions.yml (95%) rename {baselines => deprecated/baselines}/previously_seen_ec2_modifications_by_user.yml (95%) rename {baselines => deprecated/baselines}/systems_ready_for_spectre_meltdown_windows_patch.yml (96%) rename {stories/deprecated => deprecated/stories}/aws_cryptomining.yml (100%) rename {stories/deprecated => deprecated/stories}/aws_suspicious_provisioning_activities.yml (100%) rename {stories/deprecated => deprecated/stories}/common_phishing_frameworks.yml (100%) rename {stories/deprecated => deprecated/stories}/container_implantation_monitoring_and_investigation.yml (100%) rename {stories/deprecated => deprecated/stories}/host_redirection.yml (100%) rename {stories/deprecated => deprecated/stories}/kubernetes_sensitive_role_activity.yml (100%) rename {stories/deprecated => deprecated/stories}/lateral_movement.yml (100%) rename {stories/deprecated => deprecated/stories}/monitor_backup_solution.yml (100%) rename {stories/deprecated => deprecated/stories}/monitor_for_unauthorized_software.yml (100%) rename {stories/deprecated => deprecated/stories}/office_365_detections.yml (100%) rename {stories/deprecated => deprecated/stories}/spectre_and_meltdown_vulnerabilities.yml (100%) rename {stories/deprecated => deprecated/stories}/suspicious_aws_ec2_activities.yml (100%) rename {stories/deprecated => deprecated/stories}/unusual_aws_ec2_modifications.yml (100%) rename {stories/deprecated => deprecated/stories}/web_fraud_detection.yml (100%) diff --git a/baselines/monitor_successful_backups.yml b/deprecated/baselines/monitor_successful_backups.yml similarity index 94% rename from baselines/monitor_successful_backups.yml rename to deprecated/baselines/monitor_successful_backups.yml index fe0c140a5a..f178992d32 100644 --- a/baselines/monitor_successful_backups.yml +++ b/deprecated/baselines/monitor_successful_backups.yml @@ -1,10 +1,10 @@ name: Monitor Successful Backups id: b4d0dfb2-2195-4f6e-93a3-48468ed9734e -version: 1 -date: '2017-09-12' +version: 2 +date: '2025-02-27' author: David Dorsey, Splunk type: Baseline -status: production +status: deprecated description: This search is intended to give you a feel for how often successful backups are conducted in your environment. Fluctuations in these numbers will allow you to determine when you should investigate. diff --git a/baselines/monitor_unsuccessful_backups.yml b/deprecated/baselines/monitor_unsuccessful_backups.yml similarity index 94% rename from baselines/monitor_unsuccessful_backups.yml rename to deprecated/baselines/monitor_unsuccessful_backups.yml index 83195cbae0..bd694ee2b0 100644 --- a/baselines/monitor_unsuccessful_backups.yml +++ b/deprecated/baselines/monitor_unsuccessful_backups.yml @@ -1,10 +1,10 @@ name: Monitor Unsuccessful Backups id: b2178fed-592f-492b-b851-74161678aa56 -version: 1 -date: '2017-09-12' +version: 2 +date: '2025-02-27' author: David Dorsey, Splunk type: Baseline -status: production +status: deprecated description: This search is intended to give you a feel for how often backup failures happen in your environments. Fluctuations in these numbers will allow you to determine when you should investigate. diff --git a/baselines/previously_seen_aws_regions.yml b/deprecated/baselines/previously_seen_aws_regions.yml similarity index 95% rename from baselines/previously_seen_aws_regions.yml rename to deprecated/baselines/previously_seen_aws_regions.yml index da7bd98582..24fd59423f 100644 --- a/baselines/previously_seen_aws_regions.yml +++ b/deprecated/baselines/previously_seen_aws_regions.yml @@ -1,10 +1,10 @@ name: Previously Seen AWS Regions id: fc0edc95-ff2b-48b0-9f6f-63da3789fd63 -version: 1 -date: '2018-01-08' +version: 2 +date: '2025-02-27' author: Bhavin Patel, Splunk type: Baseline -status: production +status: deprecated description: This search looks for CloudTrail events where an AWS instance is started and creates a baseline of most recent time (latest) and the first time (earliest) we've seen this region in our dataset grouped by the value awsRegion for the last diff --git a/baselines/previously_seen_ec2_modifications_by_user.yml b/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml similarity index 95% rename from baselines/previously_seen_ec2_modifications_by_user.yml rename to deprecated/baselines/previously_seen_ec2_modifications_by_user.yml index fdf51c1460..426a1181ad 100644 --- a/baselines/previously_seen_ec2_modifications_by_user.yml +++ b/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml @@ -1,10 +1,10 @@ name: Previously Seen EC2 Modifications By User id: 4d69091b-d975-4267-85df-888bd41034eb -version: 1 -date: '2018-04-05' +version: 2 +date: '2025-02-27' author: David Dorsey, Splunk type: Baseline -status: production +status: deprecated description: This search builds a table of previously seen ARNs that have launched a EC2 instance. search: '`cloudtrail` `ec2_modification_api_calls` errorCode=success | spath output=arn diff --git a/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml b/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml similarity index 96% rename from baselines/systems_ready_for_spectre_meltdown_windows_patch.yml rename to deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml index 7b26e9e44d..763652d0e0 100644 --- a/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml +++ b/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml @@ -1,10 +1,10 @@ name: Systems Ready for Spectre-Meltdown Windows Patch id: fc0edc95-ff2b-48b0-9f6f-63da3789fd61 -version: 1 -date: '2018-01-08' +version: 2 +date: '2025-02-27' author: David Dorsey, Splunk type: Baseline -status: production +status: deprecated description: Some AV applications can cause the Spectre/Meltdown patch for Windows not to install successfully. This registry key is supposed to be created by the AV engine when it has been patched to be able to handle the Windows patch. If this diff --git a/stories/deprecated/aws_cryptomining.yml b/deprecated/stories/aws_cryptomining.yml similarity index 100% rename from stories/deprecated/aws_cryptomining.yml rename to deprecated/stories/aws_cryptomining.yml diff --git a/stories/deprecated/aws_suspicious_provisioning_activities.yml b/deprecated/stories/aws_suspicious_provisioning_activities.yml similarity index 100% rename from stories/deprecated/aws_suspicious_provisioning_activities.yml rename to deprecated/stories/aws_suspicious_provisioning_activities.yml diff --git a/stories/deprecated/common_phishing_frameworks.yml b/deprecated/stories/common_phishing_frameworks.yml similarity index 100% rename from stories/deprecated/common_phishing_frameworks.yml rename to deprecated/stories/common_phishing_frameworks.yml diff --git a/stories/deprecated/container_implantation_monitoring_and_investigation.yml b/deprecated/stories/container_implantation_monitoring_and_investigation.yml similarity index 100% rename from stories/deprecated/container_implantation_monitoring_and_investigation.yml rename to deprecated/stories/container_implantation_monitoring_and_investigation.yml diff --git a/stories/deprecated/host_redirection.yml b/deprecated/stories/host_redirection.yml similarity index 100% rename from stories/deprecated/host_redirection.yml rename to deprecated/stories/host_redirection.yml diff --git a/stories/deprecated/kubernetes_sensitive_role_activity.yml b/deprecated/stories/kubernetes_sensitive_role_activity.yml similarity index 100% rename from stories/deprecated/kubernetes_sensitive_role_activity.yml rename to deprecated/stories/kubernetes_sensitive_role_activity.yml diff --git a/stories/deprecated/lateral_movement.yml b/deprecated/stories/lateral_movement.yml similarity index 100% rename from stories/deprecated/lateral_movement.yml rename to deprecated/stories/lateral_movement.yml diff --git a/stories/deprecated/monitor_backup_solution.yml b/deprecated/stories/monitor_backup_solution.yml similarity index 100% rename from stories/deprecated/monitor_backup_solution.yml rename to deprecated/stories/monitor_backup_solution.yml diff --git a/stories/deprecated/monitor_for_unauthorized_software.yml b/deprecated/stories/monitor_for_unauthorized_software.yml similarity index 100% rename from stories/deprecated/monitor_for_unauthorized_software.yml rename to deprecated/stories/monitor_for_unauthorized_software.yml diff --git a/stories/deprecated/office_365_detections.yml b/deprecated/stories/office_365_detections.yml similarity index 100% rename from stories/deprecated/office_365_detections.yml rename to deprecated/stories/office_365_detections.yml diff --git a/stories/deprecated/spectre_and_meltdown_vulnerabilities.yml b/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml similarity index 100% rename from stories/deprecated/spectre_and_meltdown_vulnerabilities.yml rename to deprecated/stories/spectre_and_meltdown_vulnerabilities.yml diff --git a/stories/deprecated/suspicious_aws_ec2_activities.yml b/deprecated/stories/suspicious_aws_ec2_activities.yml similarity index 100% rename from stories/deprecated/suspicious_aws_ec2_activities.yml rename to deprecated/stories/suspicious_aws_ec2_activities.yml diff --git a/stories/deprecated/unusual_aws_ec2_modifications.yml b/deprecated/stories/unusual_aws_ec2_modifications.yml similarity index 100% rename from stories/deprecated/unusual_aws_ec2_modifications.yml rename to deprecated/stories/unusual_aws_ec2_modifications.yml diff --git a/stories/deprecated/web_fraud_detection.yml b/deprecated/stories/web_fraud_detection.yml similarity index 100% rename from stories/deprecated/web_fraud_detection.yml rename to deprecated/stories/web_fraud_detection.yml diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index a983aeb31d..4608e0a6da 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,7 +1,7 @@ name: Attacker Tools On Endpoint id: a51bfe1a-94f0-48cc-b4e4-16a110145893 version: 8 -date: '2025-02-10' +date: '2025-02-27' author: Bhavin Patel, Splunk status: production type: TTP @@ -66,7 +66,6 @@ rba: tags: analytic_story: - XMRig - - Monitor for Unauthorized Software - Unusual Processes - SamSam Ransomware - CISA AA22-264A From b70a4740a17d5de4d92d0aaa31dc47e938c082fd Mon Sep 17 00:00:00 2001 From: research-bot Date: Wed, 26 Feb 2025 11:40:03 -0800 Subject: [PATCH 15/67] updating version --- detections/endpoint/attacker_tools_on_endpoint.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 4608e0a6da..b4a9c676c9 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,6 +1,6 @@ name: Attacker Tools On Endpoint id: a51bfe1a-94f0-48cc-b4e4-16a110145893 -version: 8 +version: 9 date: '2025-02-27' author: Bhavin Patel, Splunk status: production From 098daaf4405ff4222754533e82f86b9a5f7db288 Mon Sep 17 00:00:00 2001 From: Steven Dick <38897662+nterl0k@users.noreply.github.com> Date: Thu, 27 Feb 2025 10:43:47 -0500 Subject: [PATCH 16/67] Update o365_sharepoint_suspicious_search_behavior.yml --- ..._sharepoint_suspicious_search_behavior.yml | 31 ++++++++++--------- 1 file changed, 17 insertions(+), 14 deletions(-) diff --git a/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml index 52449ed52b..8ab7ecfb4f 100644 --- a/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml +++ b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml @@ -1,7 +1,7 @@ name: O365 SharePoint Suspicious Search Behavior id: 6ca919db-52f3-4c95-a4e9-7b189e8a043d -version: 1 -date: '2025-01-08' +version: 2 +date: '2025-02-27' author: Steven Dick status: production type: Anomaly @@ -9,18 +9,20 @@ description: The following analytic identifies when the O365 SharePoint users se data_source: - Office 365 Universal Audit Log search: |- - `o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* - | where NOT (match(SearchQueryText, "\*") OR match(SearchQueryText,"(\*)")) - | eval signature_id = CorrelationId, signature=Operation, src = ClientIP, user = UserId, object_name=EventData, command = SearchQueryText, -time = _time - | bin _time span=1hr - | stats values(object_name) as object_name values(command) as command, values(src) as src, dc(command) as count, min(-time) as firstTime, max(-time) as lastTime by user,signature,_time - | where count > 20 OR match(command, "(?i)password|credential|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing") - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` + `o365_management_activity` (Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search*) OR Operation=SearchQueryInitiatedSharepoint + | eval command = case(Operation=="SearchQueryPerformed",SearchQueryText,true(),QueryText), UserId = lower(UserId), signature_id = CorrelationId, signature=Operation, src = ClientIP, user = lower(UserId), object_name=case(Operation=="SearchQueryPerformed",'EventData',true(),QuerySource), -time = _time, suspect_terms = case(match(command, `o365_suspect_search_terms_regex`),command,true(),null()) + | where command != "*" AND command != "(*)" + | bin _time span=1hr | `o365_sharepoint_suspicious_search_behavior_filter` + | stats values(ScenarioName) as app, values(object_name) as object_name values(command) as command, values(suspect_terms) as suspect_terms, values(src) as src, dc(suspect_terms) as suspect_terms_count, dc(command) as count, min(-time) as firstTime, max(-time) as lastTime by user,signature,_time + | where count > 20 OR suspect_terms_count >= 2 + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. The thresholds and match terms set within the analytic are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment. known_false_positives: Users searching excessively or possible false positives related to matching conditions. references: +- https://learn.microsoft.com/en-us/purview/audit-get-started#step-3-enable-searchqueryinitiated-events +- https://www.cisa.gov/sites/default/files/2025-01/microsoft-expanded-cloud-logs-implementation-playbook-508c.pdf - https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a - https://attack.mitre.org/techniques/T1213/002/ drilldown_searches: @@ -33,22 +35,23 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: Investigate search behavior by $user$ - search: '`o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* AND UserId = "$user$"' + search: '`o365_management_activity` (Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* AND UserId = "$user$") OR (OR Operation=SearchQueryInitiatedSharepoint AND UserId = "$user$")' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: The SharePoint Online was searched suspiciously by $user$ + message: The user $user$ searched SharePoint suspiciously, $count$ unique terms and $suspect_terms_count$ suspect terms were searched within a limited timeframe. risk_objects: - field: user type: user - score: 25 + score: 35 threat_objects: - field: src type: ip_address tags: analytic_story: - - Azure Active Directory Persistence - Office 365 Account Takeover + - Office 365 Collection Techniques + - Compromised User Account - CISA AA22-320A asset_type: O365 Tenant mitre_attack_id: From a500515a33addfbad1aebd23061f5a6b22a35798 Mon Sep 17 00:00:00 2001 From: Steven Dick <38897662+nterl0k@users.noreply.github.com> Date: Thu, 27 Feb 2025 10:52:01 -0500 Subject: [PATCH 17/67] Add files via upload --- macros/o365_suspect_search_terms_regex.yml | 3 +++ 1 file changed, 3 insertions(+) create mode 100644 macros/o365_suspect_search_terms_regex.yml diff --git a/macros/o365_suspect_search_terms_regex.yml b/macros/o365_suspect_search_terms_regex.yml new file mode 100644 index 0000000000..b1dbd9fe3d --- /dev/null +++ b/macros/o365_suspect_search_terms_regex.yml @@ -0,0 +1,3 @@ +definition: "(?i)password|credential$|credentials$|login|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing" +description: A regex used with match statements preloaded with generic suspicious terms or phrases. Is used to detect malicious actor or insider threat searches, replace/modify these terms to suit your organization. +name: o365_suspect_search_terms_regex \ No newline at end of file From 6961c6ced2a58020ca74d5a96b5e0c443065fafb Mon Sep 17 00:00:00 2001 From: Steven Dick <38897662+nterl0k@users.noreply.github.com> Date: Thu, 27 Feb 2025 11:43:30 -0500 Subject: [PATCH 18/67] Add files via upload --- .../o365_email_suspicious_search_behavior.yml | 70 +++++++++++++++++++ 1 file changed, 70 insertions(+) create mode 100644 detections/cloud/o365_email_suspicious_search_behavior.yml diff --git a/detections/cloud/o365_email_suspicious_search_behavior.yml b/detections/cloud/o365_email_suspicious_search_behavior.yml new file mode 100644 index 0000000000..5d67c47519 --- /dev/null +++ b/detections/cloud/o365_email_suspicious_search_behavior.yml @@ -0,0 +1,70 @@ +name: O365 Email Suspicious Search Behavior +id: 3b6e1d36-6916-4eec-a7d5-bc98953ba595 +version: 1 +date: '2025-02-27' +author: Steven Dick +status: production +type: Anamoly +description: The following analytic identifies when Office 365 users search for suspicious keywords or have an excessive number of queries to a mailbox within a limited timeframe. This behavior may indicate that a malicious actor has gained control of a mailbox and is conducting discovery or enumeration activities. +data_source: +- Office 365 Universal Audit Log +search: |- + `o365_management_activity` Operation=SearchQueryInitiatedExchange + | eval command = case(Operation=="SearchQueryPerformed",SearchQueryText,true(),QueryText), UserId = lower(UserId), signature_id = CorrelationId, signature=Operation, src = ClientIP, user = lower(UserId), object_name=case(Operation=="SearchQueryPerformed",'EventData',true(),QuerySource), -time = _time, suspect_terms = case(match(command, `o365_suspect_search_terms_regex`),command,true(),null()) + | where command != "*" AND command != "(*)" + | bin _time span=1hr + | `o365_email_suspicious_search_behavior_filter` + | stats values(ScenarioName) as app, values(object_name) as object_name values(command) as command, values(suspect_terms) as suspect_terms, values(src) as src, dc(suspect_terms) as suspect_terms_count, dc(command) as count, min(-time) as firstTime, max(-time) as lastTime by user,signature,_time + | where count > 20 OR suspect_terms_count >= 2 + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` +how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. You must also enable SearchQueryInitiated category as part of your organizations mailbox audit logging policy. The thresholds and match terms set within the analytic are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment. +known_false_positives: Users searching excessively or possible false positives related to matching conditions. +references: +- https://learn.microsoft.com/en-us/purview/audit-get-started#step-3-enable-searchqueryinitiated-events +- https://www.cisa.gov/sites/default/files/2025-01/microsoft-expanded-cloud-logs-implementation-playbook-508c.pdf +- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a +- https://attack.mitre.org/techniques/T1114/002/ +drilldown_searches: +- name: View the detection results for - "$user$" + search: '%original_detection_search% | search user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: Investigate search behavior by $user$ + search: '`o365_management_activity` AND Operation=SearchQueryInitiatedExchange AND UserId = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The user $user$ searched email suspiciously, $count$ unique terms and $suspect_terms_count$ suspect terms were searched within a limited timeframe. + risk_objects: + - field: user + type: user + score: 35 + threat_objects: + - field: src + type: ip_address +tags: + analytic_story: + - Office 365 Account Takeover + - Office 365 Collection Techniques + - Compromised User Account + - CISA AA22-320A + asset_type: O365 Tenant + mitre_attack_id: + - T1114.002 + - T1552 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: threat +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213.002/o365_sus_sharepoint_search/o365_sus_sharepoint_search.log + source: o365 + sourcetype: o365:management:activity \ No newline at end of file From 9ca556447582afc26cac9530425b9613b6d22133 Mon Sep 17 00:00:00 2001 From: Steven Dick <38897662+nterl0k@users.noreply.github.com> Date: Thu, 27 Feb 2025 12:05:57 -0500 Subject: [PATCH 19/67] Update o365_email_suspicious_search_behavior.yml --- detections/cloud/o365_email_suspicious_search_behavior.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/cloud/o365_email_suspicious_search_behavior.yml b/detections/cloud/o365_email_suspicious_search_behavior.yml index 5d67c47519..f9ae1c57ab 100644 --- a/detections/cloud/o365_email_suspicious_search_behavior.yml +++ b/detections/cloud/o365_email_suspicious_search_behavior.yml @@ -67,4 +67,4 @@ tests: attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213.002/o365_sus_sharepoint_search/o365_sus_sharepoint_search.log source: o365 - sourcetype: o365:management:activity \ No newline at end of file + sourcetype: o365:management:activity From 65c66a4270c1116ad0ab810c35965559ce96cb90 Mon Sep 17 00:00:00 2001 From: Steven Dick <38897662+nterl0k@users.noreply.github.com> Date: Thu, 27 Feb 2025 12:07:13 -0500 Subject: [PATCH 20/67] Update o365_sharepoint_suspicious_search_behavior.yml --- detections/cloud/o365_sharepoint_suspicious_search_behavior.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml index 8ab7ecfb4f..87ef5a4414 100644 --- a/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml +++ b/detections/cloud/o365_sharepoint_suspicious_search_behavior.yml @@ -5,7 +5,7 @@ date: '2025-02-27' author: Steven Dick status: production type: Anomaly -description: The following analytic identifies when the O365 SharePoint users search for suspicious keywords or have an excessive number of queries within a limited timeframe. This behavior may indicate malicious actor enumeration of SharePoint based data within O365. +description: The following analytic identifies when Office 365 users search for suspicious keywords or have an excessive number of queries to a SharePoint site within a limited timeframe. This behavior may indicate that a malicious actor has gained control of a user account and is conducting discovery or enumeration activities. data_source: - Office 365 Universal Audit Log search: |- From 1e9a8c8f2017ad27ed2a84e0635dbb50526d81f0 Mon Sep 17 00:00:00 2001 From: Steven Dick <38897662+nterl0k@users.noreply.github.com> Date: Thu, 27 Feb 2025 12:10:30 -0500 Subject: [PATCH 21/67] Update o365_email_suspicious_search_behavior.yml --- detections/cloud/o365_email_suspicious_search_behavior.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/cloud/o365_email_suspicious_search_behavior.yml b/detections/cloud/o365_email_suspicious_search_behavior.yml index f9ae1c57ab..f94970bf6b 100644 --- a/detections/cloud/o365_email_suspicious_search_behavior.yml +++ b/detections/cloud/o365_email_suspicious_search_behavior.yml @@ -4,7 +4,7 @@ version: 1 date: '2025-02-27' author: Steven Dick status: production -type: Anamoly +type: Anomaly description: The following analytic identifies when Office 365 users search for suspicious keywords or have an excessive number of queries to a mailbox within a limited timeframe. This behavior may indicate that a malicious actor has gained control of a mailbox and is conducting discovery or enumeration activities. data_source: - Office 365 Universal Audit Log From 7489993e96b541ac890fb966024f23011eec6cfc Mon Sep 17 00:00:00 2001 From: Teoderick Contreras Date: Fri, 28 Feb 2025 11:44:04 +0100 Subject: [PATCH 22/67] systembc --- ..._or_script_creation_in_suspicious_path.yml | 5 +-- .../endpoint/powershell_4104_hunting.yml | 5 +-- .../registry_keys_used_for_persistence.yml | 5 +-- ...ution_policy_to_unrestricted_or_bypass.yml | 5 +-- .../windows_suspicious_process_file_path.yml | 5 +-- ..._scheduled_task_created_to_spawn_shell.yml | 5 +-- ...eduled_task_created_within_public_path.yml | 5 +-- ...ws_task_scheduler_event_action_started.yml | 5 +-- stories/systembc.yml | 35 +++++++++++++++++++ 9 files changed, 59 insertions(+), 16 deletions(-) create mode 100644 stories/systembc.yml diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index 741c492268..6cc1ec1a85 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -1,7 +1,7 @@ name: Executables Or Script Creation In Suspicious Path id: a7e3f0f0-ae42-11eb-b245-acde48001122 -version: '11' -date: '2025-02-24' +version: '12' +date: '2025-02-28' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -101,6 +101,7 @@ tags: - Data Destruction - Amadey - WhisperGate + - SystemBC asset_type: Endpoint mitre_attack_id: - T1036 diff --git a/detections/endpoint/powershell_4104_hunting.yml b/detections/endpoint/powershell_4104_hunting.yml index d4a20fcd06..d03afb46b9 100644 --- a/detections/endpoint/powershell_4104_hunting.yml +++ b/detections/endpoint/powershell_4104_hunting.yml @@ -1,7 +1,7 @@ name: PowerShell 4104 Hunting id: d6f2b006-0041-11ec-8885-acde48001122 -version: '12' -date: '2025-02-24' +version: '13' +date: '2025-02-28' author: Michael Haag, Splunk status: production type: Hunting @@ -72,6 +72,7 @@ tags: - Rhysida Ransomware - Data Destruction - Hermetic Wiper + - SystemBC asset_type: Endpoint mitre_attack_id: - T1059.001 diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 968c76a2f3..af322ef9b3 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -1,7 +1,7 @@ name: Registry Keys Used For Persistence id: f5f6af30-7aa7-4295-bfe9-07fe87c01a4b -version: '17' -date: '2025-02-24' +version: '18' +date: '2025-02-28' author: Jose Hernandez, David Dorsey, Teoderick Contreras, Rod Soto, Splunk status: production type: TTP @@ -105,6 +105,7 @@ tags: - DarkGate Malware - Azorult - Amadey + - SystemBC asset_type: Endpoint mitre_attack_id: - T1547.001 diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index 00822bc0c3..071b4ea163 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -1,7 +1,7 @@ name: Set Default PowerShell Execution Policy To Unrestricted or Bypass id: c2590137-0b08-4985-9ec5-6ae23d92f63d -version: 13 -date: '2025-02-10' +version: 14 +date: '2025-02-28' author: Steven Dick, Patrick Bareiss, Splunk status: production type: TTP @@ -77,6 +77,7 @@ tags: - Malicious PowerShell - Data Destruction - DarkGate Malware + - SystemBC asset_type: Endpoint mitre_attack_id: - T1059.001 diff --git a/detections/endpoint/windows_suspicious_process_file_path.yml b/detections/endpoint/windows_suspicious_process_file_path.yml index 0675251a94..2c05ad3d0c 100644 --- a/detections/endpoint/windows_suspicious_process_file_path.yml +++ b/detections/endpoint/windows_suspicious_process_file_path.yml @@ -1,7 +1,7 @@ name: Windows Suspicious Process File Path id: ecddae4e-3d4b-41e2-b3df-e46a88b38521 -version: 7 -date: '2025-02-10' +version: 8 +date: '2025-02-28' author: Teoderick Contreras, Splunk status: production type: TTP @@ -103,6 +103,7 @@ tags: - MoonPeak - ValleyRAT - Meduza Stealer + - SystemBC asset_type: Endpoint mitre_attack_id: - T1543 diff --git a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml index eb98f737e4..515bdb1768 100644 --- a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml +++ b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml @@ -1,7 +1,7 @@ name: WinEvent Scheduled Task Created to Spawn Shell id: 203ef0ea-9bd8-11eb-8201-acde48001122 -version: '10' -date: '2025-02-24' +version: '11' +date: '2025-02-25' author: Michael Haag, Splunk status: production type: TTP @@ -64,6 +64,7 @@ tags: - Scheduled Tasks - Earth Estries - Winter Vivern + - SystemBC asset_type: Endpoint mitre_attack_id: - T1053.005 diff --git a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml index f464f02690..142adf55be 100644 --- a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml +++ b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml @@ -1,7 +1,7 @@ name: WinEvent Scheduled Task Created Within Public Path id: 5d9c6eee-988c-11eb-8253-acde48001122 -version: '10' -date: '2025-02-24' +version: '11' +date: '2025-02-28' author: Michael Haag, Splunk status: production type: TTP @@ -70,6 +70,7 @@ tags: - Scheduled Tasks - Data Destruction - Winter Vivern + - SystemBC asset_type: Endpoint mitre_attack_id: - T1053.005 diff --git a/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml b/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml index f20cf4265e..040059360b 100644 --- a/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml +++ b/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml @@ -1,7 +1,7 @@ name: WinEvent Windows Task Scheduler Event Action Started id: b3632472-310b-11ec-9aab-acde48001122 -version: 6 -date: '2024-11-13' +version: 7 +date: '2025-02-28' author: Michael Haag, Splunk status: production type: Hunting @@ -47,6 +47,7 @@ tags: - CISA AA24-241A - BlackSuit Ransomware - ValleyRAT + - SystemBC asset_type: Endpoint mitre_attack_id: - T1053.005 diff --git a/stories/systembc.yml b/stories/systembc.yml new file mode 100644 index 0000000000..5b02eae405 --- /dev/null +++ b/stories/systembc.yml @@ -0,0 +1,35 @@ +name: SystemBC +id: +version: 1 +date: '2025-02-28' +author: Teoderick Contreras, Splunk +status: production +description: Leverage searches for Dropped Files anomalies, and registry modification to detect SystemBC malware. + This threat acts as a backdoor proxy that enables attackers to maintain persistence, evade detection, and facilitate ransomware operations. + It often uses SOCKS5 proxies to disguise malicious traffic, making traditional network monitoring less effective. + Look for unusual outbound connections, especially to known threat actor infrastructure. Additionally, analyze PowerShell scripts, + scheduled tasks, and process injections that may indicate SystemBC deployment. Proactive threat hunting and endpoint monitoring are + essential to detecting and mitigating this malware. +narrative: SystemBC is a stealthy malware strain known for its proxy and backdoor capabilities, + often used by cybercriminals to facilitate ransomware attacks. First reported in 2019, it operates as a SOCKS5 proxy, + allowing attackers to route malicious traffic through infected systems while evading detection. + The malware is typically delivered via exploit kits, phishing emails, or secondary payloads from other malware families. + It enables persistent remote access, executes encrypted commands from a C2 server, and helps adversaries maintain control + over compromised networks. SystemBC has been linked to major ransomware operations, making it a significant threat in modern cyberattacks. +references: +- https://malpedia.caad.fkie.fraunhofer.de/details/win.systembc +- https://thedfirreport.com/2025/01/27/cobalt-strike-and-a-pair-of-socks-lead-to-lockbit-ransomware/ +- https://hackread.com/systembc-rat-targets-linux-ransomware-infostealers/ +- https://hackread.com/infostealers-breach-us-security-military-fbi-hit/ +- https://www.kroll.com/en/insights/publications/cyber/inside-the-systembc-malware-server +- https://medium.com/walmartglobaltech/systembc-powershell-version-68c9aad0f85c +- https://securelist.com/focus-on-droxidat-systembc/110302/ +- https://blogs.blackberry.com/en/2021/06/threat-thursday-systembc-a-rat-in-the-pipeline +tags: + category: + - Malware + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection \ No newline at end of file From 95384fcf0561680e7ad03ae0222c9c13a58e9ead Mon Sep 17 00:00:00 2001 From: Teoderick Contreras Date: Fri, 28 Feb 2025 12:00:07 +0100 Subject: [PATCH 23/67] systembc --- stories/systembc.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/stories/systembc.yml b/stories/systembc.yml index 5b02eae405..e25c032ccd 100644 --- a/stories/systembc.yml +++ b/stories/systembc.yml @@ -1,5 +1,5 @@ name: SystemBC -id: +id: ddc2801b-a881-4458-8f9d-c20e95daebea version: 1 date: '2025-02-28' author: Teoderick Contreras, Splunk From c8087bc330e607c086ee2d7f71919aa970601478 Mon Sep 17 00:00:00 2001 From: Teoderick Contreras Date: Mon, 3 Mar 2025 14:12:55 +0100 Subject: [PATCH 24/67] systembc --- ...dedit_command_back_to_normal_mode_boot.yml | 8 +++--- ...hange_to_safe_mode_with_network_config.yml | 8 +++--- .../endpoint/common_ransomware_extensions.yml | 28 ++++++++++--------- .../endpoint/common_ransomware_notes.yml | 20 ++++++------- .../endpoint/deleting_shadow_copies.yml | 18 ++++++------ .../detect_rclone_command_line_usage.yml | 8 +++--- detections/endpoint/detect_renamed_rclone.yml | 8 +++--- .../disable_defender_antivirus_registry.yml | 10 +++---- .../disable_windows_behavior_monitoring.yml | 16 +++++------ .../endpoint/modification_of_wallpaper.yml | 18 ++++++------ .../print_spooler_adding_a_printer_driver.yml | 8 +++--- ...print_spooler_failed_to_load_a_plug_in.yml | 8 +++--- .../ransomware_notes_bulk_creation.yml | 18 ++++++------ .../endpoint/spoolsv_spawning_rundll32.yml | 8 +++--- .../spoolsv_suspicious_loaded_modules.yml | 8 +++--- .../spoolsv_suspicious_process_access.yml | 8 +++--- detections/endpoint/spoolsv_writing_a_dll.yml | 8 +++--- .../spoolsv_writing_a_dll___sysmon.yml | 8 +++--- ...ndows_curl_download_to_suspicious_path.yml | 7 +++-- .../windows_high_file_deletion_frequency.yml | 16 +++++------ .../network/detect_zerologon_via_zeek.yml | 11 ++++---- lookups/ransomware_extensions_lookup.csv | 3 +- stories/black_basta_ransomware.yml | 18 ++++++++++++ 23 files changed, 147 insertions(+), 124 deletions(-) create mode 100644 stories/black_basta_ransomware.yml diff --git a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml index 0b6dcac7d9..d8c602f6b4 100644 --- a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml +++ b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml @@ -1,7 +1,7 @@ name: Bcdedit Command Back To Normal Mode Boot id: dc7a8004-0f18-11ec-8c54-acde48001122 -version: 4 -date: '2024-11-13' +version: '5' +date: '2025-03-03' author: Teoderick Contreras, Splunk status: production type: TTP @@ -62,6 +62,7 @@ rba: threat_objects: [] tags: analytic_story: + - Black Basta Ransomware - BlackMatter Ransomware asset_type: Endpoint mitre_attack_id: @@ -74,7 +75,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/change_to_safe_mode_with_network_config.yml b/detections/endpoint/change_to_safe_mode_with_network_config.yml index 6d8c2aa9ec..75247f707c 100644 --- a/detections/endpoint/change_to_safe_mode_with_network_config.yml +++ b/detections/endpoint/change_to_safe_mode_with_network_config.yml @@ -1,7 +1,7 @@ name: Change To Safe Mode With Network Config id: 81f1dce0-0f18-11ec-a5d7-acde48001122 -version: 4 -date: '2024-11-13' +version: '5' +date: '2025-03-03' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,6 +61,7 @@ rba: threat_objects: [] tags: analytic_story: + - Black Basta Ransomware - BlackMatter Ransomware asset_type: Endpoint mitre_attack_id: @@ -73,7 +74,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.002/autoadminlogon/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/common_ransomware_extensions.yml b/detections/endpoint/common_ransomware_extensions.yml index b7dbef7eb3..079d11de57 100644 --- a/detections/endpoint/common_ransomware_extensions.yml +++ b/detections/endpoint/common_ransomware_extensions.yml @@ -1,7 +1,7 @@ name: Common Ransomware Extensions id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec -version: 11 -date: '2025-01-07' +version: '12' +date: '2025-03-03' author: David Dorsey, Michael Haag, Splunk, Steven Dick status: production type: TTP @@ -24,10 +24,10 @@ search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_ path_count dc(file_name) as file_count latest(true_file_path) as file_path by dest file_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `ransomware_extensions` | where path_count > 1 OR file_count > 20 | `common_ransomware_extensions_filter`' -how_to_implement: 'You must be ingesting data that records the filesystem activity +how_to_implement: You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint Filesystem data model node. To see the additional metadata, add the following fields, if not already present, please review - the detailed documentation on how to create a new field within Incident Review' + the detailed documentation on how to create a new field within Incident Review known_false_positives: It is possible for a legitimate file with these extensions to be created. If this is a true ransomware attack, there will be a large number of files created with these extensions. @@ -47,8 +47,10 @@ drilldown_searches: | `security_content_ctime(lastTime)`' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ -rba: - message: The device $dest$ wrote $file_count$ files to $path_count$ path(s) with the $Extensions$ extension. This extension and behavior may indicate a $Name$ ransomware attack. +rba: + message: The device $dest$ wrote $file_count$ files to $path_count$ path(s) with + the $Extensions$ extension. This extension and behavior may indicate a $Name$ + ransomware attack. risk_objects: - field: user type: user @@ -59,13 +61,14 @@ rba: threat_objects: [] tags: analytic_story: - - SamSam Ransomware - - Ryuk Ransomware - - Ransomware - - Clop Ransomware + - Rhysida Ransomware - Prestige Ransomware - LockBit Ransomware - - Rhysida Ransomware + - Ryuk Ransomware + - SamSam Ransomware + - Black Basta Ransomware + - Ransomware + - Clop Ransomware asset_type: Endpoint mitre_attack_id: - T1485 @@ -77,7 +80,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/ransom-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/ransom-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/common_ransomware_notes.yml b/detections/endpoint/common_ransomware_notes.yml index 2535f7533b..069996fda3 100644 --- a/detections/endpoint/common_ransomware_notes.yml +++ b/detections/endpoint/common_ransomware_notes.yml @@ -1,7 +1,7 @@ name: Common Ransomware Notes id: ada0f478-84a8-4641-a3f1-d82362d6bd71 -version: 7 -date: '2024-11-13' +version: '8' +date: '2025-03-03' author: David Dorsey, Splunk status: production type: Hunting @@ -29,13 +29,14 @@ known_false_positives: It's possible that a legitimate file could be created wit references: [] tags: analytic_story: - - SamSam Ransomware - - Ransomware - - Ryuk Ransomware - - Clop Ransomware - - Chaos Ransomware - - LockBit Ransomware - Rhysida Ransomware + - LockBit Ransomware + - Ryuk Ransomware + - SamSam Ransomware + - Chaos Ransomware + - Black Basta Ransomware + - Ransomware + - Clop Ransomware asset_type: Endpoint mitre_attack_id: - T1485 @@ -47,7 +48,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml index 89b5ebed9b..ed825e84fd 100644 --- a/detections/endpoint/deleting_shadow_copies.yml +++ b/detections/endpoint/deleting_shadow_copies.yml @@ -1,7 +1,7 @@ name: Deleting Shadow Copies id: b89919ed-ee5f-492c-b139-95dbb162039e -version: 10 -date: '2024-12-10' +version: '11' +date: '2025-03-03' author: David Dorsey, Splunk status: production type: TTP @@ -69,15 +69,16 @@ rba: type: process_name tags: analytic_story: - - Chaos Ransomware - Rhysida Ransomware - - Windows Log Manipulation - Prestige Ransomware - - Ransomware - - SamSam Ransomware - CISA AA22-264A - - DarkGate Malware - LockBit Ransomware + - SamSam Ransomware + - Chaos Ransomware + - Black Basta Ransomware + - DarkGate Malware + - Ransomware + - Windows Log Manipulation - Compromised Windows Host - Clop Ransomware asset_type: Endpoint @@ -91,7 +92,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml index a36e49cace..d5dae5c8af 100644 --- a/detections/endpoint/detect_rclone_command_line_usage.yml +++ b/detections/endpoint/detect_rclone_command_line_usage.yml @@ -1,7 +1,7 @@ name: Detect RClone Command-Line Usage id: 32e0baea-b3f1-11eb-a2ce-acde48001122 -version: 7 -date: '2024-11-13' +version: '8' +date: '2025-03-03' author: Michael Haag, Splunk status: production type: TTP @@ -75,6 +75,7 @@ tags: analytic_story: - DarkSide Ransomware - Ransomware + - Black Basta Ransomware asset_type: Endpoint mitre_attack_id: - T1020 @@ -86,7 +87,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/detect_renamed_rclone.yml b/detections/endpoint/detect_renamed_rclone.yml index 04c0a7e651..8d842c1444 100644 --- a/detections/endpoint/detect_renamed_rclone.yml +++ b/detections/endpoint/detect_renamed_rclone.yml @@ -1,7 +1,7 @@ name: Detect Renamed RClone id: 6dca1124-b3ec-11eb-9328-acde48001122 -version: 6 -date: '2024-11-13' +version: '7' +date: '2025-03-03' author: Michael Haag, Splunk status: production type: Hunting @@ -42,6 +42,7 @@ tags: analytic_story: - DarkSide Ransomware - Ransomware + - Black Basta Ransomware asset_type: Endpoint mitre_attack_id: - T1020 @@ -53,7 +54,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/disable_defender_antivirus_registry.yml b/detections/endpoint/disable_defender_antivirus_registry.yml index 6aca910525..d7b9f60813 100644 --- a/detections/endpoint/disable_defender_antivirus_registry.yml +++ b/detections/endpoint/disable_defender_antivirus_registry.yml @@ -1,7 +1,7 @@ name: Disable Defender AntiVirus Registry id: aa4f695a-3024-11ec-9987-acde48001122 -version: 9 -date: '2025-02-10' +version: '10' +date: '2025-03-03' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -56,9 +56,10 @@ rba: threat_objects: [] tags: analytic_story: - - IcedID - Windows Registry Abuse - CISA AA24-241A + - IcedID + - Black Basta Ransomware asset_type: Endpoint mitre_attack_id: - T1562.001 @@ -70,7 +71,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index 1fd00e8d98..2e0c1f7cd4 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -1,7 +1,7 @@ name: Disable Windows Behavior Monitoring id: 79439cae-9200-11eb-a4d3-acde48001122 -version: 11 -date: '2025-02-10' +version: '12' +date: '2025-03-03' author: Teoderick Contreras, Splunk, Steven Dick status: production type: TTP @@ -58,13 +58,14 @@ rba: threat_objects: [] tags: analytic_story: - - Azorult - - Ransomware - - Windows Registry Abuse - - RedLine Stealer - Windows Defense Evasion Tactics - CISA AA23-347A - Revil Ransomware + - Azorult + - Windows Registry Abuse + - Black Basta Ransomware + - Ransomware + - RedLine Stealer asset_type: Endpoint mitre_attack_id: - T1562.001 @@ -76,7 +77,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/modification_of_wallpaper.yml b/detections/endpoint/modification_of_wallpaper.yml index e51be7f390..fcb014d2a1 100644 --- a/detections/endpoint/modification_of_wallpaper.yml +++ b/detections/endpoint/modification_of_wallpaper.yml @@ -1,7 +1,7 @@ name: Modification Of Wallpaper id: accb0712-c381-11eb-8e5b-acde48001122 -version: 4 -date: '2024-11-13' +version: '5' +date: '2025-03-03' author: Teoderick Contreras, Splunk status: production type: TTP @@ -54,13 +54,14 @@ rba: threat_objects: [] tags: analytic_story: - - Ransomware - Revil Ransomware - - BlackMatter Ransomware - - Windows Registry Abuse - - Brute Ratel C4 - - LockBit Ransomware - Rhysida Ransomware + - LockBit Ransomware + - BlackMatter Ransomware + - Brute Ratel C4 + - Windows Registry Abuse + - Black Basta Ransomware + - Ransomware asset_type: Endpoint mitre_attack_id: - T1491 @@ -72,7 +73,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/print_spooler_adding_a_printer_driver.yml b/detections/endpoint/print_spooler_adding_a_printer_driver.yml index 8afd39363a..3f642c1daf 100644 --- a/detections/endpoint/print_spooler_adding_a_printer_driver.yml +++ b/detections/endpoint/print_spooler_adding_a_printer_driver.yml @@ -1,7 +1,7 @@ name: Print Spooler Adding A Printer Driver id: 313681a2-da8e-11eb-adad-acde48001122 -version: 5 -date: '2025-02-10' +version: '6' +date: '2025-03-03' author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -52,6 +52,7 @@ rba: tags: analytic_story: - PrintNightmare CVE-2021-34527 + - Black Basta Ransomware asset_type: Endpoint cve: - CVE-2021-34527 @@ -66,7 +67,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-printservice_operational.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-printservice_operational.log source: WinEventLog:Microsoft-Windows-PrintService/Operational sourcetype: WinEventLog diff --git a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml index 7ad22f6b32..505ec33faf 100644 --- a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml +++ b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml @@ -1,7 +1,7 @@ name: Print Spooler Failed to Load a Plug-in id: 1adc9548-da7c-11eb-8f13-acde48001122 -version: 5 -date: '2025-02-10' +version: '6' +date: '2025-03-03' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -53,6 +53,7 @@ rba: tags: analytic_story: - PrintNightmare CVE-2021-34527 + - Black Basta Ransomware asset_type: Endpoint cve: - CVE-2021-34527 @@ -67,7 +68,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-printservice_admin.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-printservice_admin.log source: WinEventLog:Microsoft-Windows-PrintService/Admin sourcetype: WinEventLog diff --git a/detections/endpoint/ransomware_notes_bulk_creation.yml b/detections/endpoint/ransomware_notes_bulk_creation.yml index 61d4c21f17..631b0fc764 100644 --- a/detections/endpoint/ransomware_notes_bulk_creation.yml +++ b/detections/endpoint/ransomware_notes_bulk_creation.yml @@ -1,7 +1,7 @@ name: Ransomware Notes bulk creation id: eff7919a-8330-11eb-83f8-acde48001122 -version: 4 -date: '2024-11-13' +version: '5' +date: '2025-03-03' author: Teoderick Contreras status: production type: Anomaly @@ -51,12 +51,13 @@ rba: threat_objects: [] tags: analytic_story: - - Clop Ransomware - - DarkSide Ransomware - - BlackMatter Ransomware - - Chaos Ransomware - - LockBit Ransomware - Rhysida Ransomware + - LockBit Ransomware + - BlackMatter Ransomware + - DarkSide Ransomware + - Chaos Ransomware + - Black Basta Ransomware + - Clop Ransomware asset_type: Endpoint mitre_attack_id: - T1486 @@ -68,7 +69,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/spoolsv_spawning_rundll32.yml b/detections/endpoint/spoolsv_spawning_rundll32.yml index 70da48f52e..e65d63e295 100644 --- a/detections/endpoint/spoolsv_spawning_rundll32.yml +++ b/detections/endpoint/spoolsv_spawning_rundll32.yml @@ -1,7 +1,7 @@ name: Spoolsv Spawning Rundll32 id: 15d905f6-da6b-11eb-ab82-acde48001122 -version: 7 -date: '2025-02-10' +version: '8' +date: '2025-03-03' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -67,6 +67,7 @@ tags: analytic_story: - PrintNightmare CVE-2021-34527 - Compromised Windows Host + - Black Basta Ransomware asset_type: Endpoint cve: - CVE-2021-34527 @@ -80,7 +81,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml index 07a521d03e..fa3847f8b0 100644 --- a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml +++ b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml @@ -1,7 +1,7 @@ name: Spoolsv Suspicious Loaded Modules id: a5e451f8-da81-11eb-b245-acde48001122 -version: 6 -date: '2025-02-10' +version: '7' +date: '2025-03-03' author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -50,6 +50,7 @@ rba: tags: analytic_story: - PrintNightmare CVE-2021-34527 + - Black Basta Ransomware asset_type: Endpoint cve: - CVE-2021-34527 @@ -63,7 +64,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/spoolsv_suspicious_process_access.yml b/detections/endpoint/spoolsv_suspicious_process_access.yml index a41111a7b1..3b7ec83687 100644 --- a/detections/endpoint/spoolsv_suspicious_process_access.yml +++ b/detections/endpoint/spoolsv_suspicious_process_access.yml @@ -1,7 +1,7 @@ name: Spoolsv Suspicious Process Access id: 799b606e-da81-11eb-93f8-acde48001122 -version: 6 -date: '2024-11-13' +version: '7' +date: '2025-03-03' author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk status: production type: TTP @@ -59,6 +59,7 @@ rba: tags: analytic_story: - PrintNightmare CVE-2021-34527 + - Black Basta Ransomware asset_type: Endpoint cve: - CVE-2021-34527 @@ -72,7 +73,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml index 3111e77d23..a8fab8f7b0 100644 --- a/detections/endpoint/spoolsv_writing_a_dll.yml +++ b/detections/endpoint/spoolsv_writing_a_dll.yml @@ -1,7 +1,7 @@ name: Spoolsv Writing a DLL id: d5bf5cf2-da71-11eb-92c2-acde48001122 -version: 7 -date: '2025-02-10' +version: '8' +date: '2025-03-03' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -65,6 +65,7 @@ tags: analytic_story: - PrintNightmare CVE-2021-34527 - Compromised Windows Host + - Black Basta Ransomware asset_type: Endpoint cve: - CVE-2021-34527 @@ -78,7 +79,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml index de8fec23dd..3fce3b68aa 100644 --- a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml +++ b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml @@ -1,7 +1,7 @@ name: Spoolsv Writing a DLL - Sysmon id: 347fd388-da87-11eb-836d-acde48001122 -version: 5 -date: '2025-02-10' +version: '6' +date: '2025-03-03' author: Mauricio Velazco, Michael Haag, Splunk status: production type: TTP @@ -58,6 +58,7 @@ rba: tags: analytic_story: - PrintNightmare CVE-2021-34527 + - Black Basta Ransomware asset_type: Endpoint cve: - CVE-2021-34527 @@ -71,7 +72,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index aa27afdfc7..95fd1c0638 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -1,7 +1,7 @@ name: Windows Curl Download to Suspicious Path id: c32f091e-30db-11ec-8738-acde48001122 -version: '9' -date: '2025-02-24' +version: '11' +date: '2025-03-03' author: Michael Haag, Splunk status: production type: TTP @@ -70,11 +70,12 @@ rba: type: process_name tags: analytic_story: - - Ingress Tool Transfer - China-Nexus Threat Activity + - Ingress Tool Transfer - IcedID - Forest Blizzard - Earth Estries + - Black Basta Ransomware - Compromised Windows Host asset_type: Endpoint mitre_attack_id: diff --git a/detections/endpoint/windows_high_file_deletion_frequency.yml b/detections/endpoint/windows_high_file_deletion_frequency.yml index 7c18190d62..93778f82a0 100644 --- a/detections/endpoint/windows_high_file_deletion_frequency.yml +++ b/detections/endpoint/windows_high_file_deletion_frequency.yml @@ -1,7 +1,7 @@ name: Windows High File Deletion Frequency id: 45b125c4-866f-11eb-a95a-acde48001122 -version: 5 -date: '2024-11-13' +version: '6' +date: '2025-03-03' author: Teoderick Contreras, Splunk, Steven Dick status: production type: Anomaly @@ -65,13 +65,14 @@ rba: type: process_name tags: analytic_story: - - Clop Ransomware + - Handala Wiper - DarkCrystal RAT - - Swift Slicer - - Data Destruction - WhisperGate - Sandworm Tools - - Handala Wiper + - Black Basta Ransomware + - Swift Slicer + - Data Destruction + - Clop Ransomware asset_type: Endpoint mitre_attack_id: - T1485 @@ -83,7 +84,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog diff --git a/detections/network/detect_zerologon_via_zeek.yml b/detections/network/detect_zerologon_via_zeek.yml index 94fadd635c..33000d7d6b 100644 --- a/detections/network/detect_zerologon_via_zeek.yml +++ b/detections/network/detect_zerologon_via_zeek.yml @@ -1,18 +1,18 @@ name: Detect Zerologon via Zeek id: bf7a06ec-f703-11ea-adc1-0242ac120002 -version: 4 -date: '2024-11-15' +version: '5' +date: '2025-03-03' author: Shannon Davis, Splunk status: experimental type: TTP -description: "The following analytic detects attempts to exploit the Zerologon CVE-2020-1472 +description: 'The following analytic detects attempts to exploit the Zerologon CVE-2020-1472 vulnerability via Zeek RPC. It leverages Zeek DCE-RPC data to identify specific operations: NetrServerPasswordSet2, NetrServerReqChallenge, and NetrServerAuthenticate3. This activity is significant because it indicates an attempt to gain unauthorized access to a domain controller, potentially leading to a complete takeover of an - organization's IT infrastructure. If confirmed malicious, the impact could be severe, + organization''s IT infrastructure. If confirmed malicious, the impact could be severe, including data theft, ransomware deployment, or other devastating outcomes. Immediate - investigation of the identified IP addresses and RPC operations is crucial." + investigation of the identified IP addresses and RPC operations is crucial.' data_source: [] search: '`zeek_rpc` operation IN (NetrServerPasswordSet2,NetrServerReqChallenge,NetrServerAuthenticate3) | bin span=5m _time | stats values(operation) dc(operation) as opscount count(eval(operation=="NetrServerReqChallenge")) @@ -40,6 +40,7 @@ tags: analytic_story: - Detect Zerologon Attack - Rhysida Ransomware + - Black Basta Ransomware asset_type: Network cve: - CVE-2020-1472 diff --git a/lookups/ransomware_extensions_lookup.csv b/lookups/ransomware_extensions_lookup.csv index 38cca70a09..c6cb398475 100644 --- a/lookups/ransomware_extensions_lookup.csv +++ b/lookups/ransomware_extensions_lookup.csv @@ -300,4 +300,5 @@ Extensions,Name *.GANGBANG,Gangbang *.reddot,RedDot *.MEDUSA,Medusa -*.rhysida,Rhysida \ No newline at end of file +*.rhysida,Rhysida +*.basta, BlackBasta \ No newline at end of file diff --git a/stories/black_basta_ransomware.yml b/stories/black_basta_ransomware.yml new file mode 100644 index 0000000000..d58f9bc49c --- /dev/null +++ b/stories/black_basta_ransomware.yml @@ -0,0 +1,18 @@ +name: Black Basta Ransomware +id: b543afc8-2b65-49d7-8325-a9bca4fd65c8 +version: 1 +date: '2025-02-03' +author: Teoderick Contreras, Splunk +status: production +description: Leverage searches for suspicious behaviors associated with Black Basta ransomware, focusing on key indicators such as process execution, registry modifications, and network activity. Monitor for unusual file encryption patterns, particularly involving cmd.exe, powershell.exe, or wmic.exe executing with arguments linked to volume shadow copy deletion (vssadmin delete shadows). Look for registry changes disabling security features or altering startup configurations. Track high-volume file modifications in rapid succession, indicative of ransomware encryption. Additionally, unauthorized remote service executions. Cross-reference endpoint logs, EDR alerts, and SIEM detections to correlate malicious activity. Behavioral analytics and heuristic-based detections can enhance visibility into evolving tactics. Implement robust monitoring and response mechanisms to mitigate Black Basta’s impact effectively. +narrative: Black Basta ransomware is a highly sophisticated and fast-moving threat that has been targeting organizations worldwide, often disrupting critical operations and demanding hefty ransoms. It operates as a double extortion ransomware, encrypting victim data while simultaneously exfiltrating it to pressure victims into paying. The attack typically begins with initial access via phishing emails, compromised credentials, or exploitation of vulnerabilities in remote desktop services. Once inside, attackers escalate privileges, disable security defenses, and deploy the ransomware payload. The malware rapidly encrypts files across local and networked drives, deleting shadow copies to prevent recovery. It often abuses legitimate system tools like wmic.exe and rundll32.exe, to evade detection. Simultaneously, it establishes command-and-control (C2) connections to exfiltrate sensitive data. The impact is severe—disrupting business operations, exposing confidential information, and leaving organizations with few options for recovery. Early detection, network segmentation, and strong endpoint defenses are crucial to mitigating the risk posed by Black Basta. +references: +- https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a +tags: + category: + - Malware + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection From d87b3f6a48ffb3e2647507e6cbdf36f77630a0f4 Mon Sep 17 00:00:00 2001 From: Teoderick Contreras Date: Mon, 3 Mar 2025 15:10:33 +0100 Subject: [PATCH 25/67] systembc --- lookups/ransomware_notes_lookup.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lookups/ransomware_notes_lookup.yml b/lookups/ransomware_notes_lookup.yml index e36d441ec7..21ec31a3bf 100644 --- a/lookups/ransomware_notes_lookup.yml +++ b/lookups/ransomware_notes_lookup.yml @@ -1,6 +1,6 @@ name: ransomware_notes_lookup -date: 2024-12-23 -version: 2 +date: 2025-03-03 +version: 3 id: 93d9fb06-035e-496c-91d5-7a79543ce1e1 author: Splunk Threat Research Team lookup_type: csv From 4f4f87af9ffc2103eec27d2022cd74728c1e42fd Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Tue, 4 Mar 2025 13:42:37 -0800 Subject: [PATCH 26/67] Add baselines, stories, and investigations to deprecation yml. --- deprecated/deprecated_detection_mapping.yml | 426 +++++++++++++++++++- 1 file changed, 423 insertions(+), 3 deletions(-) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index 322dea112d..48f6c3f118 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -897,6 +897,426 @@ detections: TA update replacement_content: - Okta Multiple Failed MFA Requests For User -baselines: [] -investigations: [] -stories: [] \ No newline at end of file + - deprecated_content: Excel Spawning Windows Script Host + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: GitHub Actions Disable Security Workflow + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Github Commit Changes In Master + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Github Commit In Develop + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: GitHub Dependabot Alert + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: GitHub Pull Request from Unknown User + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Known Services Killed by Ransomware + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Remote Desktop Network Bruteforce + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Suspicious Driver Loaded Path + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Suspicious Event Log Service Behavior + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Suspicious Process File Path + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Windows Service Stop Via Net and SC Application + deprecated_in_version: 5.3.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] +baselines: + - deprecated_content: Add Prohibited Processes to Enterprise Security + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Baseline of API Calls per User ARN + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously seen API call per user roles in CloudTrail + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously Seen AWS Provisioning Activity Sources + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously Seen EC2 AMIs + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously Seen EC2 Instance Types + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously Seen EC2 Launches By User + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously seen users in CloudTrail + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Update previously seen users in CloudTrail + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] +investigations: + - deprecated_content: All backup logs for host + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Amazon EKS Kubernetes activity by src ip + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS Investigate Security Hub alerts by dest + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS Investigate User Activities By AccessKeyId + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS Investigate User Activities By ARN + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS Network ACL Details from ID + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS Network Interface details via resourceId + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS S3 Bucket details via bucketName + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: GCP Kubernetes activity by src ip + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get All AWS Activity From City + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get All AWS Activity From Country + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get All AWS Activity From IP Address + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get All AWS Activity From Region + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Backup Logs For Endpoint + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Certificate logs for a domain + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get DNS Server History for a host + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get DNS traffic ratio + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get EC2 Instance Details by instanceId + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get EC2 Launch Details + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Email Info + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Emails From Specific Sender + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get History Of Email Sources + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Logon Rights Modifications For Endpoint + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Logon Rights Modifications For User + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Notable History + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Parent Process Info + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Process File Activity + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Process Info + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Process Information For Port Activity + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Process Responsible For The DNS Traffic + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Sysmon WMI Activity for Host + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Web Session Information via session id + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate AWS activities via region name + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate AWS User Activities by user field + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Failed Logins for Multiple Destinations + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Network Traffic From src ip + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Okta Activity by app + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Okta Activity by IP Address + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Pass the Hash Attempts + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Pass the Ticket Attempts + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Previous Unseen User + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Successful Remote Desktop Authentications + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Suspicious Strings in HTTP Header + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate User Activities In Okta + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Web POSTs From src + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] +stories: + - deprecated_content: AWS Cryptomining + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: AWS Suspicious Provisioning Activities + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Common Phishing Frameworks + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Container Implantation Monitoring and Investigation + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Host Redirection + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes Sensitive Role Activity + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Lateral Movement + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Monitor Backup Solution + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Monitor for Unauthorized Software + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Office 365 Detections + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Spectre And Meltdown Vulnerabilities + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Suspicious AWS EC2 Activities + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Unusual AWS EC2 Modifications + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Web Fraud Detection + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] From 78cc0c0f1793cf01227fb95cbccf499161b200d6 Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Wed, 5 Mar 2025 14:24:11 -0800 Subject: [PATCH 27/67] updated deprecation mapping again --- deprecated/deprecated_detection_mapping.yml | 729 ++++++++++---------- 1 file changed, 366 insertions(+), 363 deletions(-) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index 48f6c3f118..1e7efff47c 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -957,366 +957,369 @@ detections: deprecated_date: 2025-03-12 reason: '' replacement_content: [] -baselines: - - deprecated_content: Add Prohibited Processes to Enterprise Security - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - - deprecated_content: Baseline of API Calls per User ARN - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - - deprecated_content: Previously seen API call per user roles in CloudTrail - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - - deprecated_content: Previously Seen AWS Provisioning Activity Sources - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - - deprecated_content: Previously Seen EC2 AMIs - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - - deprecated_content: Previously Seen EC2 Instance Types - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - - deprecated_content: Previously Seen EC2 Launches By User - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - - deprecated_content: Previously seen users in CloudTrail - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - - deprecated_content: Update previously seen users in CloudTrail - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] -investigations: - - deprecated_content: All backup logs for host - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Amazon EKS Kubernetes activity by src ip - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: AWS Investigate Security Hub alerts by dest - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: AWS Investigate User Activities By AccessKeyId - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: AWS Investigate User Activities By ARN - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: AWS Network ACL Details from ID - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: AWS Network Interface details via resourceId - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: AWS S3 Bucket details via bucketName - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: GCP Kubernetes activity by src ip - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get All AWS Activity From City - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get All AWS Activity From Country - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get All AWS Activity From IP Address - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get All AWS Activity From Region - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Backup Logs For Endpoint - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Certificate logs for a domain - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get DNS Server History for a host - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get DNS traffic ratio - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get EC2 Instance Details by instanceId - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get EC2 Launch Details - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Email Info - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Emails From Specific Sender - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get History Of Email Sources - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Logon Rights Modifications For Endpoint - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Logon Rights Modifications For User - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Notable History - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Parent Process Info - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Process File Activity - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Process Info - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Process Information For Port Activity - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Process Responsible For The DNS Traffic - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Sysmon WMI Activity for Host - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Get Web Session Information via session id - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate AWS activities via region name - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate AWS User Activities by user field - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate Failed Logins for Multiple Destinations - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate Network Traffic From src ip - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate Okta Activity by app - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate Okta Activity by IP Address - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate Pass the Hash Attempts - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate Pass the Ticket Attempts - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate Previous Unseen User - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate Successful Remote Desktop Authentications - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate Suspicious Strings in HTTP Header - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate User Activities In Okta - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - - deprecated_content: Investigate Web POSTs From src - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] -stories: - - deprecated_content: AWS Cryptomining - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: AWS Suspicious Provisioning Activities - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Common Phishing Frameworks - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Container Implantation Monitoring and Investigation - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Host Redirection - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Kubernetes Sensitive Role Activity - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Lateral Movement - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Monitor Backup Solution - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Monitor for Unauthorized Software - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Office 365 Detections - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Spectre And Meltdown Vulnerabilities - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Suspicious AWS EC2 Activities - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Unusual AWS EC2 Modifications - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] - - deprecated_content: Web Fraud Detection - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: '' - replacement_content: [] +baselines: [] +investigations: [] +stories: [] +# baselines: +# - deprecated_content: Add Prohibited Processes to Enterprise Security +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' +# replacement_content: [] +# - deprecated_content: Baseline of API Calls per User ARN +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' +# replacement_content: [] +# - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' +# replacement_content: [] +# - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' +# replacement_content: [] +# - deprecated_content: Previously seen API call per user roles in CloudTrail +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' +# replacement_content: [] +# - deprecated_content: Previously Seen AWS Provisioning Activity Sources +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' +# replacement_content: [] +# - deprecated_content: Previously Seen EC2 AMIs +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' +# replacement_content: [] +# - deprecated_content: Previously Seen EC2 Instance Types +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' +# replacement_content: [] +# - deprecated_content: Previously Seen EC2 Launches By User +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' +# replacement_content: [] +# - deprecated_content: Previously seen users in CloudTrail +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' +# replacement_content: [] +# - deprecated_content: Update previously seen users in CloudTrail +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' +# replacement_content: [] +# investigations: +# - deprecated_content: All backup logs for host +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Amazon EKS Kubernetes activity by src ip +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: AWS Investigate Security Hub alerts by dest +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: AWS Investigate User Activities By AccessKeyId +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: AWS Investigate User Activities By ARN +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: AWS Network ACL Details from ID +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: AWS Network Interface details via resourceId +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: AWS S3 Bucket details via bucketName +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: GCP Kubernetes activity by src ip +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get All AWS Activity From City +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get All AWS Activity From Country +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get All AWS Activity From IP Address +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get All AWS Activity From Region +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Backup Logs For Endpoint +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Certificate logs for a domain +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get DNS Server History for a host +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get DNS traffic ratio +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get EC2 Instance Details by instanceId +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get EC2 Launch Details +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Email Info +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Emails From Specific Sender +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get History Of Email Sources +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Logon Rights Modifications For Endpoint +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Logon Rights Modifications For User +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Notable History +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Parent Process Info +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Process File Activity +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Process Info +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Process Information For Port Activity +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Process Responsible For The DNS Traffic +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Sysmon WMI Activity for Host +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Get Web Session Information via session id +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate AWS activities via region name +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate AWS User Activities by user field +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate Failed Logins for Multiple Destinations +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate Network Traffic From src ip +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate Okta Activity by app +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate Okta Activity by IP Address +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate Pass the Hash Attempts +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate Pass the Ticket Attempts +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate Previous Unseen User +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate Successful Remote Desktop Authentications +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate Suspicious Strings in HTTP Header +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate User Activities In Okta +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# - deprecated_content: Investigate Web POSTs From src +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' +# replacement_content: [] +# stories: +# - deprecated_content: AWS Cryptomining +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: AWS Suspicious Provisioning Activities +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Common Phishing Frameworks +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Container Implantation Monitoring and Investigation +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Host Redirection +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Kubernetes Sensitive Role Activity +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Lateral Movement +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Monitor Backup Solution +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Monitor for Unauthorized Software +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Office 365 Detections +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Spectre And Meltdown Vulnerabilities +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Suspicious AWS EC2 Activities +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Unusual AWS EC2 Modifications +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] +# - deprecated_content: Web Fraud Detection +# deprecated_in_version: 5.2.0 +# deprecated_date: 2025-03-12 +# reason: '' +# replacement_content: [] From d86e7667205765e76d6f7e0e8f7272a60a399452 Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Thu, 6 Mar 2025 13:16:16 -0800 Subject: [PATCH 28/67] updated with missing content --- deprecated/deprecated_detection_mapping.yml | 729 ++++++++++---------- 1 file changed, 363 insertions(+), 366 deletions(-) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index 1e7efff47c..48f6c3f118 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -957,369 +957,366 @@ detections: deprecated_date: 2025-03-12 reason: '' replacement_content: [] -baselines: [] -investigations: [] -stories: [] -# baselines: -# - deprecated_content: Add Prohibited Processes to Enterprise Security -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' -# replacement_content: [] -# - deprecated_content: Baseline of API Calls per User ARN -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' -# replacement_content: [] -# - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' -# replacement_content: [] -# - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' -# replacement_content: [] -# - deprecated_content: Previously seen API call per user roles in CloudTrail -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' -# replacement_content: [] -# - deprecated_content: Previously Seen AWS Provisioning Activity Sources -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' -# replacement_content: [] -# - deprecated_content: Previously Seen EC2 AMIs -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' -# replacement_content: [] -# - deprecated_content: Previously Seen EC2 Instance Types -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' -# replacement_content: [] -# - deprecated_content: Previously Seen EC2 Launches By User -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' -# replacement_content: [] -# - deprecated_content: Previously seen users in CloudTrail -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' -# replacement_content: [] -# - deprecated_content: Update previously seen users in CloudTrail -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' -# replacement_content: [] -# investigations: -# - deprecated_content: All backup logs for host -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Amazon EKS Kubernetes activity by src ip -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: AWS Investigate Security Hub alerts by dest -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: AWS Investigate User Activities By AccessKeyId -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: AWS Investigate User Activities By ARN -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: AWS Network ACL Details from ID -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: AWS Network Interface details via resourceId -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: AWS S3 Bucket details via bucketName -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: GCP Kubernetes activity by src ip -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get All AWS Activity From City -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get All AWS Activity From Country -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get All AWS Activity From IP Address -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get All AWS Activity From Region -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Backup Logs For Endpoint -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Certificate logs for a domain -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get DNS Server History for a host -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get DNS traffic ratio -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get EC2 Instance Details by instanceId -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get EC2 Launch Details -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Email Info -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Emails From Specific Sender -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get History Of Email Sources -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Logon Rights Modifications For Endpoint -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Logon Rights Modifications For User -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Notable History -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Parent Process Info -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Process File Activity -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Process Info -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Process Information For Port Activity -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Process Responsible For The DNS Traffic -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Sysmon WMI Activity for Host -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Get Web Session Information via session id -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate AWS activities via region name -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate AWS User Activities by user field -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate Failed Logins for Multiple Destinations -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate Network Traffic From src ip -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate Okta Activity by app -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate Okta Activity by IP Address -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate Pass the Hash Attempts -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate Pass the Ticket Attempts -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate Previous Unseen User -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate Successful Remote Desktop Authentications -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate Suspicious Strings in HTTP Header -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate User Activities In Okta -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# - deprecated_content: Investigate Web POSTs From src -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' -# replacement_content: [] -# stories: -# - deprecated_content: AWS Cryptomining -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: AWS Suspicious Provisioning Activities -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Common Phishing Frameworks -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Container Implantation Monitoring and Investigation -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Host Redirection -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Kubernetes Sensitive Role Activity -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Lateral Movement -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Monitor Backup Solution -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Monitor for Unauthorized Software -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Office 365 Detections -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Spectre And Meltdown Vulnerabilities -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Suspicious AWS EC2 Activities -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Unusual AWS EC2 Modifications -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] -# - deprecated_content: Web Fraud Detection -# deprecated_in_version: 5.2.0 -# deprecated_date: 2025-03-12 -# reason: '' -# replacement_content: [] +baselines: + - deprecated_content: Add Prohibited Processes to Enterprise Security + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Baseline of API Calls per User ARN + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously seen API call per user roles in CloudTrail + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously Seen AWS Provisioning Activity Sources + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously Seen EC2 AMIs + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously Seen EC2 Instance Types + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously Seen EC2 Launches By User + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Previously seen users in CloudTrail + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] + - deprecated_content: Update previously seen users in CloudTrail + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + replacement_content: [] +investigations: + - deprecated_content: All backup logs for host + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Amazon EKS Kubernetes activity by src ip + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS Investigate Security Hub alerts by dest + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS Investigate User Activities By AccessKeyId + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS Investigate User Activities By ARN + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS Network ACL Details from ID + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS Network Interface details via resourceId + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: AWS S3 Bucket details via bucketName + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: GCP Kubernetes activity by src ip + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get All AWS Activity From City + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get All AWS Activity From Country + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get All AWS Activity From IP Address + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get All AWS Activity From Region + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Backup Logs For Endpoint + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Certificate logs for a domain + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get DNS Server History for a host + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get DNS traffic ratio + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get EC2 Instance Details by instanceId + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get EC2 Launch Details + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Email Info + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Emails From Specific Sender + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get History Of Email Sources + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Logon Rights Modifications For Endpoint + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Logon Rights Modifications For User + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Notable History + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Parent Process Info + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Process File Activity + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Process Info + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Process Information For Port Activity + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Process Responsible For The DNS Traffic + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Sysmon WMI Activity for Host + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Get Web Session Information via session id + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate AWS activities via region name + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate AWS User Activities by user field + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Failed Logins for Multiple Destinations + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Network Traffic From src ip + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Okta Activity by app + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Okta Activity by IP Address + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Pass the Hash Attempts + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Pass the Ticket Attempts + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Previous Unseen User + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Successful Remote Desktop Authentications + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Suspicious Strings in HTTP Header + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate User Activities In Okta + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] + - deprecated_content: Investigate Web POSTs From src + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' + replacement_content: [] +stories: + - deprecated_content: AWS Cryptomining + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: AWS Suspicious Provisioning Activities + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Common Phishing Frameworks + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Container Implantation Monitoring and Investigation + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Host Redirection + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Kubernetes Sensitive Role Activity + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Lateral Movement + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Monitor Backup Solution + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Monitor for Unauthorized Software + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Office 365 Detections + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Spectre And Meltdown Vulnerabilities + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Suspicious AWS EC2 Activities + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Unusual AWS EC2 Modifications + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] + - deprecated_content: Web Fraud Detection + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: '' + replacement_content: [] From 726dd930598ee95c7e3d4405329eaeb267bb2b19 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Tue, 11 Mar 2025 17:20:32 -0700 Subject: [PATCH 29/67] adding a reason for empty detections --- deprecated/deprecated_detection_mapping.yml | 200 ++++++++++---------- 1 file changed, 100 insertions(+), 100 deletions(-) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index 48f6c3f118..7990514343 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -2,7 +2,7 @@ detections: - deprecated_content: ASL AWS Excessive Security Scanning deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region deprecated_in_version: 5.2.0 @@ -14,27 +14,27 @@ detections: - deprecated_content: First time seen command line argument deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Windows connhost exe started forcefully deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Detect Mimikatz Using Loaded Images deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Kubernetes Azure detect sensitive role access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Web Fraud - Anomalous User Clickspeed deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type deprecated_in_version: 5.2.0 @@ -53,13 +53,13 @@ detections: - deprecated_content: Domain Group Discovery With Net deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Group Discovery Via Net - deprecated_content: Kubernetes AWS detect sensitive role access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Winword Spawning Windows Script Host deprecated_in_version: 5.2.0 @@ -73,7 +73,7 @@ detections: - deprecated_content: Winword Spawning PowerShell deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Attempted Credential Dump From Registry via Reg exe @@ -131,27 +131,27 @@ detections: - deprecated_content: Detect AWS API Activities From Unapproved Accounts deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Monitor DNS For Brand Abuse deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Kubernetes GCP detect sensitive object access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Kubernetes Azure scan fingerprint deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: ASL AWS Password Policy Changes deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: O365 Suspicious Admin Email Forwarding deprecated_in_version: 5.2.0 @@ -170,12 +170,12 @@ detections: - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Osquery pack - ColdRoot detection deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Windows Modify Registry Reg Restore deprecated_in_version: 5.2.0 @@ -186,7 +186,7 @@ detections: - deprecated_content: Kubernetes GCP detect most active service accounts by pod deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Scheduled tasks used in BadRabbit ransomware deprecated_in_version: 5.2.0 @@ -197,7 +197,7 @@ detections: - deprecated_content: Suspicious Rundll32 Rename deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Remote System Discovery with Net deprecated_in_version: 5.2.0 @@ -211,23 +211,23 @@ detections: - deprecated_content: Remote System Discovery with Net deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Sensitive Group Discovery With Net - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Suspicious Changes to File Associations deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: GCP Detect high risk permissions by resource and account deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Office Product Writing cab or inf deprecated_in_version: 5.2.0 @@ -238,12 +238,12 @@ detections: - deprecated_content: Identify New User Accounts deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Office Product Spawn CMD Process deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Windows DLL Search Order Hijacking Hunt @@ -263,7 +263,7 @@ detections: - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Detect Spike in Security Group Activity deprecated_in_version: 5.2.0 @@ -275,7 +275,7 @@ detections: - deprecated_content: Office Product Spawning BITSAdmin deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Create local admin accounts using net exe @@ -287,7 +287,7 @@ detections: - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Windows Office Product Spawning MSDT deprecated_in_version: 5.2.0 @@ -298,18 +298,18 @@ detections: - deprecated_content: Detect Spike in AWS API Activity deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Office Product Spawning Windows Script Host deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Prohibited Software On Endpoint deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Attacker Tools On Endpoint - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country @@ -332,19 +332,19 @@ detections: - deprecated_content: Detect Critical Alerts from Security Tools deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Microsoft Defender Incident Alerts - deprecated_content: Excel Spawning PowerShell deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Office Application Spawn rundll32 process deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Excessive Usage Of Net App @@ -374,7 +374,7 @@ detections: - deprecated_content: Suspicious Email - UBA Anomaly deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Detect web traffic to dynamic domain providers deprecated_in_version: 5.2.0 @@ -392,17 +392,17 @@ detections: - deprecated_content: Kubernetes AWS detect RBAC authorization by account deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Remote Registry Key modifications deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: O365 Suspicious User Email Forwarding deprecated_in_version: 5.2.0 @@ -414,13 +414,13 @@ detections: - deprecated_content: Office Product Spawning MSHTA deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Kubernetes AWS detect most active service accounts by pod deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Correlation by Repository and Risk deprecated_in_version: 5.2.0 @@ -431,12 +431,12 @@ detections: - deprecated_content: Kubernetes Azure detect RBAC authorization by account deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Clients Connecting to Multiple DNS Servers deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Excessive Service Stop Attempt deprecated_in_version: 5.2.0 @@ -454,7 +454,7 @@ detections: - deprecated_content: Suspicious writes to System Volume Information deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Detect new user AWS Console Login deprecated_in_version: 5.2.0 @@ -475,12 +475,12 @@ detections: - deprecated_content: Detection of DNS Tunnels deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2 deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Office Document Creating Schedule Task deprecated_in_version: 5.2.0 @@ -498,7 +498,7 @@ detections: - deprecated_content: Unsuccessful Netbackup backups deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703 deprecated_in_version: 5.2.0 @@ -509,7 +509,7 @@ detections: - deprecated_content: Winword Spawning Cmd deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: GCP Kubernetes cluster scan detection @@ -522,12 +522,12 @@ detections: - deprecated_content: Kubernetes GCP detect suspicious kubectl calls deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: gcp detect oauth token abuse deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Correlation by User and Risk deprecated_in_version: 5.2.0 @@ -544,7 +544,7 @@ detections: - deprecated_content: Office Product Spawning Wmic deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Extraction of Registry Hives @@ -588,17 +588,17 @@ detections: - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Reg exe used to hide files directories via registry keys deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Detect Long DNS TXT Record Response deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Password Policy Discovery with Net deprecated_in_version: 5.2.0 @@ -622,12 +622,12 @@ detections: - deprecated_content: Kubernetes Azure detect suspicious kubectl calls deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Kubernetes GCP detect sensitive role access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Detect Webshell Exploit Behavior deprecated_in_version: 5.2.0 @@ -638,17 +638,17 @@ detections: - deprecated_content: DNS record changed deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Unsigned Image Loaded by LSASS deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Detect USB device insertion deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Windows Network Share Interaction With Net deprecated_in_version: 5.2.0 @@ -713,7 +713,7 @@ detections: - deprecated_content: Windows hosts file modification deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: MSHTML Module Load in Office Product deprecated_in_version: 5.2.0 @@ -731,7 +731,7 @@ detections: - deprecated_content: Web Fraud - Account Harvesting deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Office Spawning Control deprecated_in_version: 5.2.0 @@ -742,7 +742,7 @@ detections: - deprecated_content: Detect Activity Related to Pass the Hash Attacks deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Deleting Of Net Users deprecated_in_version: 5.2.0 @@ -753,7 +753,7 @@ detections: - deprecated_content: Suspicious File Write deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: AWS EKS Kubernetes cluster sensitive object access deprecated_in_version: 5.2.0 @@ -765,7 +765,7 @@ detections: - deprecated_content: Spectre and Meltdown Vulnerable Systems deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: EC2 Instance Started With Previously Unseen User deprecated_in_version: 5.2.0 @@ -777,13 +777,13 @@ detections: - deprecated_content: Office Product Spawning CertUtil deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Kubernetes GCP detect RBAC authorizations by account deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Office Application Drop Executable deprecated_in_version: 5.2.0 @@ -794,12 +794,12 @@ detections: - deprecated_content: Kubernetes Azure active service accounts by pod namespace deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Kubernetes Azure pod scan fingerprint deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Detect Spike in Network ACL Activity deprecated_in_version: 5.2.0 @@ -811,13 +811,13 @@ detections: - deprecated_content: Suspicious Powershell Command-Line Arguments deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Malicious PowerShell Process - Encoded Command - deprecated_content: Office Application Spawn Regsvr32 process deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Detect API activity from users without MFA @@ -830,12 +830,12 @@ detections: - deprecated_content: Kubernetes Azure detect sensitive object access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Web Fraud - Password Sharing Across Accounts deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Disabling Net User Account deprecated_in_version: 5.2.0 @@ -846,17 +846,17 @@ detections: - deprecated_content: GCP Detect accounts with high risk roles by project deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Extended Period Without Successful Netbackup Backups deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Office Product Spawning Rundll32 with no DLL deprecated_in_version: 5.2.0 @@ -881,7 +881,7 @@ detections: - deprecated_content: Uncommon Processes On Endpoint deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: - Attacker Tools On Endpoint - deprecated_content: Dump LSASS via procdump Rename @@ -900,62 +900,62 @@ detections: - deprecated_content: Excel Spawning Windows Script Host deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: GitHub Actions Disable Security Workflow deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Github Commit Changes In Master deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Github Commit In Develop deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: GitHub Dependabot Alert deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: GitHub Pull Request from Unknown User deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Known Services Killed by Ransomware deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Remote Desktop Network Bruteforce deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Suspicious Driver Loaded Path deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Suspicious Event Log Service Behavior deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Suspicious Process File Path deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Windows Service Stop Via Net and SC Application deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] baselines: - deprecated_content: Add Prohibited Processes to Enterprise Security @@ -1253,70 +1253,70 @@ stories: - deprecated_content: AWS Cryptomining deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: AWS Suspicious Provisioning Activities deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Common Phishing Frameworks deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Container Implantation Monitoring and Investigation deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Host Redirection deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Kubernetes Sensitive Role Activity deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Lateral Movement deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Monitor Backup Solution deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Monitor for Unauthorized Software deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Office 365 Detections deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Spectre And Meltdown Vulnerabilities deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Suspicious AWS EC2 Activities deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Unusual AWS EC2 Modifications deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] - deprecated_content: Web Fraud Detection deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: '' + reason: The detection does not work as expected and is now deprecated replacement_content: [] From 2445b44357cbe25cc501d3a303bfa349b5243ed3 Mon Sep 17 00:00:00 2001 From: Steven Dick <38897662+nterl0k@users.noreply.github.com> Date: Wed, 12 Mar 2025 07:32:14 -0400 Subject: [PATCH 30/67] Update o365_suspect_search_terms_regex.yml removing regex using $ because ContentCTL is being dumb and thinks it's a variable. --- macros/o365_suspect_search_terms_regex.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/macros/o365_suspect_search_terms_regex.yml b/macros/o365_suspect_search_terms_regex.yml index b1dbd9fe3d..e5190a3cb3 100644 --- a/macros/o365_suspect_search_terms_regex.yml +++ b/macros/o365_suspect_search_terms_regex.yml @@ -1,3 +1,3 @@ -definition: "(?i)password|credential$|credentials$|login|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing" +definition: "(?i)password|credential|login|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing" description: A regex used with match statements preloaded with generic suspicious terms or phrases. Is used to detect malicious actor or insider threat searches, replace/modify these terms to suit your organization. -name: o365_suspect_search_terms_regex \ No newline at end of file +name: o365_suspect_search_terms_regex From 5e02c6b38cb09b64ccbe7fa04ca160245c220c69 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Wed, 12 Mar 2025 14:25:10 -0700 Subject: [PATCH 31/67] updating for nexus --- deprecated/deprecated_detection_mapping.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index 7990514343..1c79dd2c27 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -1320,3 +1320,8 @@ stories: deprecated_date: 2025-03-12 reason: The detection does not work as expected and is now deprecated replacement_content: [] + - deprecated_content: Nexus APT Threat Activity + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: The detection does not work as expected and is now deprecated + replacement_content: [] From 97395878e97777cc96786c92db47ad574c6d59a6 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Thu, 13 Mar 2025 17:42:27 -0700 Subject: [PATCH 32/67] updating text --- deprecated/deprecated_detection_mapping.yml | 322 ++++++++++---------- 1 file changed, 161 insertions(+), 161 deletions(-) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index 1c79dd2c27..c5d72406cb 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -2,7 +2,7 @@ detections: - deprecated_content: ASL AWS Excessive Security Scanning deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region deprecated_in_version: 5.2.0 @@ -14,27 +14,27 @@ detections: - deprecated_content: First time seen command line argument deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Windows connhost exe started forcefully deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Detect Mimikatz Using Loaded Images deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Kubernetes Azure detect sensitive role access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Web Fraud - Anomalous User Clickspeed deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type deprecated_in_version: 5.2.0 @@ -53,13 +53,13 @@ detections: - deprecated_content: Domain Group Discovery With Net deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Group Discovery Via Net - deprecated_content: Kubernetes AWS detect sensitive role access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Winword Spawning Windows Script Host deprecated_in_version: 5.2.0 @@ -73,7 +73,7 @@ detections: - deprecated_content: Winword Spawning PowerShell deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Attempted Credential Dump From Registry via Reg exe @@ -131,27 +131,27 @@ detections: - deprecated_content: Detect AWS API Activities From Unapproved Accounts deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Monitor DNS For Brand Abuse deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Kubernetes GCP detect sensitive object access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Kubernetes Azure scan fingerprint deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: ASL AWS Password Policy Changes deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: O365 Suspicious Admin Email Forwarding deprecated_in_version: 5.2.0 @@ -170,12 +170,12 @@ detections: - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Osquery pack - ColdRoot detection deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Windows Modify Registry Reg Restore deprecated_in_version: 5.2.0 @@ -186,7 +186,7 @@ detections: - deprecated_content: Kubernetes GCP detect most active service accounts by pod deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Scheduled tasks used in BadRabbit ransomware deprecated_in_version: 5.2.0 @@ -197,7 +197,7 @@ detections: - deprecated_content: Suspicious Rundll32 Rename deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Remote System Discovery with Net deprecated_in_version: 5.2.0 @@ -211,23 +211,23 @@ detections: - deprecated_content: Remote System Discovery with Net deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Sensitive Group Discovery With Net - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Suspicious Changes to File Associations deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: GCP Detect high risk permissions by resource and account deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Office Product Writing cab or inf deprecated_in_version: 5.2.0 @@ -238,12 +238,12 @@ detections: - deprecated_content: Identify New User Accounts deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Office Product Spawn CMD Process deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Windows DLL Search Order Hijacking Hunt @@ -263,7 +263,7 @@ detections: - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Detect Spike in Security Group Activity deprecated_in_version: 5.2.0 @@ -275,7 +275,7 @@ detections: - deprecated_content: Office Product Spawning BITSAdmin deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Create local admin accounts using net exe @@ -287,7 +287,7 @@ detections: - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Windows Office Product Spawning MSDT deprecated_in_version: 5.2.0 @@ -298,18 +298,18 @@ detections: - deprecated_content: Detect Spike in AWS API Activity deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Office Product Spawning Windows Script Host deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Prohibited Software On Endpoint deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Attacker Tools On Endpoint - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country @@ -332,19 +332,19 @@ detections: - deprecated_content: Detect Critical Alerts from Security Tools deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Microsoft Defender Incident Alerts - deprecated_content: Excel Spawning PowerShell deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Office Application Spawn rundll32 process deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Excessive Usage Of Net App @@ -374,7 +374,7 @@ detections: - deprecated_content: Suspicious Email - UBA Anomaly deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Detect web traffic to dynamic domain providers deprecated_in_version: 5.2.0 @@ -392,17 +392,17 @@ detections: - deprecated_content: Kubernetes AWS detect RBAC authorization by account deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Remote Registry Key modifications deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: O365 Suspicious User Email Forwarding deprecated_in_version: 5.2.0 @@ -414,13 +414,13 @@ detections: - deprecated_content: Office Product Spawning MSHTA deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Kubernetes AWS detect most active service accounts by pod deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Correlation by Repository and Risk deprecated_in_version: 5.2.0 @@ -431,12 +431,12 @@ detections: - deprecated_content: Kubernetes Azure detect RBAC authorization by account deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Clients Connecting to Multiple DNS Servers deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Excessive Service Stop Attempt deprecated_in_version: 5.2.0 @@ -454,7 +454,7 @@ detections: - deprecated_content: Suspicious writes to System Volume Information deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Detect new user AWS Console Login deprecated_in_version: 5.2.0 @@ -475,12 +475,12 @@ detections: - deprecated_content: Detection of DNS Tunnels deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2 deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Office Document Creating Schedule Task deprecated_in_version: 5.2.0 @@ -498,7 +498,7 @@ detections: - deprecated_content: Unsuccessful Netbackup backups deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703 deprecated_in_version: 5.2.0 @@ -509,7 +509,7 @@ detections: - deprecated_content: Winword Spawning Cmd deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: GCP Kubernetes cluster scan detection @@ -522,12 +522,12 @@ detections: - deprecated_content: Kubernetes GCP detect suspicious kubectl calls deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: gcp detect oauth token abuse deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Correlation by User and Risk deprecated_in_version: 5.2.0 @@ -544,7 +544,7 @@ detections: - deprecated_content: Office Product Spawning Wmic deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Extraction of Registry Hives @@ -588,17 +588,17 @@ detections: - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Reg exe used to hide files directories via registry keys deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Detect Long DNS TXT Record Response deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Password Policy Discovery with Net deprecated_in_version: 5.2.0 @@ -622,12 +622,12 @@ detections: - deprecated_content: Kubernetes Azure detect suspicious kubectl calls deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Kubernetes GCP detect sensitive role access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Detect Webshell Exploit Behavior deprecated_in_version: 5.2.0 @@ -638,17 +638,17 @@ detections: - deprecated_content: DNS record changed deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Unsigned Image Loaded by LSASS deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Detect USB device insertion deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Windows Network Share Interaction With Net deprecated_in_version: 5.2.0 @@ -713,7 +713,7 @@ detections: - deprecated_content: Windows hosts file modification deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: MSHTML Module Load in Office Product deprecated_in_version: 5.2.0 @@ -731,7 +731,7 @@ detections: - deprecated_content: Web Fraud - Account Harvesting deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Office Spawning Control deprecated_in_version: 5.2.0 @@ -742,7 +742,7 @@ detections: - deprecated_content: Detect Activity Related to Pass the Hash Attacks deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Deleting Of Net Users deprecated_in_version: 5.2.0 @@ -753,7 +753,7 @@ detections: - deprecated_content: Suspicious File Write deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: AWS EKS Kubernetes cluster sensitive object access deprecated_in_version: 5.2.0 @@ -765,7 +765,7 @@ detections: - deprecated_content: Spectre and Meltdown Vulnerable Systems deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: EC2 Instance Started With Previously Unseen User deprecated_in_version: 5.2.0 @@ -777,13 +777,13 @@ detections: - deprecated_content: Office Product Spawning CertUtil deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Kubernetes GCP detect RBAC authorizations by account deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Office Application Drop Executable deprecated_in_version: 5.2.0 @@ -794,12 +794,12 @@ detections: - deprecated_content: Kubernetes Azure active service accounts by pod namespace deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Kubernetes Azure pod scan fingerprint deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Detect Spike in Network ACL Activity deprecated_in_version: 5.2.0 @@ -811,13 +811,13 @@ detections: - deprecated_content: Suspicious Powershell Command-Line Arguments deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Malicious PowerShell Process - Encoded Command - deprecated_content: Office Application Spawn Regsvr32 process deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Detect API activity from users without MFA @@ -830,12 +830,12 @@ detections: - deprecated_content: Kubernetes Azure detect sensitive object access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Web Fraud - Password Sharing Across Accounts deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Disabling Net User Account deprecated_in_version: 5.2.0 @@ -846,17 +846,17 @@ detections: - deprecated_content: GCP Detect accounts with high risk roles by project deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Extended Period Without Successful Netbackup Backups deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Office Product Spawning Rundll32 with no DLL deprecated_in_version: 5.2.0 @@ -881,7 +881,7 @@ detections: - deprecated_content: Uncommon Processes On Endpoint deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Attacker Tools On Endpoint - deprecated_content: Dump LSASS via procdump Rename @@ -900,62 +900,62 @@ detections: - deprecated_content: Excel Spawning Windows Script Host deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: GitHub Actions Disable Security Workflow deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Github Commit Changes In Master deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Github Commit In Develop deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: GitHub Dependabot Alert deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: GitHub Pull Request from Unknown User deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Known Services Killed by Ransomware deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Remote Desktop Network Bruteforce deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Suspicious Driver Loaded Path deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Suspicious Event Log Service Behavior deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Suspicious Process File Path deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Windows Service Stop Via Net and SC Application deprecated_in_version: 5.3.0 deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] baselines: - deprecated_content: Add Prohibited Processes to Enterprise Security @@ -1250,78 +1250,78 @@ investigations: reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' replacement_content: [] stories: - - deprecated_content: AWS Cryptomining - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: AWS Suspicious Provisioning Activities - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Common Phishing Frameworks - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Container Implantation Monitoring and Investigation - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Host Redirection - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Kubernetes Sensitive Role Activity - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Lateral Movement - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Monitor Backup Solution - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Monitor for Unauthorized Software - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Office 365 Detections - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Spectre And Meltdown Vulnerabilities - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Suspicious AWS EC2 Activities - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Unusual AWS EC2 Modifications - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Web Fraud Detection - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] - - deprecated_content: Nexus APT Threat Activity - deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: The detection does not work as expected and is now deprecated - replacement_content: [] + - deprecated_content: AWS Cryptomining + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: AWS Suspicious Provisioning Activities + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Common Phishing Frameworks + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Container Implantation Monitoring and Investigation + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Host Redirection + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Kubernetes Sensitive Role Activity + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Lateral Movement + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Monitor Backup Solution + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Monitor for Unauthorized Software + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Office 365 Detections + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Spectre And Meltdown Vulnerabilities + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Suspicious AWS EC2 Activities + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Unusual AWS EC2 Modifications + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Web Fraud Detection + deprecated_in_version: 5.2.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] + - deprecated_content: Nexus APT Threat Activity + deprecated_in_version: 5.4.0 + deprecated_date: 2025-03-12 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: [] \ No newline at end of file From bebfe2e13e2d5b89afd5fd7514794dbcef7a9ea5 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Thu, 13 Mar 2025 18:12:45 -0700 Subject: [PATCH 33/67] updating lookups from latest mapping --- lookups/deprecation_info.csv | 195 +++++++++++++++++++++++++++++++++++ lookups/deprecation_info.yml | 9 ++ 2 files changed, 204 insertions(+) create mode 100644 lookups/deprecation_info.csv create mode 100644 lookups/deprecation_info.yml diff --git a/lookups/deprecation_info.csv b/lookups/deprecation_info.csv new file mode 100644 index 0000000000..ca41e89981 --- /dev/null +++ b/lookups/deprecation_info.csv @@ -0,0 +1,195 @@ +Name,Content Type,Deprecated in Version,Reason,Migration Guide,Replacement Content +ESCU - ASL AWS Excessive Security Scanning - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aba1860-9617-4af9-b19d-aecac16fe4f2 +ESCU - First time seen command line argument - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Windows connhost exe started forcefully - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Detect Mimikatz Using Loaded Images - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Kubernetes Azure detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Web Fraud - Anomalous User Clickspeed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c6ddbf53-9715-49f3-bb4c-fb2e8a309cda +ESCU - EC2 Instance Started With Previously Unseen AMI - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc24922d-987c-4645-b288-f8c73ec194c4 +ESCU - Domain Group Discovery With Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44 +ESCU - Kubernetes AWS detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Winword Spawning Windows Script Host - Rule,Detection,5.2.0,"The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level. +This would ease management and false positives tuning.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Winword Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Attempted Credential Dump From Registry via Reg exe - Rule,Detection,5.2.0,"This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e +ESCU - Detect processes used for System Network Configuration Discovery - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3f0b95e3-3195-46ac-bea3-84fb59e7fac5 +ESCU - Execution of File With Spaces Before Extension - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b06a555e-dce0-417d-a2eb-28a5d8d66ef7 +ESCU - EC2 Instance Started In Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/fa4089e2-50e3-40f7-8469-d2cc1564ca59 +ESCU - Office Document Spawned Child Process To Download - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f02b64b8-cbea-4f75-bf77-7a05111566b1 +ESCU - Detect new API calls from user roles - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f +ESCU - Cmdline Tool Not Executed In CMD Shell - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2afa393f-b88d-41b7-9793-623c93a2dfde +ESCU - Linux Auditd Find Private Keys - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/892eb674-3344-4143-8e52-4775b1daf3f1 +ESCU - Detect AWS API Activities From Unapproved Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Monitor DNS For Brand Abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Kubernetes GCP detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Kubernetes Azure scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - ASL AWS Password Policy Changes - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - O365 Suspicious Admin Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24 +ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e7ecc5e0-88df-48b9-91af-51104c68f02f +ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Osquery pack - ColdRoot detection - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Windows Modify Registry Reg Restore - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a17af481-e2ad-494c-9da6-afb4d243a019 +ESCU - Kubernetes GCP detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Scheduled tasks used in BadRabbit ransomware - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d5af132c-7c17-439c-9d31-13d55340f36c +ESCU - Suspicious Rundll32 Rename - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,"This analytic was focusing on 2 separate and unrelated type of threats or actions. It was split into other analytics, namely: + +Windows Network Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277 +Windows Sensitive Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4dc3951f-b3f8-4f46-b412-76a483f72277 +ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af +ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Suspicious Changes to File Associations - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - GCP Detect high risk permissions by resource and account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Office Product Writing cab or inf - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/dbdd251e-dd45-4ec9-a555-f5e151391746 +ESCU - Identify New User Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Office Product Spawn CMD Process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Windows DLL Search Order Hijacking Hunt - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/79c7d1fc-64c7-91be-a616-ccda752efe81 +ESCU - ASL AWS CreateAccessKey - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/81a9f2fe-1697-473c-af1d-086b0d8b63c8 +ESCU - Okta ThreatInsight Login Failure with High Unknown users - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Detect Spike in Security Group Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d4dfb7f3-7a37-498a-b5df-f19334e871af +ESCU - Office Product Spawning BITSAdmin - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Create local admin accounts using net exe - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2c568c34-bb57-4b43-9d75-19c605b98e70 +ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Windows Office Product Spawning MSDT - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a3148fad-3734-4b7f-9a71-62f08d39fab1 +ESCU - Detect Spike in AWS API Activity - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Office Product Spawning Windows Script Host - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Prohibited Software On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893 +ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/94994255-3acf-4213-9b3f-0494df03bb31 +ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,"As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender Incident Alerts. Going forward analytics from leveraging alerts from vendors will have their specific analytics.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/38f034ed-1598-46c8-95e8-14edf05fdf5d +ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/13435b55-afd8-46d4-9045-7d5457f430a5 +ESCU - Excel Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Office Application Spawn rundll32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Excessive Usage Of Net App - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38 +ESCU - Elevated Group Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af +ESCU - Local Account Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72 +ESCU - Windows Command Shell Fetch Env Variables - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/aec157f4-8783-4584-aca6-754c4dc7fba9 +ESCU - Suspicious Email - UBA Anomaly - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Detect web traffic to dynamic domain providers - Rule,Detection,5.2.0,Updated to use a different log source,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a1e761ac-1344-4dbd-88b2-3f34c912d359 +ESCU - Okta Failed SSO Attempts - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5f661629-9750-4cb9-897c-1f05d6db8727 +ESCU - Kubernetes AWS detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Remote Registry Key modifications - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - O365 Suspicious User Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24 +ESCU - Office Product Spawning MSHTA - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Kubernetes AWS detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Correlation by Repository and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67 +ESCU - Kubernetes Azure detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Clients Connecting to Multiple DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Excessive Service Stop Attempt - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8f3a614f-6b98-4f7d-82dd-d0df38452a8b +ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/de365ffa-42f5-46b5-b43f-fa72290b8218 +ESCU - Suspicious writes to System Volume Information - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Detect new user AWS Console Login - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc91a8cd-35e7-4bb2-6140-e756cc46fd71 +ESCU - Domain Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that looked only for commands that tries to query info about the users via net user /do. This had a couple of issues, such as triggering on creation of users via the /add flag etc.. +It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72 +ESCU - Detection of DNS Tunnels - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Detect DNS requests to Phishing Sites leveraging EvilGinx2 - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Office Document Creating Schedule Task - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d7297cfa-1f04-4714-bfbe-3679e0666959 +ESCU - Okta Account Locked Out - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1 +ESCU - Unsuccessful Netbackup backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8148c29c-c952-11eb-9255-acde48001122 +ESCU - Winword Spawning Cmd - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - GCP Kubernetes cluster scan detection - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f9cadf4e-df22-4f4e-a08f-9d3344c2165d +ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - gcp detect oauth token abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Correlation by User and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67 +ESCU - Processes created by netsh - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b89919ed-fe5f-492c-b139-95dbb162040e +ESCU - Office Product Spawning Wmic - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Extraction of Registry Hives - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e +ESCU - Attempt To Stop Security Service - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/9ed27cea-4e27-4eff-b2c6-aac9e78a7517 +ESCU - Windows MSIExec With Network Connections - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0fd38c7-f71a-43a2-870e-f3ca06bcdd99 +ESCU - Windows Query Registry Reg Save - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/466379bc-0f47-476c-8202-16ef38112e0d +ESCU - Cloud Network Access Control List Deleted - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ada0f478-84a8-4641-a3f1-d82362d6fd75 +ESCU - O365 Suspicious Rights Delegation - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2246c142-a678-45f8-8546-aaed7e0efd30 +ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Reg exe used to hide files directories via registry keys - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Detect Long DNS TXT Record Response - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Password Policy Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e52f7865-be78-46bf-b7ed-150fbe447613 +ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f86a8ec9-b042-45eb-92f4-e9ed1d781078 +ESCU - Network Connection Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/86a5b949-679b-4197-8d4c-9c180a818c45 +ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Kubernetes GCP detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Detect Webshell Exploit Behavior - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2d4470ef-7158-4b47-b68b-1f7f16382156 +ESCU - DNS record changed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Unsigned Image Loaded by LSASS - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Detect USB device insertion - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Windows Network Share Interaction With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e51fbdb0-0be0-474f-92ea-d289f71a695e +ESCU - Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 / Windows Excessive Usage Of Net App.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38 +ESCU - Change Default File Association - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a +ESCU - Windows Lateral Tool Transfer RemCom - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7e3d68db-ea4d-419b-adbd-e14a525ecf09 +ESCU - Office Document Executing Macro Code - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7cfec906-2697-43f7-898b-83634a051d9a +ESCU - Okta Account Lockout Events - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1 +ESCU - Abnormally High AWS Instances Launched by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f2361e9f-3928-496c-a556-120cd4223a65 +ESCU - EC2 Instance Modified With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f +ESCU - Windows Valid Account With Never Expires Password - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/11f93009-8083-43fd-82a7-821fcbdc8342 +ESCU - Windows hosts file modification - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - MSHTML Module Load in Office Product - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4cc015c9-687c-40d2-adcc-46350f66e10c +ESCU - Abnormally High AWS Instances Terminated by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ef629fc9-1583-4590-b62a-f2247fbf7bbf +ESCU - Web Fraud - Account Harvesting - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Office Spawning Control - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/081c485d-ac8d-4bee-ad4c-525772fead4d +ESCU - Detect Activity Related to Pass the Hash Attacks - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Deleting Of Net Users - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e +ESCU - Suspicious File Write - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/40a064c1-4ec1-4381-9e35-61192ba8ef82 +ESCU - Spectre and Meltdown Vulnerable Systems - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - EC2 Instance Started With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/37a0ec8d-827e-4d6d-8025-cedf31f3a149 +ESCU - Office Product Spawning CertUtil - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Office Application Drop Executable - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7ac0fced-9eae-4381-a748-90dcd1aa9393 +ESCU - Kubernetes Azure active service accounts by pod namespace - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Kubernetes Azure pod scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Detect Spike in Network ACL Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0840ddf1-8c89-46ff-b730-c8d6722478c0 +ESCU - Suspicious Powershell Command-Line Arguments - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c4db14d9-7909-48b4-a054-aa14d89dbb19 +ESCU - Office Application Spawn Regsvr32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Detect API activity from users without MFA - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a520b1fe-cc9e-4f56-b762-18354594c52f +ESCU - Kubernetes Azure detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Web Fraud - Password Sharing Across Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Disabling Net User Account - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0359e05-c87b-4354-83d8-aee0d890243f +ESCU - GCP Detect accounts with high risk roles by project - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Extended Period Without Successful Netbackup Backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Office Product Spawning Rundll32 with no DLL - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f28e787e-69ca-480e-9f98-ab970e6d4bcc +ESCU - Okta ThreatInsight Suspected PasswordSpray Attack - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/140504ae-5fe2-4d65-b2bc-a211813fbca6 +ESCU - Net Localgroup Discovery - Rule,Detection,5.2.0,Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44 +ESCU - Uncommon Processes On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893 +ESCU - Dump LSASS via procdump Rename - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3742ebfe-64c2-11eb-ae93-0242ac130002 +ESCU - Okta Two or More Rejected Okta Pushes - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/826dbaae-a1e6-4c8c-b384-d16898956e73 +ESCU - Excel Spawning Windows Script Host - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - GitHub Actions Disable Security Workflow - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Github Commit Changes In Master - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Github Commit In Develop - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - GitHub Dependabot Alert - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - GitHub Pull Request from Unknown User - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Known Services Killed by Ransomware - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Remote Desktop Network Bruteforce - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Suspicious Driver Loaded Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Suspicious Event Log Service Behavior - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Suspicious Process File Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Windows Service Stop Via Net and SC Application - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +ESCU - Add Prohibited Processes to Enterprise Security,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, +ESCU - Baseline of API Calls per User ARN,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, +ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, +ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, +ESCU - Previously seen API call per user roles in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, +ESCU - Previously Seen AWS Provisioning Activity Sources,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, +ESCU - Previously Seen EC2 AMIs,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, +ESCU - Previously Seen EC2 Instance Types,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, +ESCU - Previously Seen EC2 Launches By User,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, +ESCU - Previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, +ESCU - Update previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, +AWS Cryptomining,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +AWS Suspicious Provisioning Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Common Phishing Frameworks,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Container Implantation Monitoring and Investigation,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Host Redirection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Kubernetes Sensitive Role Activity,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Lateral Movement,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Monitor Backup Solution,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Monitor for Unauthorized Software,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Office 365 Detections,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Spectre And Meltdown Vulnerabilities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Suspicious AWS EC2 Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Unusual AWS EC2 Modifications,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Web Fraud Detection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +Nexus APT Threat Activity,Story,5.4.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, diff --git a/lookups/deprecation_info.yml b/lookups/deprecation_info.yml new file mode 100644 index 0000000000..dab74f8b34 --- /dev/null +++ b/lookups/deprecation_info.yml @@ -0,0 +1,9 @@ +name: deprecation_info +date: 2025-03-14 +version: 1 +id: d83dad4f-7bce-4979-bf07-a88c610da5f6 +author: Splunk Threat Research Team +lookup_type: csv +default_match: false +description: A lookup file for deprecation information +min_matches: 1 From 09d1d1c02f82330eace98f878b6c29f1785449d6 Mon Sep 17 00:00:00 2001 From: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com> Date: Fri, 14 Mar 2025 06:57:50 +0000 Subject: [PATCH 34/67] Updated TAs --- contentctl.yml | 4 ++-- .../cisco_secure_application_appdynamics_alerts.yml | 11 +++++++++-- data_sources/linux_secure.yml | 2 +- 3 files changed, 12 insertions(+), 5 deletions(-) diff --git a/contentctl.yml b/contentctl.yml index 401119b03c..b17f8ecc0c 100644 --- a/contentctl.yml +++ b/contentctl.yml @@ -221,8 +221,8 @@ apps: - uid: 2882 title: Splunk Add-on for AppDynamics appid: Splunk_TA_AppDynamics - version: 3.1.0 + version: 3.0.0 description: The Splunk Add-on for AppDynamics enables you to easily configure data inputs to pull data from AppDynamics' REST APIs - hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_310.tgz + hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_300.tgz githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd diff --git a/data_sources/cisco_secure_application_appdynamics_alerts.yml b/data_sources/cisco_secure_application_appdynamics_alerts.yml index d4a59e0eb7..cdd022fe72 100644 --- a/data_sources/cisco_secure_application_appdynamics_alerts.yml +++ b/data_sources/cisco_secure_application_appdynamics_alerts.yml @@ -9,7 +9,7 @@ sourcetype: appdynamics_security supported_TA: - name: Splunk Add-on for AppDynamics url: https://splunkbase.splunk.com/app/3471 - version: 3.1.0 + version: 3.0.0 fields: - SourceType - apiServerExternal @@ -133,4 +133,11 @@ fields: - _si - _sourcetype - _time -example_log: '{ "SourceType": "secure_app_attacks", "attackId": "24815279", "attackSource": "EXTERNAL", "attackOutcome": "EXPLOITED", "attackTypes": "{SSRF}", "attackEventTrigger": "", "application": "AD-Ecommerce", "tier": "Order-Processing-Services", "businessTransaction": "Checkout", "attackStatus": "OPEN", "attackLastDetected": "2025-01-31 12:30:22 +0000 UTC", "attackEvents": [{"attackOutcome":"EXPLOITED","eventType":"SOCKET_RESOLVE","attackTypes":"SSRF","timestamp":"2025-01-31T12:30:22Z","applicationName":"AD-Ecommerce","tierName":"Order-Processing-Services","maliciousIpOut":"","maliciousIpSourceOut":"","detailJson":{"classname":"java.net.SocketPermission","ptype":"SOCKET","socketOut":"www.cisco.com","hostContext":"www.cisco.com","methodName":"sun.net.www.http.HttpClient.openServer","apiServerExternal":true,"apiServerInUrl":true},"blocked":false,"blockedReason":"","vulnerableMethod":"org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:868)","matchedCveName":"CVE-2020-13934","keyInfo":"","cveId":"a21931cd-52fa-11ec-a8b2-8e3051145156","stackTrace":"java.lang.SecurityManager.checkConnect(SecurityManager.java:1051)\nsun.net.www.http.HttpClient.openServer(HttpClient.java:510)\nsun.net.www.protocol.https.HttpsClient.\u003cinit\u003e(HttpsClient.java:264)\nsun.net.www.protocol.https.HttpsClient.New(HttpsClient.java:367)\nsun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.getNewHttpClient(AbstractDelegateHttpsURLConnection.java:191)\norg.apache.activemq.artemis.spi.core.security.jaas.LDAPLoginModule.login(SomeFile.java:12)\nsun.net.www.protocol.http.HttpURLConnection.plainConnect0(HttpURLConnection.java:1138)\nsun.net.www.protocol.http.HttpURLConnection$6.run(HttpURLConnection.java:1022)\nsun.net.www.protocol.http.HttpURLConnection$6.run(HttpURLConnection.java:1020)\njava.security.AccessController.doPrivileged(Native Method)\njava.security.AccessController.doPrivilegedWithCombiner(AccessController.java:782)\nsun.net.www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:1019)\nsun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:177)\nsun.net.www.protocol.http.HttpURLConnection.getInputStream0(HttpURLConnection.java:1546)\nsun.net.www.protocol.http.HttpURLConnection.access$200(HttpURLConnection.java:91)\nsun.net.www.protocol.http.HttpURLConnection$9.run(HttpURLConnection.java:1466)\nsun.net.www.protocol.http.HttpURLConnection$9.run(HttpURLConnection.java:1464)\njava.security.AccessController.doPrivileged(Native Method)\njava.security.AccessController.doPrivilegedWithCombiner(AccessController.java:782)\nsun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:1463)\nsun.net.www.protocol.https.HttpsURLConnectionImpl.getInputStream(HttpsURLConnectionImpl.java:254)\nservlet.ArgentoDemoApp$GenericExecution._executeServletCommand(ArgentoDemoApp.java:850)\nservlet.ArgentoDemoApp$GenericExecution.executeServletCommand(ArgentoDemoApp.java:778)\nservlet.ArgentoDemoApp$MyApplicationExecution.executeServletCommand(ArgentoDemoApp.java:718)\nservlet.ArgentoDemoApp._doGet(ArgentoDemoApp.java:441)\nservlet.ArgentoDemoApp.doGet(ArgentoDemoApp.java:376)\njavax.servlet.http.HttpServlet.service(HttpServlet.java:634)\njavax.servlet.http.HttpServlet.service(HttpServlet.java:741)\norg.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:231)\norg.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\norg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:53)\norg.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)\norg.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\norg.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:202)\norg.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96)\norg.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:541)\norg.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:139)\norg.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:92)\norg.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:690)\norg.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:74)\norg.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:343)\norg.apache.coyote.http11.Http11Processor.service(Http11Processor.java:373)\norg.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:65)\norg.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:868)\norg.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1590)\norg.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)\njava.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)\njava.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)\norg.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)\njava.lang.Thread.run(Thread.java:745)\n","jvmId":"EEcommerce_MS_NODE","maliciousIpSource":"","webTransactionUrl":"https://localhost:8088/argentoDemoApp/execute?upload=https://www.cisco.com/c/dam/cdc/t/ctm-core.js","clientAddressType":4,"clientAddress":"218.132.217.179","serverPort":"1047","serverAddress":"75.155.150.130","clientPort":"68389","serverName":"/usr/src/argento/prod/demo-run/tomcat-demo-app/webapps/argentoDemoApp/","vulnerabilityInfo":{"cvePublishDate":"2020-07-15T16:40:14.601976Z","cvssScore":5.3,"cvssSeverity":"MEDIUM","cveNvdUrl":"https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-584427","incidentFirstDetected":"2020-07-15T16:40:14.601976Z","kennaScore":53.0971,"library":"org.apache.tomcat.embed:tomcat-embed-core","title":"Denial of Service (DoS)","type":"java","kennaActiveInternetBreach":false,"kennaEasilyExploitable":false,"kennaMalwareExploitable":false,"kennaPredictedExploitable":true,"kennaPopularTarget":false}}]}' +example_log: '{ "SourceType": "secure_app_attacks", "attackId": "24815279", "attackSource": + "EXTERNAL", "attackOutcome": "EXPLOITED", "attackTypes": "{SSRF}", "attackEventTrigger": + "", "application": "AD-Ecommerce", "tier": "Order-Processing-Services", "businessTransaction": + "Checkout", "attackStatus": "OPEN", "attackLastDetected": "2025-01-31 12:30:22 + +0000 UTC", "attackEvents": [{"attackOutcome":"EXPLOITED","eventType":"SOCKET_RESOLVE","attackTypes":"SSRF","timestamp":"2025-01-31T12:30:22Z","applicationName":"AD-Ecommerce","tierName":"Order-Processing-Services","maliciousIpOut":"","maliciousIpSourceOut":"","detailJson":{"classname":"java.net.SocketPermission","ptype":"SOCKET","socketOut":"www.cisco.com","hostContext":"www.cisco.com","methodName":"sun.net.www.http.HttpClient.openServer","apiServerExternal":true,"apiServerInUrl":true},"blocked":false,"blockedReason":"","vulnerableMethod":"org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:868)","matchedCveName":"CVE-2020-13934","keyInfo":"","cveId":"a21931cd-52fa-11ec-a8b2-8e3051145156","stackTrace":"java.lang.SecurityManager.checkConnect(SecurityManager.java:1051)\nsun.net.www.http.HttpClient.openServer(HttpClient.java:510)\nsun.net.www.protocol.https.HttpsClient.\u003cinit\u003e(HttpsClient.java:264)\nsun.net.www.protocol.https.HttpsClient.New(HttpsClient.java:367)\nsun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.getNewHttpClient(AbstractDelegateHttpsURLConnection.java:191)\norg.apache.activemq.artemis.spi.core.security.jaas.LDAPLoginModule.login(SomeFile.java:12)\nsun.net.www.protocol.http.HttpURLConnection.plainConnect0(HttpURLConnection.java:1138)\nsun.net.www.protocol.http.HttpURLConnection$6.run(HttpURLConnection.java:1022)\nsun.net.www.protocol.http.HttpURLConnection$6.run(HttpURLConnection.java:1020)\njava.security.AccessController.doPrivileged(Native + Method)\njava.security.AccessController.doPrivilegedWithCombiner(AccessController.java:782)\nsun.net.www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:1019)\nsun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:177)\nsun.net.www.protocol.http.HttpURLConnection.getInputStream0(HttpURLConnection.java:1546)\nsun.net.www.protocol.http.HttpURLConnection.access$200(HttpURLConnection.java:91)\nsun.net.www.protocol.http.HttpURLConnection$9.run(HttpURLConnection.java:1466)\nsun.net.www.protocol.http.HttpURLConnection$9.run(HttpURLConnection.java:1464)\njava.security.AccessController.doPrivileged(Native + Method)\njava.security.AccessController.doPrivilegedWithCombiner(AccessController.java:782)\nsun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:1463)\nsun.net.www.protocol.https.HttpsURLConnectionImpl.getInputStream(HttpsURLConnectionImpl.java:254)\nservlet.ArgentoDemoApp$GenericExecution._executeServletCommand(ArgentoDemoApp.java:850)\nservlet.ArgentoDemoApp$GenericExecution.executeServletCommand(ArgentoDemoApp.java:778)\nservlet.ArgentoDemoApp$MyApplicationExecution.executeServletCommand(ArgentoDemoApp.java:718)\nservlet.ArgentoDemoApp._doGet(ArgentoDemoApp.java:441)\nservlet.ArgentoDemoApp.doGet(ArgentoDemoApp.java:376)\njavax.servlet.http.HttpServlet.service(HttpServlet.java:634)\njavax.servlet.http.HttpServlet.service(HttpServlet.java:741)\norg.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:231)\norg.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\norg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:53)\norg.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)\norg.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\norg.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:202)\norg.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96)\norg.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:541)\norg.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:139)\norg.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:92)\norg.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:690)\norg.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:74)\norg.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:343)\norg.apache.coyote.http11.Http11Processor.service(Http11Processor.java:373)\norg.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:65)\norg.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:868)\norg.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1590)\norg.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)\njava.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)\njava.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)\norg.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)\njava.lang.Thread.run(Thread.java:745)\n","jvmId":"EEcommerce_MS_NODE","maliciousIpSource":"","webTransactionUrl":"https://localhost:8088/argentoDemoApp/execute?upload=https://www.cisco.com/c/dam/cdc/t/ctm-core.js","clientAddressType":4,"clientAddress":"218.132.217.179","serverPort":"1047","serverAddress":"75.155.150.130","clientPort":"68389","serverName":"/usr/src/argento/prod/demo-run/tomcat-demo-app/webapps/argentoDemoApp/","vulnerabilityInfo":{"cvePublishDate":"2020-07-15T16:40:14.601976Z","cvssScore":5.3,"cvssSeverity":"MEDIUM","cveNvdUrl":"https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-584427","incidentFirstDetected":"2020-07-15T16:40:14.601976Z","kennaScore":53.0971,"library":"org.apache.tomcat.embed:tomcat-embed-core","title":"Denial + of Service (DoS)","type":"java","kennaActiveInternetBreach":false,"kennaEasilyExploitable":false,"kennaMalwareExploitable":false,"kennaPredictedExploitable":true,"kennaPopularTarget":false}}]}' diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index 468d387446..c3bb4697bb 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -9,7 +9,7 @@ sourcetype: linux_secure supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 + version: 10.0.0 fields: - _time - action From e49f84d06dcf4b6104b84cc9248dcef2e00958d0 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Fri, 14 Mar 2025 09:47:06 -0700 Subject: [PATCH 35/67] fixes --- contentctl.yml | 2 +- data_sources/linux_secure.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/contentctl.yml b/contentctl.yml index b17f8ecc0c..0fcd575b4a 100644 --- a/contentctl.yml +++ b/contentctl.yml @@ -218,7 +218,7 @@ apps: version: 3.1.0 description: description of app hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-github_310.tgz -- uid: 2882 +- uid: 3471 title: Splunk Add-on for AppDynamics appid: Splunk_TA_AppDynamics version: 3.0.0 diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index c3bb4697bb..468d387446 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -9,7 +9,7 @@ sourcetype: linux_secure supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.0.0 + version: 9.2.0 fields: - _time - action From 1120cea9a0f8b9ab6d1bf17e53debd79789a4446 Mon Sep 17 00:00:00 2001 From: Patrick Bareiss Date: Mon, 17 Mar 2025 12:24:08 +0100 Subject: [PATCH 36/67] Improve data source validation --- data_sources/asl_aws_cloudtrail.yml | 1 - data_sources/aws_cloudtrail.yml | 9 -------- ...s_multi_factor_authentication_disabled.yml | 6 +++--- ...mber_of_failed_authentications_from_ip.yml | 7 ++++--- detections/cloud/aws_updateloginprofile.yml | 21 ++++++++++--------- 5 files changed, 18 insertions(+), 26 deletions(-) diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml index edd56c9a67..32818e97f8 100644 --- a/data_sources/asl_aws_cloudtrail.yml +++ b/data_sources/asl_aws_cloudtrail.yml @@ -16,7 +16,6 @@ output_fields: - dest - user - user_agent -- status - src - vendor_account - vendor_region diff --git a/data_sources/aws_cloudtrail.yml b/data_sources/aws_cloudtrail.yml index 560f4ec819..e2734eacfe 100644 --- a/data_sources/aws_cloudtrail.yml +++ b/data_sources/aws_cloudtrail.yml @@ -11,12 +11,3 @@ supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 version: 7.9.1 -output_fields: -- action -- dest -- user -- user_agent -- src -- vendor_account -- vendor_region -- vendor_product diff --git a/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml b/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml index 9f331adb00..916df22a3a 100644 --- a/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml +++ b/detections/cloud/asl_aws_multi_factor_authentication_disabled.yml @@ -17,8 +17,8 @@ data_source: - ASL AWS CloudTrail search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice) | fillnull - | stats count min(_time) as firstTime max(_time) as lastTime by actor.user.uid api.operation actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region - | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent + | stats count min(_time) as firstTime max(_time) as lastTime by actor.user.uid api.operation api.service.name http_request.user_agent src_endpoint.ip actor.user.account.uid cloud.provider cloud.region + | rename actor.user.uid as user api.operation as action api.service.name as dest http_request.user_agent as user_agent src_endpoint.ip as src actor.user.account.uid as vendor_account cloud.provider as vendor_product cloud.region as vendor_region | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_multi_factor_authentication_disabled_filter`' how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App. @@ -47,7 +47,7 @@ rba: type: user score: 64 threat_objects: - - field: src_ip + - field: src type: ip_address tags: analytic_story: diff --git a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml index 81255cca76..97241dc694 100644 --- a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml @@ -16,7 +16,8 @@ data_source: - AWS CloudTrail ConsoleLogin search: '`cloudtrail` eventName=ConsoleLogin action=failure | bucket span=10m _time - | stats dc(_raw) AS distinct_attempts values(user_name) as tried_accounts by _time, src_ip + | stats dc(_raw) AS distinct_attempts values(user_name) as tried_accounts values(action) as action values(dest) as dest + values(vendor_account) as vendor_account values(vendor_region) as vendor_region values(vendor_product) as vendor_product values(user_agent) as user_agent by _time, src_ip | eventstats avg(distinct_attempts) as avg_attempts , stdev(distinct_attempts) as ip_std by _time | eval upperBound=(avg_attempts+ip_std*3) | eval isOutlier=if(distinct_attempts > 10 and distinct_attempts >= upperBound, 1, 0) @@ -47,13 +48,13 @@ drilldown_searches: latest_offset: $info_max_time$ rba: message: 'Unusual number of failed console login attempts (Count: $distinct_attempts$) - against users from IP Address - $src_ip$' + against users from IP Address - $src$' risk_objects: - field: tried_accounts type: user score: 54 threat_objects: - - field: src_ip + - field: src type: ip_address tags: analytic_story: diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml index c90f5d742a..6c831b3172 100644 --- a/detections/cloud/aws_updateloginprofile.yml +++ b/detections/cloud/aws_updateloginprofile.yml @@ -17,9 +17,10 @@ data_source: - AWS CloudTrail UpdateLoginProfile search: '`cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com errorCode = success | eval match=if(match(userIdentity.userName,requestParameters.userName), - 1,0) | search match=0 | stats count min(_time) as firstTime max(_time) as lastTime - by requestParameters.userName src eventName eventSource aws_account_id errorCode - userAgent eventID awsRegion userIdentity.userName user_arn | `security_content_ctime(firstTime)` + 1,0) | search match=0 + | stats count min(_time) as firstTime max(_time) as lastTime by actor.user.uid api.operation api.service.name http_request.user_agent src_endpoint.ip actor.user.account.uid cloud.provider cloud.region + | rename actor.user.uid as user api.operation as action api.service.name as dest http_request.user_agent as user_agent src_endpoint.ip as src actor.user.account.uid as vendor_account cloud.provider as vendor_product cloud.region as vendor_region + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_updateloginprofile_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. @@ -29,12 +30,12 @@ references: - https://bishopfox.com/blog/privilege-escalation-in-aws - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ drilldown_searches: -- name: View the detection results for - "$user_arn$" - search: '%original_detection_search% | search user_arn = "$user_arn$"' +- name: View the detection results for - "$user$" + search: '%original_detection_search% | search user = "$user$"' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ -- name: View risk events for the last 7 days for - "$user_arn$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user_arn$") +- name: View risk events for the last 7 days for - "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) @@ -43,11 +44,11 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: From IP address $src$, user agent $userAgent$ has trigged an event $eventName$ - for updating the existing login profile, potentially giving user $user_arn$ more + message: From IP address $src$, user agent $userAgent$ has trigged an event UpdateLoginProfile + for updating the existing login profile, potentially giving user $user$ more access privilleges risk_objects: - - field: user_arn + - field: user type: user score: 30 threat_objects: From 13f692c0521323a3126830254eef7568e10979e6 Mon Sep 17 00:00:00 2001 From: Patrick Bareiss Date: Mon, 17 Mar 2025 12:28:56 +0100 Subject: [PATCH 37/67] version bump --- detections/cloud/aws_updateloginprofile.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml index 6c831b3172..2c2f4f835b 100644 --- a/detections/cloud/aws_updateloginprofile.yml +++ b/detections/cloud/aws_updateloginprofile.yml @@ -1,6 +1,6 @@ name: AWS UpdateLoginProfile id: 2a9b80d3-6a40-4115-11ad-212bf3d0d111 -version: 8 +version: 9 date: '2025-02-10' author: Bhavin Patel, Splunk status: production From 850a172af4b9fc2c1fbf64f52405a64a77615246 Mon Sep 17 00:00:00 2001 From: Patrick Bareiss Date: Mon, 17 Mar 2025 13:02:18 +0100 Subject: [PATCH 38/67] bug fix --- .../aws_unusual_number_of_failed_authentications_from_ip.yml | 2 +- detections/cloud/aws_updateloginprofile.yml | 5 +++-- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml index 97241dc694..4c59fbe732 100644 --- a/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/aws_unusual_number_of_failed_authentications_from_ip.yml @@ -17,7 +17,7 @@ data_source: search: '`cloudtrail` eventName=ConsoleLogin action=failure | bucket span=10m _time | stats dc(_raw) AS distinct_attempts values(user_name) as tried_accounts values(action) as action values(dest) as dest - values(vendor_account) as vendor_account values(vendor_region) as vendor_region values(vendor_product) as vendor_product values(user_agent) as user_agent by _time, src_ip + values(vendor_account) as vendor_account values(vendor_region) as vendor_region values(vendor_product) as vendor_product values(user_agent) as user_agent by _time, src | eventstats avg(distinct_attempts) as avg_attempts , stdev(distinct_attempts) as ip_std by _time | eval upperBound=(avg_attempts+ip_std*3) | eval isOutlier=if(distinct_attempts > 10 and distinct_attempts >= upperBound, 1, 0) diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml index 2c2f4f835b..0534a0819d 100644 --- a/detections/cloud/aws_updateloginprofile.yml +++ b/detections/cloud/aws_updateloginprofile.yml @@ -18,8 +18,9 @@ data_source: search: '`cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com errorCode = success | eval match=if(match(userIdentity.userName,requestParameters.userName), 1,0) | search match=0 - | stats count min(_time) as firstTime max(_time) as lastTime by actor.user.uid api.operation api.service.name http_request.user_agent src_endpoint.ip actor.user.account.uid cloud.provider cloud.region - | rename actor.user.uid as user api.operation as action api.service.name as dest http_request.user_agent as user_agent src_endpoint.ip as src actor.user.account.uid as vendor_account cloud.provider as vendor_product cloud.region as vendor_region + | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region + | eval vendor_product = "AWS" + | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_updateloginprofile_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This From b3a3caeccae9f864c59b332b015437862ab8ac96 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 09:53:18 -0700 Subject: [PATCH 39/67] updating for manual test --- .../endpoint/windows_sql_server_critical_procedures_enabled.yml | 1 + detections/endpoint/windows_sql_server_startup_procedure.yml | 1 + .../endpoint/windows_sql_server_xp_cmdshell_config_change.yml | 1 + 3 files changed, 3 insertions(+) diff --git a/detections/endpoint/windows_sql_server_critical_procedures_enabled.yml b/detections/endpoint/windows_sql_server_critical_procedures_enabled.yml index 9fed3fb897..fde5c9f7ef 100644 --- a/detections/endpoint/windows_sql_server_critical_procedures_enabled.yml +++ b/detections/endpoint/windows_sql_server_critical_procedures_enabled.yml @@ -71,6 +71,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud security_domain: endpoint + manual_test: The risk message is dynamically generated in the SPL and it needs to be manually tested for integration testing. tests: - name: True Positive Test attack_data: diff --git a/detections/endpoint/windows_sql_server_startup_procedure.yml b/detections/endpoint/windows_sql_server_startup_procedure.yml index f229b0bd3b..ec7dcaeca4 100644 --- a/detections/endpoint/windows_sql_server_startup_procedure.yml +++ b/detections/endpoint/windows_sql_server_startup_procedure.yml @@ -60,6 +60,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud security_domain: endpoint + manual_test: The risk message is dynamically generated in the SPL and it needs to be manually tested for integration testing. tests: - name: True Positive Test attack_data: diff --git a/detections/endpoint/windows_sql_server_xp_cmdshell_config_change.yml b/detections/endpoint/windows_sql_server_xp_cmdshell_config_change.yml index aa9f81c6e3..a99a2646dd 100644 --- a/detections/endpoint/windows_sql_server_xp_cmdshell_config_change.yml +++ b/detections/endpoint/windows_sql_server_xp_cmdshell_config_change.yml @@ -72,6 +72,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud security_domain: endpoint + manual_test: The risk message is dynamically generated in the SPL and it needs to be manually tested for integration testing. tests: - name: True Positive Test attack_data: From 58d7d6052c9bc8788b658e3344932424b10b6205 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Mon, 17 Mar 2025 13:25:49 -0600 Subject: [PATCH 40/67] version updates --- detections/endpoint/any_powershell_downloadstring.yml | 2 +- detections/endpoint/attacker_tools_on_endpoint.yml | 2 +- .../endpoint/detect_regsvr32_application_control_bypass.yml | 2 +- .../endpoint/powershell_webrequest_using_memory_stream.yml | 2 +- detections/endpoint/system_user_discovery_with_whoami.yml | 2 +- detections/endpoint/w3wp_spawning_shell.yml | 2 +- .../windows_process_writing_file_to_world_writable_path.yml | 2 +- 7 files changed, 7 insertions(+), 7 deletions(-) diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml index 7f516361ff..3974f041fa 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/endpoint/any_powershell_downloadstring.yml @@ -1,6 +1,6 @@ name: Any Powershell DownloadString id: 4d015ef2-7adf-11eb-95da-acde48001122 -version: 9 +version: 10 date: '2025-02-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index a983aeb31d..9838d2984e 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,6 +1,6 @@ name: Attacker Tools On Endpoint id: a51bfe1a-94f0-48cc-b4e4-16a110145893 -version: 8 +version: 9 date: '2025-02-10' author: Bhavin Patel, Splunk status: production diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml index a3df354b36..a12339df48 100644 --- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml +++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml @@ -1,6 +1,6 @@ name: Detect Regsvr32 Application Control Bypass id: 070e9b80-6252-11eb-ae93-0242ac130002 -version: 9 +version: 10 date: '2025-02-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/powershell_webrequest_using_memory_stream.yml b/detections/endpoint/powershell_webrequest_using_memory_stream.yml index 2c0fa1ba0d..8a72593916 100644 --- a/detections/endpoint/powershell_webrequest_using_memory_stream.yml +++ b/detections/endpoint/powershell_webrequest_using_memory_stream.yml @@ -1,6 +1,6 @@ name: PowerShell WebRequest Using Memory Stream id: 103affa6-924a-4b53-aff4-1d5075342aab -version: 4 +version: 5 date: '2024-11-13' author: Steven Dick status: production diff --git a/detections/endpoint/system_user_discovery_with_whoami.yml b/detections/endpoint/system_user_discovery_with_whoami.yml index 594b175c8d..380d3d6ac0 100644 --- a/detections/endpoint/system_user_discovery_with_whoami.yml +++ b/detections/endpoint/system_user_discovery_with_whoami.yml @@ -1,6 +1,6 @@ name: System User Discovery With Whoami id: 894fc43e-6f50-47d5-a68b-ee9ee23e18f4 -version: 4 +version: 5 date: '2024-11-13' author: Mauricio Velazco, Splunk status: production diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml index 21d2e3fb4f..dcc6145ea5 100644 --- a/detections/endpoint/w3wp_spawning_shell.yml +++ b/detections/endpoint/w3wp_spawning_shell.yml @@ -1,6 +1,6 @@ name: W3WP Spawning Shell id: 0f03423c-7c6a-11eb-bc47-acde48001122 -version: 6 +version: 7 date: '2025-02-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml b/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml index 454d390356..5d244c589a 100644 --- a/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml +++ b/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml @@ -1,6 +1,6 @@ name: Windows Process Writing File to World Writable Path id: c051b68c-60f7-4022-b3ad-773bec7a225b -version: 4 +version: 5 date: '2024-11-13' author: Michael Haag, Splunk data_source: [] From 81a16341a3396153082b6e072f1593ab7b92b3e3 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 14:28:53 -0700 Subject: [PATCH 41/67] Revert "version updates" This reverts commit 58d7d6052c9bc8788b658e3344932424b10b6205. --- detections/endpoint/any_powershell_downloadstring.yml | 2 +- detections/endpoint/attacker_tools_on_endpoint.yml | 2 +- .../endpoint/detect_regsvr32_application_control_bypass.yml | 2 +- .../endpoint/powershell_webrequest_using_memory_stream.yml | 2 +- detections/endpoint/system_user_discovery_with_whoami.yml | 2 +- detections/endpoint/w3wp_spawning_shell.yml | 2 +- .../windows_process_writing_file_to_world_writable_path.yml | 2 +- 7 files changed, 7 insertions(+), 7 deletions(-) diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml index 3974f041fa..7f516361ff 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/endpoint/any_powershell_downloadstring.yml @@ -1,6 +1,6 @@ name: Any Powershell DownloadString id: 4d015ef2-7adf-11eb-95da-acde48001122 -version: 10 +version: 9 date: '2025-02-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 9838d2984e..a983aeb31d 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,6 +1,6 @@ name: Attacker Tools On Endpoint id: a51bfe1a-94f0-48cc-b4e4-16a110145893 -version: 9 +version: 8 date: '2025-02-10' author: Bhavin Patel, Splunk status: production diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml index a12339df48..a3df354b36 100644 --- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml +++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml @@ -1,6 +1,6 @@ name: Detect Regsvr32 Application Control Bypass id: 070e9b80-6252-11eb-ae93-0242ac130002 -version: 10 +version: 9 date: '2025-02-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/powershell_webrequest_using_memory_stream.yml b/detections/endpoint/powershell_webrequest_using_memory_stream.yml index 8a72593916..2c0fa1ba0d 100644 --- a/detections/endpoint/powershell_webrequest_using_memory_stream.yml +++ b/detections/endpoint/powershell_webrequest_using_memory_stream.yml @@ -1,6 +1,6 @@ name: PowerShell WebRequest Using Memory Stream id: 103affa6-924a-4b53-aff4-1d5075342aab -version: 5 +version: 4 date: '2024-11-13' author: Steven Dick status: production diff --git a/detections/endpoint/system_user_discovery_with_whoami.yml b/detections/endpoint/system_user_discovery_with_whoami.yml index 380d3d6ac0..594b175c8d 100644 --- a/detections/endpoint/system_user_discovery_with_whoami.yml +++ b/detections/endpoint/system_user_discovery_with_whoami.yml @@ -1,6 +1,6 @@ name: System User Discovery With Whoami id: 894fc43e-6f50-47d5-a68b-ee9ee23e18f4 -version: 5 +version: 4 date: '2024-11-13' author: Mauricio Velazco, Splunk status: production diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml index dcc6145ea5..21d2e3fb4f 100644 --- a/detections/endpoint/w3wp_spawning_shell.yml +++ b/detections/endpoint/w3wp_spawning_shell.yml @@ -1,6 +1,6 @@ name: W3WP Spawning Shell id: 0f03423c-7c6a-11eb-bc47-acde48001122 -version: 7 +version: 6 date: '2025-02-10' author: Michael Haag, Splunk status: production diff --git a/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml b/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml index 5d244c589a..454d390356 100644 --- a/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml +++ b/detections/endpoint/windows_process_writing_file_to_world_writable_path.yml @@ -1,6 +1,6 @@ name: Windows Process Writing File to World Writable Path id: c051b68c-60f7-4022-b3ad-773bec7a225b -version: 5 +version: 4 date: '2024-11-13' author: Michael Haag, Splunk data_source: [] From 89cc1aca90edcba24ec74f1d03ead86b4830f602 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 15:12:39 -0700 Subject: [PATCH 42/67] replacement stories --- deprecated/deprecated_detection_mapping.yml | 27 ++++++++++++++------- 1 file changed, 18 insertions(+), 9 deletions(-) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index c5d72406cb..d6a0025376 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -1254,12 +1254,14 @@ stories: deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] + replacement_content: + - Cloud Cryptomining - deprecated_content: AWS Suspicious Provisioning Activities deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] + replacement_content: + - Suspicious Cloud Provisioning Activities - deprecated_content: Common Phishing Frameworks deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 @@ -1269,7 +1271,8 @@ stories: deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] + replacement_content: + - Kubernetes Security - deprecated_content: Host Redirection deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 @@ -1279,12 +1282,14 @@ stories: deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] + replacement_content: + - Kubernetes Security - deprecated_content: Lateral Movement deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] + replacement_content: + - Compromised User Account - deprecated_content: Monitor Backup Solution deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 @@ -1299,7 +1304,8 @@ stories: deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] + replacement_content: + - Office 365 Account Takeover - deprecated_content: Spectre And Meltdown Vulnerabilities deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 @@ -1309,12 +1315,14 @@ stories: deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] + replacement_content: + - Suspicious Cloud Instance Activities - deprecated_content: Unusual AWS EC2 Modifications deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] + replacement_content: + - Suspicious Cloud Instance Activities - deprecated_content: Web Fraud Detection deprecated_in_version: 5.2.0 deprecated_date: 2025-03-12 @@ -1324,4 +1332,5 @@ stories: deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] \ No newline at end of file + replacement_content: + - China-Nexus Threat Activity \ No newline at end of file From a24a2f0a1b6ba2dcb4de24317593c7980d68cf29 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 15:30:39 -0700 Subject: [PATCH 43/67] updating next batch to 5.4.0 --- deprecated/deprecated_detection_mapping.yml | 24 ++++++++++----------- 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index d6a0025376..618796b43d 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -898,62 +898,62 @@ detections: replacement_content: - Okta Multiple Failed MFA Requests For User - deprecated_content: Excel Spawning Windows Script Host - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: GitHub Actions Disable Security Workflow - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Github Commit Changes In Master - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Github Commit In Develop - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: GitHub Dependabot Alert - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: GitHub Pull Request from Unknown User - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Known Services Killed by Ransomware - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Remote Desktop Network Bruteforce - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Suspicious Driver Loaded Path - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Suspicious Event Log Service Behavior - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Suspicious Process File Path - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] - deprecated_content: Windows Service Stop Via Net and SC Application - deprecated_in_version: 5.3.0 + deprecated_in_version: 5.4.0 deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: [] From 5dcad4a631aaf9f67af8e1b694a10f2bc5df0edb Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Mon, 17 Mar 2025 15:35:21 -0700 Subject: [PATCH 44/67] remove deprecated_date and replacement_content if there is no content defined --- deprecated/deprecated_detection_mapping.yml | 411 +------------------- 1 file changed, 21 insertions(+), 390 deletions(-) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index 618796b43d..c104358a54 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -1,69 +1,50 @@ detections: - deprecated_content: ASL AWS Excessive Security Scanning deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen Region - deprecated_content: First time seen command line argument deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Windows connhost exe started forcefully deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Detect Mimikatz Using Loaded Images deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Kubernetes Azure detect sensitive role access deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Web Fraud - Anomalous User Clickspeed deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created With Previously Unseen Instance Type - deprecated_content: EC2 Instance Started With Previously Unseen AMI deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created With Previously Unseen Image - deprecated_content: Domain Group Discovery With Net deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Group Discovery Via Net - deprecated_content: Kubernetes AWS detect sensitive role access deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Winword Spawning Windows Script Host deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: "The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level.\nThis would ease management @@ -72,13 +53,11 @@ detections: - Windows Office Product Spawned Uncommon Process - deprecated_content: Winword Spawning PowerShell deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Attempted Credential Dump From Registry via Reg exe deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine @@ -86,122 +65,92 @@ detections: - Windows Sensitive Registry Hive Dump Via CommandLine - deprecated_content: Detect processes used for System Network Configuration Discovery deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Potential System Network Configuration Discovery Activity - deprecated_content: Execution of File With Spaces Before Extension deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Execution of File with Multiple Extensions - deprecated_content: EC2 Instance Started In Previously Unseen Region deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created In Previously Unused Region - deprecated_content: Office Document Spawned Child Process To Download deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Child Process For Download - deprecated_content: Detect new API calls from user roles deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud API Calls From Previously Unseen User Roles - deprecated_content: Cmdline Tool Not Executed In CMD Shell deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Cmdline Tool Execution From Non-Shell Process - deprecated_content: Linux Auditd Find Private Keys deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Linux Auditd Private Keys and Certificate Enumeration - deprecated_content: Detect AWS API Activities From Unapproved Accounts deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Monitor DNS For Brand Abuse deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Kubernetes GCP detect sensitive object access deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Kubernetes Azure scan fingerprint deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: ASL AWS Password Policy Changes deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: O365 Suspicious Admin Email Forwarding deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Mailbox Email Forwarding Enabled - deprecated_content: AWS Cloud Provisioning From Previously Unseen City deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen City - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Osquery pack - ColdRoot detection deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Windows Modify Registry Reg Restore deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Registry Entries Restored Via Reg - deprecated_content: Kubernetes GCP detect most active service accounts by pod deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Scheduled tasks used in BadRabbit ransomware deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Scheduled Task Deleted Or Created via CMD - deprecated_content: Suspicious Rundll32 Rename deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Remote System Discovery with Net deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: "This analytic was focusing on 2 separate and unrelated type of threats or actions. It was split into other analytics, namely:\r\n\r\nWindows Network Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive @@ -210,118 +159,91 @@ detections: - Windows Network Share Interaction With Net - deprecated_content: Remote System Discovery with Net deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Sensitive Group Discovery With Net - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Suspicious Changes to File Associations deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: GCP Detect high risk permissions by resource and account deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Office Product Writing cab or inf deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Dropped Cab or Inf File - deprecated_content: Identify New User Accounts deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Office Product Spawn CMD Process deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Windows DLL Search Order Hijacking Hunt deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Windows DLL Search Order Hijacking Hunt with Sysmon - deprecated_content: ASL AWS CreateAccessKey deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - ASL AWS Create Access Key - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Detect Spike in Security Group Activity deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Security Group API Calls - deprecated_content: Office Product Spawning BITSAdmin deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Create local admin accounts using net exe deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Create Local Administrator Account Via Net - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Windows Office Product Spawning MSDT deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned MSDT - deprecated_content: Detect Spike in AWS API Activity deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Office Product Spawning Windows Script Host deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Prohibited Software On Endpoint deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Attacker Tools On Endpoint - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen Country - deprecated_content: Detect Critical Alerts from Security Tools deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender @@ -331,141 +253,109 @@ detections: - Microsoft Defender ATP Alerts - deprecated_content: Detect Critical Alerts from Security Tools deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Microsoft Defender Incident Alerts - deprecated_content: Excel Spawning PowerShell deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Office Application Spawn rundll32 process deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Excessive Usage Of Net App deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Excessive Usage Of Net App - deprecated_content: Elevated Group Discovery With Net deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Sensitive Group Discovery With Net - deprecated_content: Local Account Discovery with Net deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows User Discovery Via Net - deprecated_content: Windows Command Shell Fetch Env Variables deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows List ENV Variables Via SET Command From Uncommon Parent - deprecated_content: Suspicious Email - UBA Anomaly deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Detect web traffic to dynamic domain providers deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Updated to use a different log source replacement_content: - Detect hosts connecting to dynamic domain providers - deprecated_content: Okta Failed SSO Attempts deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Unauthorized Access to Application - deprecated_content: Kubernetes AWS detect RBAC authorization by account deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Remote Registry Key modifications deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: O365 Suspicious User Email Forwarding deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Mailbox Email Forwarding Enabled - deprecated_content: Office Product Spawning MSHTA deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Kubernetes AWS detect most active service accounts by pod deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Correlation by Repository and Risk deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the datamodel replacement_content: - Risk Rule for Dev Sec Ops by Repository - deprecated_content: Kubernetes Azure detect RBAC authorization by account deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Clients Connecting to Multiple DNS Servers deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Excessive Service Stop Attempt deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Excessive Service Stop Attempt - deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Users Failing To Authenticate From Ip - deprecated_content: Suspicious writes to System Volume Information deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Detect new user AWS Console Login deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Detect AWS Console Login by New User - deprecated_content: Domain Account Discovery With Net App deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: "This analytic was a TTP that looked only for commands that tries to query info about the users via net user /do. This had a couple of issues, such as triggering on creation of users via the /add flag etc..\nIt was deprecated in favor of a @@ -474,191 +364,145 @@ detections: - Windows User Discovery Via Net - deprecated_content: Detection of DNS Tunnels deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2 deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Office Document Creating Schedule Task deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Loading Taskschd DLL - deprecated_content: Okta Account Locked Out deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Accounts Locked Out - deprecated_content: Unsuccessful Netbackup backups deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703 deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Detect Mimikatz With PowerShell Script Block Logging - deprecated_content: Winword Spawning Cmd deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: GCP Kubernetes cluster scan detection deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Kubernetes Scanning by Unauthenticated IP Address - deprecated_content: Kubernetes GCP detect suspicious kubectl calls deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: gcp detect oauth token abuse deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Correlation by User and Risk deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the datamodel replacement_content: - Risk Rule for Dev Sec Ops by Repository - deprecated_content: Processes created by netsh deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Processes launching netsh - deprecated_content: Office Product Spawning Wmic deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Extraction of Registry Hives deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Sensitive Registry Hive Dump Via CommandLine - deprecated_content: Attempt To Stop Security Service deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Attempt To Stop Security Service - deprecated_content: Windows MSIExec With Network Connections deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows HTTP Network Communication From MSIExec - deprecated_content: Windows Query Registry Reg Save deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Registry Entries Exported Via Reg - deprecated_content: Cloud Network Access Control List Deleted deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - AWS Network Access Control List Deleted - deprecated_content: O365 Suspicious Rights Delegation deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Elevated Mailbox Permission Assigned - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Reg exe used to hide files directories via registry keys deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Detect Long DNS TXT Record Response deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Password Policy Discovery with Net deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Password Policy Discovery with Net - deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen IP Address - deprecated_content: Network Connection Discovery With Net deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Network Connection Discovery Via Net - deprecated_content: Kubernetes Azure detect suspicious kubectl calls deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Kubernetes GCP detect sensitive role access deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Detect Webshell Exploit Behavior deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Suspicious Child Process Spawned From WebServer - deprecated_content: DNS record changed deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Unsigned Image Loaded by LSASS deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Detect USB device insertion deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Windows Network Share Interaction With Net deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Network Share Interaction Via Net - deprecated_content: Account Discovery With Net App deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 @@ -667,670 +511,457 @@ detections: - Windows Excessive Usage Of Net App - deprecated_content: Change Default File Association deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows New Default File Association Value Set - deprecated_content: Windows Lateral Tool Transfer RemCom deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Windows Service Execution RemCom - deprecated_content: Office Document Executing Macro Code deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Loading VBE7 DLL - deprecated_content: Okta Account Lockout Events deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Accounts Locked Out - deprecated_content: Abnormally High AWS Instances Launched by User deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Instances Launched - deprecated_content: EC2 Instance Modified With Previously Unseen User deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud API Calls From Previously Unseen User Roles - deprecated_content: Windows Valid Account With Never Expires Password deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Set Account Password Policy To Unlimited Via Net - deprecated_content: Windows hosts file modification deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: MSHTML Module Load in Office Product deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Loaded MSHTML Module - deprecated_content: Abnormally High AWS Instances Terminated by User deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Instances Destroyed - deprecated_content: Web Fraud - Account Harvesting deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Office Spawning Control deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Control - deprecated_content: Detect Activity Related to Pass the Hash Attacks deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Deleting Of Net Users deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows User Deletion Via Net - deprecated_content: Suspicious File Write deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: AWS EKS Kubernetes cluster sensitive object access deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Kubernetes Abuse of Secret by Unusual Location - deprecated_content: Spectre and Meltdown Vulnerable Systems deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: EC2 Instance Started With Previously Unseen User deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created By Previously Unseen User - deprecated_content: Office Product Spawning CertUtil deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Kubernetes GCP detect RBAC authorizations by account deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Office Application Drop Executable deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Dropped Uncommon File - deprecated_content: Kubernetes Azure active service accounts by pod namespace deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Kubernetes Azure pod scan fingerprint deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Detect Spike in Network ACL Activity deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Infrastructure API Calls - deprecated_content: Suspicious Powershell Command-Line Arguments deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Malicious PowerShell Process - Encoded Command - deprecated_content: Office Application Spawn Regsvr32 process deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - deprecated_content: Detect API activity from users without MFA deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - AWS Successful Single-Factor Authentication - deprecated_content: Kubernetes Azure detect sensitive object access deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Web Fraud - Password Sharing Across Accounts deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Disabling Net User Account deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows User Disabled Via Net - deprecated_content: GCP Detect accounts with high risk roles by project deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Extended Period Without Successful Netbackup Backups deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Office Product Spawning Rundll32 with no DLL deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Rundll32 With No DLL - deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta ThreatInsight Threat Detected - deprecated_content: Net Localgroup Discovery deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net replacement_content: - Windows Group Discovery Via Net - deprecated_content: Uncommon Processes On Endpoint deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Attacker Tools On Endpoint - deprecated_content: Dump LSASS via procdump Rename deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Updated to a new detection name replacement_content: - Dump LSASS via procdump - deprecated_content: Okta Two or More Rejected Okta Pushes deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Failed MFA Requests For User - deprecated_content: Excel Spawning Windows Script Host deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: GitHub Actions Disable Security Workflow deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Github Commit Changes In Master deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Github Commit In Develop deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: GitHub Dependabot Alert deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: GitHub Pull Request from Unknown User deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Known Services Killed by Ransomware deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Remote Desktop Network Bruteforce deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Suspicious Driver Loaded Path deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Suspicious Event Log Service Behavior deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Suspicious Process File Path deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - deprecated_content: Windows Service Stop Via Net and SC Application deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] baselines: - deprecated_content: Add Prohibited Processes to Enterprise Security deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - deprecated_content: Baseline of API Calls per User ARN deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - deprecated_content: Previously seen API call per user roles in CloudTrail deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - deprecated_content: Previously Seen AWS Provisioning Activity Sources deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - deprecated_content: Previously Seen EC2 AMIs deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - deprecated_content: Previously Seen EC2 Instance Types deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - deprecated_content: Previously Seen EC2 Launches By User deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - deprecated_content: Previously seen users in CloudTrail deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] - deprecated_content: Update previously seen users in CloudTrail deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - replacement_content: [] investigations: - deprecated_content: All backup logs for host deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Amazon EKS Kubernetes activity by src ip deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: AWS Investigate Security Hub alerts by dest deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: AWS Investigate User Activities By AccessKeyId deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: AWS Investigate User Activities By ARN deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: AWS Network ACL Details from ID deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: AWS Network Interface details via resourceId deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: AWS S3 Bucket details via bucketName deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: GCP Kubernetes activity by src ip deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get All AWS Activity From City deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get All AWS Activity From Country deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get All AWS Activity From IP Address deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get All AWS Activity From Region deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Backup Logs For Endpoint deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Certificate logs for a domain deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get DNS Server History for a host deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get DNS traffic ratio deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get EC2 Instance Details by instanceId deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get EC2 Launch Details deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Email Info deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Emails From Specific Sender deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get History Of Email Sources deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Logon Rights Modifications For Endpoint deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Logon Rights Modifications For User deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Notable History deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Parent Process Info deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Process File Activity deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Process Info deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Process Information For Port Activity deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Process Responsible For The DNS Traffic deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Sysmon WMI Activity for Host deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Get Web Session Information via session id deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate AWS activities via region name deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate AWS User Activities by user field deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate Failed Logins for Multiple Destinations deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate Network Traffic From src ip deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate Okta Activity by app deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate Okta Activity by IP Address deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate Pass the Hash Attempts deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate Pass the Ticket Attempts deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate Previous Unseen User deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate Successful Remote Desktop Authentications deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate Suspicious Strings in HTTP Header deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate User Activities In Okta deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] - deprecated_content: Investigate Web POSTs From src deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - replacement_content: [] stories: - deprecated_content: AWS Cryptomining deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Cloud Cryptomining - deprecated_content: AWS Suspicious Provisioning Activities deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Suspicious Cloud Provisioning Activities - deprecated_content: Common Phishing Frameworks deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - - deprecated_content: Container Implantation Monitoring and Investigation + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Container Implantation Monitoring and Investigation deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Kubernetes Security - deprecated_content: Host Redirection deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - - deprecated_content: Kubernetes Sensitive Role Activity + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Kubernetes Sensitive Role Activity deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Kubernetes Security - deprecated_content: Lateral Movement deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Compromised User Account - deprecated_content: Monitor Backup Solution deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - - deprecated_content: Monitor for Unauthorized Software + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Monitor for Unauthorized Software deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - - deprecated_content: Office 365 Detections + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Office 365 Detections deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Office 365 Account Takeover - deprecated_content: Spectre And Meltdown Vulnerabilities deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - - deprecated_content: Suspicious AWS EC2 Activities + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Suspicious AWS EC2 Activities deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Suspicious Cloud Instance Activities - deprecated_content: Unusual AWS EC2 Modifications deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Suspicious Cloud Instance Activities - deprecated_content: Web Fraud Detection deprecated_in_version: 5.2.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: [] - - deprecated_content: Nexus APT Threat Activity + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Nexus APT Threat Activity deprecated_in_version: 5.4.0 - deprecated_date: 2025-03-12 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - China-Nexus Threat Activity \ No newline at end of file From 990b5442719043d2172cfddb00414afeb21b10f8 Mon Sep 17 00:00:00 2001 From: pyth0n1c Date: Mon, 17 Mar 2025 16:41:52 -0700 Subject: [PATCH 45/67] Fixed spacing in improperly formatted YML file --- deprecated/deprecated_detection_mapping.yml | 126 ++++++++++---------- 1 file changed, 63 insertions(+), 63 deletions(-) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index c104358a54..eb9b6abec0 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -902,66 +902,66 @@ investigations: deprecated_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' stories: - - deprecated_content: AWS Cryptomining - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: - - Cloud Cryptomining - - deprecated_content: AWS Suspicious Provisioning Activities - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: - - Suspicious Cloud Provisioning Activities - - deprecated_content: Common Phishing Frameworks - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Container Implantation Monitoring and Investigation - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: - - Kubernetes Security - - deprecated_content: Host Redirection - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Kubernetes Sensitive Role Activity - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: - - Kubernetes Security - - deprecated_content: Lateral Movement - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: - - Compromised User Account - - deprecated_content: Monitor Backup Solution - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Monitor for Unauthorized Software - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Office 365 Detections - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: - - Office 365 Account Takeover - - deprecated_content: Spectre And Meltdown Vulnerabilities - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Suspicious AWS EC2 Activities - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: - - Suspicious Cloud Instance Activities - - deprecated_content: Unusual AWS EC2 Modifications - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: - - Suspicious Cloud Instance Activities - - deprecated_content: Web Fraud Detection - deprecated_in_version: 5.2.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Nexus APT Threat Activity - deprecated_in_version: 5.4.0 - reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - replacement_content: - - China-Nexus Threat Activity \ No newline at end of file + - deprecated_content: AWS Cryptomining + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: + - Cloud Cryptomining + - deprecated_content: AWS Suspicious Provisioning Activities + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: + - Suspicious Cloud Provisioning Activities + - deprecated_content: Common Phishing Frameworks + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Container Implantation Monitoring and Investigation + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: + - Kubernetes Security + - deprecated_content: Host Redirection + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Kubernetes Sensitive Role Activity + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: + - Kubernetes Security + - deprecated_content: Lateral Movement + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: + - Compromised User Account + - deprecated_content: Monitor Backup Solution + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Monitor for Unauthorized Software + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Office 365 Detections + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: + - Office 365 Account Takeover + - deprecated_content: Spectre And Meltdown Vulnerabilities + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Suspicious AWS EC2 Activities + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: + - Suspicious Cloud Instance Activities + - deprecated_content: Unusual AWS EC2 Modifications + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: + - Suspicious Cloud Instance Activities + - deprecated_content: Web Fraud Detection + deprecated_in_version: 5.2.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Nexus APT Threat Activity + deprecated_in_version: 5.4.0 + reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity + replacement_content: + - China-Nexus Threat Activity \ No newline at end of file From 77dfe52b895e69d2cd0392e3e1eaa39b53cabf36 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 16:44:09 -0700 Subject: [PATCH 46/67] Update macro --- macros/o365_suspect_search_terms_regex.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/macros/o365_suspect_search_terms_regex.yml b/macros/o365_suspect_search_terms_regex.yml index e5190a3cb3..e78548955f 100644 --- a/macros/o365_suspect_search_terms_regex.yml +++ b/macros/o365_suspect_search_terms_regex.yml @@ -1,3 +1,3 @@ -definition: "(?i)password|credential|login|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing" +definition: "\"(?i)password|credential|login|passwd|shadow|active directory|account|username|network|computer|access|MFA|bank|deposit|payroll|EFT|Electonic Funds|routing\"" description: A regex used with match statements preloaded with generic suspicious terms or phrases. Is used to detect malicious actor or insider threat searches, replace/modify these terms to suit your organization. name: o365_suspect_search_terms_regex From 53b19285121cf0c2be72e98d5ce39f22276ed73a Mon Sep 17 00:00:00 2001 From: delgado-jacob <29643013+delgado-jacob@users.noreply.github.com> Date: Mon, 17 Mar 2025 17:07:03 -0700 Subject: [PATCH 47/67] normalize quotes --- data_sources/azure_active_directory_add_member_to_role.yml | 2 +- .../azure_active_directory_add_owner_to_application.yml | 2 +- data_sources/azure_active_directory_add_service_principal.yml | 2 +- data_sources/azure_active_directory_add_unverified_domain.yml | 2 +- data_sources/azure_active_directory_consent_to_application.yml | 2 +- .../azure_active_directory_disable_strong_authentication.yml | 2 +- data_sources/azure_active_directory_enable_account.yml | 2 +- data_sources/azure_active_directory_invite_external_user.yml | 2 +- .../azure_active_directory_reset_password_(by_admin).yml | 2 +- .../azure_active_directory_set_domain_authentication.yml | 2 +- data_sources/azure_active_directory_sign_in_activity.yml | 2 +- data_sources/azure_active_directory_update_application.yml | 2 +- .../azure_active_directory_update_authorization_policy.yml | 2 +- data_sources/azure_active_directory_update_user.yml | 2 +- .../azure_active_directory_user_registered_security_info.yml | 2 +- ...azure_audit_create_or_update_an_azure_automation_account.yml | 2 +- ...azure_audit_create_or_update_an_azure_automation_runbook.yml | 2 +- ...azure_audit_create_or_update_an_azure_automation_webhook.yml | 2 +- data_sources/azure_monitor_activity.yml | 2 +- data_sources/g_suite_drive.yml | 2 +- data_sources/g_suite_gmail.yml | 2 +- data_sources/google_workspace.yml | 2 +- data_sources/google_workspace_login_failure.yml | 2 +- data_sources/google_workspace_login_success.yml | 2 +- data_sources/o365.yml | 2 +- data_sources/o365_add_app_role_assignment_grant_to_user_.yml | 2 +- .../o365_add_app_role_assignment_to_service_principal_.yml | 2 +- data_sources/o365_add_mailboxpermission.yml | 2 +- data_sources/o365_add_member_to_role_.yml | 2 +- data_sources/o365_add_owner_to_application_.yml | 2 +- data_sources/o365_add_service_principal_.yml | 2 +- data_sources/o365_change_user_license_.yml | 2 +- 32 files changed, 32 insertions(+), 32 deletions(-) diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml index 737edf7f94..361ec5afe2 100644 --- a/data_sources/azure_active_directory_add_member_to_role.yml +++ b/data_sources/azure_active_directory_add_member_to_role.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Add member to role id: 1660d196-127f-4678-81b2-472d51711b07 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs the addition of a member to a directory role in Azure Active Directory, including details about the role, the member added, and the user or process performing diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml index 36786bbea3..1e80420bc9 100644 --- a/data_sources/azure_active_directory_add_owner_to_application.yml +++ b/data_sources/azure_active_directory_add_owner_to_application.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Add owner to application id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs the addition of an owner to an application in Azure Active Directory, including details about the application, the owner added, and the user or process diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml index 7ec49367e7..4900077c25 100644 --- a/data_sources/azure_active_directory_add_service_principal.yml +++ b/data_sources/azure_active_directory_add_service_principal.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Add service principal id: fd89d337-e4c0-4162-ad13-bca36f096fe6 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs the creation of a new service principal in Azure Active Directory, including details about the service principal, associated application, and the user diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml index 961e232a61..9c65ffb874 100644 --- a/data_sources/azure_active_directory_add_unverified_domain.yml +++ b/data_sources/azure_active_directory_add_unverified_domain.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Add unverified domain id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs the addition of an unverified domain to Azure Active Directory, including details about the domain name and the user or process performing the action. diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml index e009f3279a..a3fabfa139 100644 --- a/data_sources/azure_active_directory_consent_to_application.yml +++ b/data_sources/azure_active_directory_consent_to_application.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Consent to application id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs user or admin consent to an application's permissions in Azure Active Directory, including details about the application, granted permissions, and the diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml index 776d4966f2..dc3b8dbf05 100644 --- a/data_sources/azure_active_directory_disable_strong_authentication.yml +++ b/data_sources/azure_active_directory_disable_strong_authentication.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Disable Strong Authentication id: 8f31966d-c496-496d-8837-f7fd11f31255 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when strong authentication methods are disabled in Azure Active Directory. diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml index 6490ed964a..be0208edb9 100644 --- a/data_sources/azure_active_directory_enable_account.yml +++ b/data_sources/azure_active_directory_enable_account.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Enable account id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Active Directory account is enabled. mitre_components: diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml index 2ed2d7c705..fca5f7cf97 100644 --- a/data_sources/azure_active_directory_invite_external_user.yml +++ b/data_sources/azure_active_directory_invite_external_user.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Invite external user id: d3818bd5-f283-4518-8b67-df19240c3e40 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an external user is invited to join an Azure Active Directory tenant. diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml index c35dabeb34..aff8092dee 100644 --- a/data_sources/azure_active_directory_reset_password_(by_admin).yml +++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml @@ -1,7 +1,7 @@ name: Azure Active Directory Reset password (by admin) id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an admin resets a user's password in Azure Active Directory. diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml index 0b31d97f53..70c7e43888 100644 --- a/data_sources/azure_active_directory_set_domain_authentication.yml +++ b/data_sources/azure_active_directory_set_domain_authentication.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Set domain authentication id: e7bcdab9-908c-40ab-ba38-5db54fa87750 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when the authentication method for a domain in Azure Active Directory is set or modified. diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml index 3834f3e0b6..31a32e5a30 100644 --- a/data_sources/azure_active_directory_sign_in_activity.yml +++ b/data_sources/azure_active_directory_sign_in_activity.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Sign-in activity id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a user attempts to sign into Azure Active Directory, capturing authentication details and outcomes. diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml index e180c237a0..23dcecde69 100644 --- a/data_sources/azure_active_directory_update_application.yml +++ b/data_sources/azure_active_directory_update_application.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Update application id: 2c08188a-ba25-496e-87c7-803cf28b6c90 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an application in Azure Active Directory is updated, such as changes to its settings or permissions. diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml index 5a9cb19eb3..058f400e1a 100644 --- a/data_sources/azure_active_directory_update_authorization_policy.yml +++ b/data_sources/azure_active_directory_update_authorization_policy.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Update authorization policy id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an authorization policy is updated in Azure Active Directory. diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml index a9e43502b0..9f99e199d8 100644 --- a/data_sources/azure_active_directory_update_user.yml +++ b/data_sources/azure_active_directory_update_user.yml @@ -1,7 +1,7 @@ name: Azure Active Directory Update user id: 5495c90a-047c-4b8e-b2fe-1db6282d3872 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a user account is updated in Azure Active Directory. mitre_components: diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml index 1f3474bc88..1379b9e4f8 100644 --- a/data_sources/azure_active_directory_user_registered_security_info.yml +++ b/data_sources/azure_active_directory_user_registered_security_info.yml @@ -1,7 +1,7 @@ name: Azure Active Directory User registered security info id: b63240de-8a01-4ba8-8987-89d18d4b375d version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a user registers or updates their security information in Azure Active Directory. diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml index f6527d3d3b..d20eb1b740 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml @@ -1,7 +1,7 @@ name: Azure Audit Create or Update an Azure Automation account id: 2ab182e7-feda-4249-9418-32710b55a885 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Automation account is created or updated. mitre_components: diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml index a8f5116f79..f2dbafa993 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml @@ -1,7 +1,7 @@ name: Azure Audit Create or Update an Azure Automation Runbook id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a new Azure Automation Runbook is created or an existing one is updated. diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml index e3e30003a4..a8c611852b 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml @@ -1,7 +1,7 @@ name: Azure Audit Create or Update an Azure Automation webhook id: 575faeb2-09d0-4849-b1f6-eae241f26ff2 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs an event when a webhook is created or updated in Azure Automation. mitre_components: diff --git a/data_sources/azure_monitor_activity.yml b/data_sources/azure_monitor_activity.yml index c47465f05f..99c76ed47f 100644 --- a/data_sources/azure_monitor_activity.yml +++ b/data_sources/azure_monitor_activity.yml @@ -1,7 +1,7 @@ name: Azure Monitor Activity id: 1997a515-a61a-4f78-ada9-54af34c764f2 version: 1 -date: "2025-01-13" +date: '2025-01-13' author: Bhavin Patel, Splunk description: Data source object for Azure Monitor Activity. The Splunk Add-on for diff --git a/data_sources/g_suite_drive.yml b/data_sources/g_suite_drive.yml index 050427ab42..0064416dbb 100644 --- a/data_sources/g_suite_drive.yml +++ b/data_sources/g_suite_drive.yml @@ -1,7 +1,7 @@ name: G Suite Drive id: 5f79120f-a235-4468-bd0d-55203758ac22 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs activities related to Google Drive in G Suite, including file creation, modification, sharing, and access details. diff --git a/data_sources/g_suite_gmail.yml b/data_sources/g_suite_gmail.yml index 9471a54484..2366e69b41 100644 --- a/data_sources/g_suite_gmail.yml +++ b/data_sources/g_suite_gmail.yml @@ -1,7 +1,7 @@ name: G Suite Gmail id: 706c3978-41de-406b-b6e0-75bd01e12a5d version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs Gmail activities in G Suite, including email sending, receiving, and access details, as well as potential security-related events. diff --git a/data_sources/google_workspace.yml b/data_sources/google_workspace.yml index 1e651b883e..cdc72f6062 100644 --- a/data_sources/google_workspace.yml +++ b/data_sources/google_workspace.yml @@ -1,7 +1,7 @@ name: Google Workspace id: f1a044e3-113a-4e4d-84f2-b153ade83087 version: 1 -date: "2025-02-21" +date: '2025-02-21' author: Bhavin Patel, Splunk description: Data source object for Google Workspace source: google_workspace diff --git a/data_sources/google_workspace_login_failure.yml b/data_sources/google_workspace_login_failure.yml index 4a57f70c36..37b5e7dfd3 100644 --- a/data_sources/google_workspace_login_failure.yml +++ b/data_sources/google_workspace_login_failure.yml @@ -1,7 +1,7 @@ name: Google Workspace login_failure id: cabec7cf-4008-4899-b47e-39c34a9a1255 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs failed login attempts to Google Workspace accounts, including details about the user, IP address, and reason for failure. diff --git a/data_sources/google_workspace_login_success.yml b/data_sources/google_workspace_login_success.yml index 16beb865b8..ac11eece48 100644 --- a/data_sources/google_workspace_login_success.yml +++ b/data_sources/google_workspace_login_success.yml @@ -1,7 +1,7 @@ name: Google Workspace login_success id: bffe8013-9cdf-4fe6-9c1b-6784391a4951 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs successful login attempts to Google Workspace accounts, including details about the user, IP address, and session metadata. diff --git a/data_sources/o365.yml b/data_sources/o365.yml index c87c6d01cd..e3a8fe4084 100644 --- a/data_sources/o365.yml +++ b/data_sources/o365.yml @@ -1,7 +1,7 @@ name: O365 id: b32de97d-0074-4cca-853c-db22c392b6c0 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs management activities in Microsoft 365, including administrative actions, user activities, and configuration changes across various services. diff --git a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml index 87d209241a..b423cfb188 100644 --- a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml +++ b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml @@ -1,7 +1,7 @@ name: O365 Add app role assignment grant to user. id: ce1d7849-a1d2-47fd-b6eb-d7ef854a860c version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs the assignment of an application role grant to a user in Microsoft 365, including details about the role, user, and application involved. diff --git a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml index 8c76c22053..f701f5d05a 100644 --- a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml +++ b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml @@ -1,7 +1,7 @@ name: O365 Add app role assignment to service principal. id: 785ba57a-ba7b-474e-97c8-9474e6e00b3a version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs the assignment of an application role to a service principal in Microsoft 365, including details about the role, service principal, and application diff --git a/data_sources/o365_add_mailboxpermission.yml b/data_sources/o365_add_mailboxpermission.yml index eaaf573a62..73d8a6a770 100644 --- a/data_sources/o365_add_mailboxpermission.yml +++ b/data_sources/o365_add_mailboxpermission.yml @@ -1,7 +1,7 @@ name: O365 Add-MailboxPermission id: 9c0babdb-bb15-449e-abba-0a9cdb3fc061 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs the addition of mailbox permissions in Microsoft 365, including details about the mailbox, granted permissions, and the user or administrator performing diff --git a/data_sources/o365_add_member_to_role_.yml b/data_sources/o365_add_member_to_role_.yml index 6a582f6557..4bbd0ee8ac 100644 --- a/data_sources/o365_add_member_to_role_.yml +++ b/data_sources/o365_add_member_to_role_.yml @@ -1,7 +1,7 @@ name: O365 Add member to role. id: 8b949f7c-4b5d-404f-9694-d7403c4ec096 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs the addition of a member to a role in Microsoft 365, including details about the role, the added member, and the user or administrator performing the action. diff --git a/data_sources/o365_add_owner_to_application_.yml b/data_sources/o365_add_owner_to_application_.yml index f0b2874382..b1da0c1792 100644 --- a/data_sources/o365_add_owner_to_application_.yml +++ b/data_sources/o365_add_owner_to_application_.yml @@ -1,7 +1,7 @@ name: O365 Add owner to application. id: da012cbf-af6e-40ee-a1ba-32a5f8da8f8a version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs the addition of an owner to an application in Microsoft 365, including details about the application, the new owner, and the user or administrator performing diff --git a/data_sources/o365_add_service_principal_.yml b/data_sources/o365_add_service_principal_.yml index 145c7ea81c..b348c73689 100644 --- a/data_sources/o365_add_service_principal_.yml +++ b/data_sources/o365_add_service_principal_.yml @@ -1,7 +1,7 @@ name: O365 Add service principal. id: 9c1ef9f5-bc30-4a47-a1bd-cb34484ee778 version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs the addition of a new service principal in Microsoft 365, including details about the associated application and the action initiator. diff --git a/data_sources/o365_change_user_license_.yml b/data_sources/o365_change_user_license_.yml index 5faab95680..9204dca910 100644 --- a/data_sources/o365_change_user_license_.yml +++ b/data_sources/o365_change_user_license_.yml @@ -1,7 +1,7 @@ name: O365 Change user license. id: 1029a20d-3d0d-4fb9-b5e2-22ac5380b20a version: 2 -date: "2025-01-23" +date: '2025-01-23' author: Patrick Bareiss, Splunk description: Logs changes to user licenses in Microsoft 365, including additions, removals, or updates to service plans associated with a user account. From f672cb55c0fe2d9490227caf918115860e2d5813 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 17:48:11 -0700 Subject: [PATCH 48/67] updating missing detections --- deprecated/deprecated_detection_mapping.yml | 23 ++++++++++++++++++++- 1 file changed, 22 insertions(+), 1 deletion(-) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index eb9b6abec0..f2a4a244dd 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -690,7 +690,7 @@ detections: replacement_content: - Okta Multiple Failed MFA Requests For User - deprecated_content: Excel Spawning Windows Script Host - deprecated_in_version: 5.4.0 + deprecated_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - deprecated_content: GitHub Actions Disable Security Workflow deprecated_in_version: 5.4.0 @@ -725,6 +725,27 @@ detections: - deprecated_content: Windows Service Stop Via Net and SC Application deprecated_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: AWS Cross Account Activity From Previously Unseen Account + deprecated_in_version: 5.4.0 + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: aws detect attach to role policy + deprecated_in_version: 5.4.0 + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: aws detect permanent key creation + deprecated_in_version: 5.4.0 + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: aws detect role creation + deprecated_in_version: 5.4.0 + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: aws detect sts assume role abuse + deprecated_in_version: 5.4.0 + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: aws detect sts get session token abuse + deprecated_in_version: 5.4.0 + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: AWS SAML Access by Provider User and Principal + deprecated_in_version: 5.4.0 + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity baselines: - deprecated_content: Add Prohibited Processes to Enterprise Security deprecated_in_version: 5.2.0 From c345f920ed571afb19e38b153e3a70dd8371df19 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 18:04:26 -0700 Subject: [PATCH 49/67] adding gitkeep for empty folders --- baselines/deprecated/.gitkeep | 0 deprecated/deprecated_detection_mapping.yml | 6 +++--- detections/deprecated/.gitkeep | 0 stories/deprecated/.gitkeep | 0 4 files changed, 3 insertions(+), 3 deletions(-) create mode 100644 baselines/deprecated/.gitkeep create mode 100644 detections/deprecated/.gitkeep create mode 100644 stories/deprecated/.gitkeep diff --git a/baselines/deprecated/.gitkeep b/baselines/deprecated/.gitkeep new file mode 100644 index 0000000000..e69de29bb2 diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index f2a4a244dd..b4014fd419 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -689,6 +689,9 @@ detections: TA update replacement_content: - Okta Multiple Failed MFA Requests For User + - deprecated_content: Windows Service Stop Via Net and SC Application + deprecated_in_version: 5.2.0 + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - deprecated_content: Excel Spawning Windows Script Host deprecated_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity @@ -722,9 +725,6 @@ detections: - deprecated_content: Suspicious Process File Path deprecated_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Windows Service Stop Via Net and SC Application - deprecated_in_version: 5.4.0 - reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - deprecated_content: AWS Cross Account Activity From Previously Unseen Account deprecated_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity diff --git a/detections/deprecated/.gitkeep b/detections/deprecated/.gitkeep new file mode 100644 index 0000000000..e69de29bb2 diff --git a/stories/deprecated/.gitkeep b/stories/deprecated/.gitkeep new file mode 100644 index 0000000000..e69de29bb2 From 99a4b6fa4b62174ae556c6b501812d9d1f51a857 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 18:09:42 -0700 Subject: [PATCH 50/67] adding missing baselines --- deprecated/deprecated_detection_mapping.yml | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index b4014fd419..57c872e1bb 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -780,6 +780,21 @@ baselines: - deprecated_content: Update previously seen users in CloudTrail deprecated_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + - deprecated_content: Monitor Successful Backups + deprecated_in_version: 5.2.0 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + - deprecated_content: Monitor Unsuccessful Backups + deprecated_in_version: 5.2.0 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + - deprecated_content: Previously Seen AWS Regions + deprecated_in_version: 5.2.0 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + - deprecated_content: Previously Seen EC2 Modifications By User + deprecated_in_version: 5.2.0 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + - deprecated_content: Systems Ready for Spectre-Meltdown Windows Patch + deprecated_in_version: 5.2.0 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' investigations: - deprecated_content: All backup logs for host deprecated_in_version: 5.2.0 From 4d4a1c664928464ca663d916d7225be763e695a1 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 18:19:56 -0700 Subject: [PATCH 51/67] adding cross account stuff --- .../previously_seen_aws_cross_account_activity___initial.yml | 2 +- .../previously_seen_aws_cross_account_activity___update.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) rename baselines/{ => deprecated}/previously_seen_aws_cross_account_activity___initial.yml (98%) rename baselines/{ => deprecated}/previously_seen_aws_cross_account_activity___update.yml (98%) diff --git a/baselines/previously_seen_aws_cross_account_activity___initial.yml b/baselines/deprecated/previously_seen_aws_cross_account_activity___initial.yml similarity index 98% rename from baselines/previously_seen_aws_cross_account_activity___initial.yml rename to baselines/deprecated/previously_seen_aws_cross_account_activity___initial.yml index 6fad8d0f18..3cc411008a 100644 --- a/baselines/previously_seen_aws_cross_account_activity___initial.yml +++ b/baselines/deprecated/previously_seen_aws_cross_account_activity___initial.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-08-15' author: Rico Valdez, Splunk type: Baseline -status: production +status: deprecated description: This search looks for **AssumeRole** events where the requesting account differs from the requested account, then writes these relationships to a lookup file. diff --git a/baselines/previously_seen_aws_cross_account_activity___update.yml b/baselines/deprecated/previously_seen_aws_cross_account_activity___update.yml similarity index 98% rename from baselines/previously_seen_aws_cross_account_activity___update.yml rename to baselines/deprecated/previously_seen_aws_cross_account_activity___update.yml index 9cb9c956b9..bc8eee0872 100644 --- a/baselines/previously_seen_aws_cross_account_activity___update.yml +++ b/baselines/deprecated/previously_seen_aws_cross_account_activity___update.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-08-15' author: Rico Valdez, Splunk type: Baseline -status: production +status: deprecated description: This search looks for **AssumeRole** events where the requesting account differs from the requested account, then writes these relationships to a lookup file. From ca86201823f5d23dc29cd00921833aeb2c8926ae Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 18:28:42 -0700 Subject: [PATCH 52/67] adding 2 deprecated baselines --- deprecated/deprecated_detection_mapping.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index 57c872e1bb..94813fd1da 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -795,6 +795,12 @@ baselines: - deprecated_content: Systems Ready for Spectre-Meltdown Windows Patch deprecated_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + - deprecated_content: Previously Seen AWS Cross Account Activity - Initial + deprecated_in_version: 5.4.0 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' + - deprecated_content: Previously Seen AWS Cross Account Activity - Update + deprecated_in_version: 5.4.0 + reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' investigations: - deprecated_content: All backup logs for host deprecated_in_version: 5.2.0 From 3819c6864d71c9c5592077775bc9c3fcf80fe0b3 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 19:14:58 -0700 Subject: [PATCH 53/67] updating detections --- detections/cloud/aws_credential_access_getpassworddata.yml | 3 +-- detections/cloud/aws_ec2_snapshot_shared_externally.yml | 2 +- .../cloud/aws_network_access_control_list_deleted.yml | 7 +++---- detections/cloud/aws_saml_update_identity_provider.yml | 6 +++--- detections/cloud/aws_updateloginprofile.yml | 2 +- detections/endpoint/registry_keys_used_for_persistence.yml | 1 - 6 files changed, 9 insertions(+), 12 deletions(-) diff --git a/detections/cloud/aws_credential_access_getpassworddata.yml b/detections/cloud/aws_credential_access_getpassworddata.yml index 366d056882..f10dcbf896 100644 --- a/detections/cloud/aws_credential_access_getpassworddata.yml +++ b/detections/cloud/aws_credential_access_getpassworddata.yml @@ -46,8 +46,7 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: User $user$ is seen to make mulitple `GetPasswordData` API calls to - instance ids $instance_ids$ from IP $src$ + message: User $user$ is seen to make mulitple `GetPasswordData` API calls to multiple instances from IP $src$ risk_objects: - field: user type: user diff --git a/detections/cloud/aws_ec2_snapshot_shared_externally.yml b/detections/cloud/aws_ec2_snapshot_shared_externally.yml index b5b351c84d..16499e4a92 100644 --- a/detections/cloud/aws_ec2_snapshot_shared_externally.yml +++ b/detections/cloud/aws_ec2_snapshot_shared_externally.yml @@ -22,7 +22,7 @@ search: '`cloudtrail` eventName=ModifySnapshotAttribute | where match = "No Match" | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product requested_account_id | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ec2_snapshot_shared_externally_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This diff --git a/detections/cloud/aws_network_access_control_list_deleted.yml b/detections/cloud/aws_network_access_control_list_deleted.yml index 1f7c98e312..8d91777aae 100644 --- a/detections/cloud/aws_network_access_control_list_deleted.yml +++ b/detections/cloud/aws_network_access_control_list_deleted.yml @@ -16,9 +16,9 @@ data_source: - AWS CloudTrail DeleteNetworkAclEntry search: '`cloudtrail` eventName=DeleteNetworkAclEntry requestParameters.egress=false | fillnull - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region + | rename eventName as signature, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product signature | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_network_access_control_list_deleted_filter`' how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail @@ -41,8 +41,7 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: User $user$ from $src$ has sucessfully deleted network ACLs entry (eventName= - $eventName$), such that the instance is accessible from anywhere + message: User $user$ from $src$ has sucessfully deleted network ACLs entry, such that the instance is accessible from anywhere risk_objects: - field: user type: user diff --git a/detections/cloud/aws_saml_update_identity_provider.yml b/detections/cloud/aws_saml_update_identity_provider.yml index 51e9b3ea04..666cf8c96e 100644 --- a/detections/cloud/aws_saml_update_identity_provider.yml +++ b/detections/cloud/aws_saml_update_identity_provider.yml @@ -16,9 +16,9 @@ description: The following analytic detects updates to the SAML provider in AWS. data_source: - AWS CloudTrail UpdateSAMLProvider search: '`cloudtrail` eventName=UpdateSAMLProvider - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region + | rename requestParameters.sAMLProviderArn as request_parameters , eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | stats count min(_time) as firstTime max(_time) as lastTime values(request_parameters) as request_parameters by action dest user user_agent src vendor_account vendor_region vendor_product signature | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_saml_update_identity_provider_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This @@ -46,7 +46,7 @@ drilldown_searches: latest_offset: $info_max_time$ rba: message: User $user$ from IP address $src$ has trigged - an event $eventName$ to update the SAML provider to $requestParameters.sAMLProviderArn$ + an event $signature$ to update the SAML provider to $request_parameters$ risk_objects: - field: user type: user diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml index 0534a0819d..da468246ac 100644 --- a/detections/cloud/aws_updateloginprofile.yml +++ b/detections/cloud/aws_updateloginprofile.yml @@ -45,7 +45,7 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: From IP address $src$, user agent $userAgent$ has trigged an event UpdateLoginProfile + message: From IP address $src$, user agent $user_agent$ has trigged an event UpdateLoginProfile for updating the existing login profile, potentially giving user $user$ more access privilleges risk_objects: diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index d7408e9944..e217da8fed 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -78,7 +78,6 @@ tags: analytic_story: - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns - MoonPeak - - Amadey - RedLine Stealer - Emotet Malware DHS Report TA18-201A - Chaos Ransomware From f04362d709acaeeda5972687b4f98a1a6c286c28 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 17 Mar 2025 19:41:07 -0700 Subject: [PATCH 54/67] sort --- .../registry_keys_used_for_persistence.yml | 56 +++++++++---------- 1 file changed, 28 insertions(+), 28 deletions(-) diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index e217da8fed..65ff7b2113 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -76,38 +76,38 @@ rba: threat_objects: [] tags: analytic_story: - - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns - - MoonPeak - - RedLine Stealer - - Emotet Malware DHS Report TA18-201A - - Chaos Ransomware - - WinDealer RAT - - Warzone RAT - - China-Nexus Threat Activity - - Earth Estries - - SnappyBee - - Windows Persistence Techniques - - Snake Keylogger - - Ransomware - - CISA AA23-347A - - DHS Report TA18-074A - - Windows Registry Abuse - - Sneaky Active Directory Persistence Tricks - - BlackSuit Ransomware - - Qakbot - - DarkGate Malware - - IcedID - - Braodo Stealer - - Suspicious MSHTA Activity - - NjRAT + - Amadey - AsyncRAT - Azorult - - Amadey - - SystemBC - - Suspicious Windows Registry Activities - - Derusbi - BlackByte Ransomware + - BlackSuit Ransomware + - Braodo Stealer + - Chaos Ransomware + - China-Nexus Threat Activity + - CISA AA23-347A + - DarkGate Malware + - Derusbi + - DHS Report TA18-074A + - Earth Estries + - Emotet Malware DHS Report TA18-201A + - IcedID + - MoonPeak + - NjRAT + - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns + - Qakbot + - Ransomware + - RedLine Stealer - Remcos + - Snake Keylogger + - SnappyBee + - Sneaky Active Directory Persistence Tricks + - Suspicious MSHTA Activity + - Suspicious Windows Registry Activities + - SystemBC + - Warzone RAT + - WinDealer RAT + - Windows Persistence Techniques + - Windows Registry Abuse asset_type: Endpoint mitre_attack_id: - T1547.001 From 3122cbbc8bf880e2f7543a1362e42a0bb6df7e5b Mon Sep 17 00:00:00 2001 From: Patrick Bareiss Date: Tue, 18 Mar 2025 12:56:30 +0100 Subject: [PATCH 55/67] output improvements --- data_sources/asl_aws_cloudtrail.yml | 1 - data_sources/aws_cloudtrail_assumerolewithsaml.yml | 1 - data_sources/aws_cloudtrail_consolelogin.yml | 1 - data_sources/aws_cloudtrail_copyobject.yml | 1 - data_sources/aws_cloudtrail_createaccesskey.yml | 1 - data_sources/aws_cloudtrail_createkey.yml | 1 - data_sources/aws_cloudtrail_createloginprofile.yml | 1 - data_sources/aws_cloudtrail_createnetworkaclentry.yml | 1 - data_sources/aws_cloudtrail_createpolicyversion.yml | 1 - data_sources/aws_cloudtrail_createsnapshot.yml | 1 - data_sources/aws_cloudtrail_createtask.yml | 1 - data_sources/aws_cloudtrail_createvirtualmfadevice.yml | 1 - data_sources/aws_cloudtrail_deactivatemfadevice.yml | 1 - .../aws_cloudtrail_deleteaccountpasswordpolicy.yml | 1 - data_sources/aws_cloudtrail_deletealarms.yml | 1 - data_sources/aws_cloudtrail_deletedetector.yml | 1 - data_sources/aws_cloudtrail_deletegroup.yml | 1 - data_sources/aws_cloudtrail_deleteipset.yml | 1 - data_sources/aws_cloudtrail_deleteloggroup.yml | 1 - data_sources/aws_cloudtrail_deletelogstream.yml | 1 - data_sources/aws_cloudtrail_deletenetworkaclentry.yml | 1 - data_sources/aws_cloudtrail_deletepolicy.yml | 1 - data_sources/aws_cloudtrail_deleterule.yml | 1 - data_sources/aws_cloudtrail_deletesnapshot.yml | 1 - data_sources/aws_cloudtrail_deletetrail.yml | 1 - data_sources/aws_cloudtrail_deletevirtualmfadevice.yml | 1 - data_sources/aws_cloudtrail_deletewebacl.yml | 1 - data_sources/aws_cloudtrail_describeeventaggregates.yml | 1 - .../aws_cloudtrail_describeimagescanfindings.yml | 1 - data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml | 1 - data_sources/aws_cloudtrail_getobject.yml | 1 - data_sources/aws_cloudtrail_getpassworddata.yml | 1 - data_sources/aws_cloudtrail_jobcreated.yml | 1 - data_sources/aws_cloudtrail_modifydbinstance.yml | 1 - data_sources/aws_cloudtrail_modifyimageattribute.yml | 1 - data_sources/aws_cloudtrail_modifysnapshotattribute.yml | 1 - data_sources/aws_cloudtrail_putbucketacl.yml | 1 - data_sources/aws_cloudtrail_putbucketlifecycle.yml | 1 - data_sources/aws_cloudtrail_putbucketreplication.yml | 1 - data_sources/aws_cloudtrail_putbucketversioning.yml | 1 - data_sources/aws_cloudtrail_putimage.yml | 2 -- data_sources/aws_cloudtrail_putkeypolicy.yml | 1 - data_sources/aws_cloudtrail_replacenetworkaclentry.yml | 1 - data_sources/aws_cloudtrail_setdefaultpolicyversion.yml | 1 - data_sources/aws_cloudtrail_stoplogging.yml | 1 - .../aws_cloudtrail_updateaccountpasswordpolicy.yml | 1 - data_sources/aws_cloudtrail_updateloginprofile.yml | 1 - data_sources/aws_cloudtrail_updatesamlprovider.yml | 1 - data_sources/aws_cloudtrail_updatetrail.yml | 1 - .../aws_ami_attribute_modification_for_exfiltration.yml | 5 ++--- .../cloud/aws_concurrent_sessions_from_different_ips.yml | 5 ++--- .../aws_console_login_failed_during_mfa_challenge.yml | 5 ++--- .../aws_create_policy_version_to_allow_all_resources.yml | 5 ++--- detections/cloud/aws_createaccesskey.yml | 5 ++--- detections/cloud/aws_createloginprofile.yml | 9 ++++----- detections/cloud/aws_credential_access_failed_login.yml | 5 ++--- .../cloud/aws_credential_access_getpassworddata.yml | 5 ++--- .../cloud/aws_credential_access_rds_password_reset.yml | 5 ++--- .../cloud/aws_defense_evasion_delete_cloudtrail.yml | 5 ++--- .../aws_defense_evasion_delete_cloudwatch_log_group.yml | 5 ++--- .../aws_defense_evasion_impair_security_services.yml | 5 ++--- .../cloud/aws_defense_evasion_putbucketlifecycle.yml | 5 ++--- .../aws_defense_evasion_stop_logging_cloudtrail.yml | 5 ++--- .../cloud/aws_defense_evasion_update_cloudtrail.yml | 5 ++--- ...ers_creating_keys_with_encrypt_policy_without_mfa.yml | 5 ++--- ...tect_users_with_kms_keys_performing_encryption_s3.yml | 5 ++--- detections/cloud/aws_disable_bucket_versioning.yml | 5 ++--- detections/cloud/aws_ec2_snapshot_shared_externally.yml | 5 ++--- .../cloud/aws_ecr_container_scanning_findings_high.yml | 5 ++--- ...ainer_scanning_findings_low_informational_unknown.yml | 5 ++--- .../cloud/aws_ecr_container_scanning_findings_medium.yml | 5 ++--- .../aws_ecr_container_upload_outside_business_hours.yml | 5 ++--- .../cloud/aws_ecr_container_upload_unknown_user.yml | 5 ++--- detections/cloud/aws_excessive_security_scanning.yml | 7 +++---- ...exfiltration_via_anomalous_getobject_api_activity.yml | 5 ++--- detections/cloud/aws_exfiltration_via_batch_service.yml | 5 ++--- .../cloud/aws_exfiltration_via_bucket_replication.yml | 5 ++--- detections/cloud/aws_exfiltration_via_datasync_task.yml | 5 ++--- detections/cloud/aws_exfiltration_via_ec2_snapshot.yml | 5 ++--- ...ws_high_number_of_failed_authentications_for_user.yml | 5 ++--- ...aws_high_number_of_failed_authentications_from_ip.yml | 5 ++--- .../cloud/aws_iam_accessdenied_discovery_events.yml | 5 ++--- .../cloud/aws_iam_assume_role_policy_brute_force.yml | 5 ++--- detections/cloud/aws_iam_delete_policy.yml | 5 ++--- detections/cloud/aws_iam_failure_group_deletion.yml | 5 ++--- detections/cloud/aws_iam_successful_group_deletion.yml | 5 ++--- detections/cloud/aws_lambda_updatefunctioncode.yml | 5 ++--- .../cloud/aws_multi_factor_authentication_disabled.yml | 5 ++--- .../cloud/aws_multiple_failed_mfa_requests_for_user.yml | 5 ++--- ...ws_multiple_users_failing_to_authenticate_from_ip.yml | 5 ++--- ...k_access_control_list_created_with_all_open_ports.yml | 4 ++-- .../cloud/aws_network_access_control_list_deleted.yml | 5 ++--- .../cloud/aws_new_mfa_method_registered_for_user.yml | 7 +++---- detections/cloud/aws_password_policy_changes.yml | 5 ++--- detections/cloud/aws_saml_update_identity_provider.yml | 5 ++--- detections/cloud/aws_setdefaultpolicyversion.yml | 7 +++---- ...ccessful_console_authentication_from_multiple_ips.yml | 5 ++--- .../aws_successful_single_factor_authentication.yml | 5 ++--- detections/cloud/aws_updateloginprofile.yml | 5 ++--- 99 files changed, 105 insertions(+), 204 deletions(-) diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml index 32818e97f8..4661cd7890 100644 --- a/data_sources/asl_aws_cloudtrail.yml +++ b/data_sources/asl_aws_cloudtrail.yml @@ -12,7 +12,6 @@ supported_TA: url: https://splunkbase.splunk.com/app/1876 version: 7.9.1 output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml index 909af5d7de..034bcab85f 100644 --- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml +++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml @@ -125,7 +125,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "pri "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml index 7078b7a26c..ce74a1ecd8 100644 --- a/data_sources/aws_cloudtrail_consolelogin.yml +++ b/data_sources/aws_cloudtrail_consolelogin.yml @@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "acco "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "signin.aws.amazon.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml index 8e585a5e09..407633d8d1 100644 --- a/data_sources/aws_cloudtrail_copyobject.yml +++ b/data_sources/aws_cloudtrail_copyobject.yml @@ -118,7 +118,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111111111111", "eventCategory": "Data"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml index 8295e3b181..d6706c6c77 100644 --- a/data_sources/aws_cloudtrail_createaccesskey.yml +++ b/data_sources/aws_cloudtrail_createaccesskey.yml @@ -102,7 +102,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "121521347698"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml index ca084d10a3..aa119d01f6 100644 --- a/data_sources/aws_cloudtrail_createkey.yml +++ b/data_sources/aws_cloudtrail_createkey.yml @@ -149,7 +149,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml index c6a66e3f32..fb211300af 100644 --- a/data_sources/aws_cloudtrail_createloginprofile.yml +++ b/data_sources/aws_cloudtrail_createloginprofile.yml @@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml index 832dcc56b7..e0aadefe51 100644 --- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml @@ -120,7 +120,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "6d1ce00e-4099-463c-8a4d-2af2fb2178ba", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml index aecc7809b4..8e1f4a6263 100644 --- a/data_sources/aws_cloudtrail_createpolicyversion.yml +++ b/data_sources/aws_cloudtrail_createpolicyversion.yml @@ -105,7 +105,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml index b9a3c9f135..a398e50065 100644 --- a/data_sources/aws_cloudtrail_createsnapshot.yml +++ b/data_sources/aws_cloudtrail_createsnapshot.yml @@ -117,7 +117,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml index e7fee0117d..d484587ba3 100644 --- a/data_sources/aws_cloudtrail_createtask.yml +++ b/data_sources/aws_cloudtrail_createtask.yml @@ -120,7 +120,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "datasync.us-west-2.amazonaws.com"}, "sessionCredentialFromConsole": "true"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml index aac3d7e54e..a7a3d43c07 100644 --- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml @@ -99,7 +99,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "140429656527", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml index f75ae55128..cda2dd961e 100644 --- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml +++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml @@ -99,7 +99,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml index adac6bc3c5..d2c730a4fb 100644 --- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml @@ -99,7 +99,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml index d3f4838723..a1802e6af6 100644 --- a/data_sources/aws_cloudtrail_deletealarms.yml +++ b/data_sources/aws_cloudtrail_deletealarms.yml @@ -140,7 +140,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml index e9f71c39dd..6f7ce48ede 100644 --- a/data_sources/aws_cloudtrail_deletedetector.yml +++ b/data_sources/aws_cloudtrail_deletedetector.yml @@ -97,7 +97,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml index fb6fcd293c..e7356d4fc9 100644 --- a/data_sources/aws_cloudtrail_deletegroup.yml +++ b/data_sources/aws_cloudtrail_deletegroup.yml @@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "121522247101"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml index 5dfa194a17..79384c92fc 100644 --- a/data_sources/aws_cloudtrail_deleteipset.yml +++ b/data_sources/aws_cloudtrail_deleteipset.yml @@ -98,7 +98,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml index b26cfaec87..2bbb117a51 100644 --- a/data_sources/aws_cloudtrail_deleteloggroup.yml +++ b/data_sources/aws_cloudtrail_deleteloggroup.yml @@ -99,7 +99,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml index 7fc4b58fb7..701e581646 100644 --- a/data_sources/aws_cloudtrail_deletelogstream.yml +++ b/data_sources/aws_cloudtrail_deletelogstream.yml @@ -100,7 +100,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml index d126f8eec4..0eb7e6d70f 100644 --- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml @@ -109,7 +109,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "b9e05770-e9b0-4ba1-91e8-6537097e06e7", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml index c98ed8eef4..3c95c91f01 100644 --- a/data_sources/aws_cloudtrail_deletepolicy.yml +++ b/data_sources/aws_cloudtrail_deletepolicy.yml @@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "abd071bf-0a38-4fab-af4a-5eee55f0935e", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "151521547504"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml index 3fd4966201..60dac0131f 100644 --- a/data_sources/aws_cloudtrail_deleterule.yml +++ b/data_sources/aws_cloudtrail_deleterule.yml @@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml index ccba4f7ad5..02730fc756 100644 --- a/data_sources/aws_cloudtrail_deletesnapshot.yml +++ b/data_sources/aws_cloudtrail_deletesnapshot.yml @@ -144,7 +144,6 @@ example_log: '{"eventVersion": "1.09", "userIdentity": {"type": "AssumedRole", " "managementEvent": true, "recipientAccountId": "11111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml index 50b9c6c832..0944d15ccb 100644 --- a/data_sources/aws_cloudtrail_deletetrail.yml +++ b/data_sources/aws_cloudtrail_deletetrail.yml @@ -97,7 +97,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml index 35d80d2cf2..b66f8dc30d 100644 --- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml @@ -99,7 +99,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml index ab9fadfa4f..81501ea4b4 100644 --- a/data_sources/aws_cloudtrail_deletewebacl.yml +++ b/data_sources/aws_cloudtrail_deletewebacl.yml @@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml index bb05e04cf1..50af28b6b6 100644 --- a/data_sources/aws_cloudtrail_describeeventaggregates.yml +++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml @@ -96,7 +96,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip "AwsApiCall", "managementEvent": true, "recipientAccountId": "1111111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml index 25383e9108..6146de4e17 100644 --- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml +++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml @@ -894,7 +894,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml index 8433aa0149..1b8f8e9eb9 100644 --- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml @@ -98,7 +98,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "iam.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml index b6c55f6757..7d55728c59 100644 --- a/data_sources/aws_cloudtrail_getobject.yml +++ b/data_sources/aws_cloudtrail_getobject.yml @@ -112,7 +112,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "eventCategory": "Data", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "security-content.s3.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml index f7f9adc714..a83d3264e4 100644 --- a/data_sources/aws_cloudtrail_getpassworddata.yml +++ b/data_sources/aws_cloudtrail_getpassworddata.yml @@ -114,7 +114,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml index ca1acee232..c766323cf3 100644 --- a/data_sources/aws_cloudtrail_jobcreated.yml +++ b/data_sources/aws_cloudtrail_jobcreated.yml @@ -83,7 +83,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"accountId": "1111111111 "status": "New", "jobEventId": "4e70d2f1053c07a79d9be9a14e486020", "failureCodes": [], "statusChangeReason": []}, "eventCategory": "Management"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml index c9d2597bf2..4afe6f330f 100644 --- a/data_sources/aws_cloudtrail_modifydbinstance.yml +++ b/data_sources/aws_cloudtrail_modifydbinstance.yml @@ -192,7 +192,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml index 4b550d9c9a..22f0c62a72 100644 --- a/data_sources/aws_cloudtrail_modifyimageattribute.yml +++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml @@ -107,7 +107,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml index 2a1711a395..cca1162048 100644 --- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml @@ -100,7 +100,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml index 8607f79db3..37bc258120 100644 --- a/data_sources/aws_cloudtrail_putbucketacl.yml +++ b/data_sources/aws_cloudtrail_putbucketacl.yml @@ -115,7 +115,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "ARN": "arn:aws:s3:::patricktestbucket19"}], "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml index 8fb1f0ea5d..55cc0a7d94 100644 --- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml +++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml @@ -119,7 +119,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "my-cloudtrail-bucket-alfsujjpnbpguqrh.s3.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml index d089c50bc7..49c397946a 100644 --- a/data_sources/aws_cloudtrail_putbucketreplication.yml +++ b/data_sources/aws_cloudtrail_putbucketreplication.yml @@ -140,7 +140,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml index f7d9ea6c70..fed5c60bdf 100644 --- a/data_sources/aws_cloudtrail_putbucketversioning.yml +++ b/data_sources/aws_cloudtrail_putbucketversioning.yml @@ -128,7 +128,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml index 00942041d0..4979d0984b 100644 --- a/data_sources/aws_cloudtrail_putimage.yml +++ b/data_sources/aws_cloudtrail_putimage.yml @@ -150,8 +150,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management"}' output_fields: -- action -- dest - user - user_agent - src diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml index d2e74b6a55..6bd9926e53 100644 --- a/data_sources/aws_cloudtrail_putkeypolicy.yml +++ b/data_sources/aws_cloudtrail_putkeypolicy.yml @@ -131,7 +131,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml index df21b230e8..4668186ec5 100644 --- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml @@ -117,7 +117,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "46fe04b8-d007-4933-8bb8-c8b65c1121fa", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml index 0e1b6c9c57..1d14b86f17 100644 --- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml +++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml @@ -98,7 +98,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml index db0ffc8259..b41b64b887 100644 --- a/data_sources/aws_cloudtrail_stoplogging.yml +++ b/data_sources/aws_cloudtrail_stoplogging.yml @@ -94,7 +94,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml index 15abc1be57..6dba8a4a21 100644 --- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml @@ -106,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml index eda86cdbd3..2c6f1d8f3a 100644 --- a/data_sources/aws_cloudtrail_updateloginprofile.yml +++ b/data_sources/aws_cloudtrail_updateloginprofile.yml @@ -96,7 +96,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml index d2b4294c10..d43549d693 100644 --- a/data_sources/aws_cloudtrail_updatesamlprovider.yml +++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml @@ -186,7 +186,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", " "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}' output_fields: -- action - dest - user - user_agent diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml index 564b226acd..0aa753b227 100644 --- a/data_sources/aws_cloudtrail_updatetrail.yml +++ b/data_sources/aws_cloudtrail_updatetrail.yml @@ -106,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}' output_fields: -- action - dest - user - user_agent diff --git a/detections/cloud/aws_ami_attribute_modification_for_exfiltration.yml b/detections/cloud/aws_ami_attribute_modification_for_exfiltration.yml index 1f1fd7d422..040277bda5 100644 --- a/detections/cloud/aws_ami_attribute_modification_for_exfiltration.yml +++ b/detections/cloud/aws_ami_attribute_modification_for_exfiltration.yml @@ -19,9 +19,8 @@ search: '`cloudtrail` eventName=ModifyImageAttribute (requestParameters.launchPe | rename requestParameters.launchPermission.add.items{}.group as group_added | rename requestParameters.launchPermission.add.items{}.userId as accounts_added | eval ami_status=if(match(group_added,"all") ,"Public AMI", "Not Public") - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime values(group_added) as group_added values(accounts_added) as accounts_added values(ami_status) as ami_status by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime values(group_added) as group_added values(accounts_added) as accounts_added values(ami_status) as ami_status by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `aws_ami_attribute_modification_for_exfiltration_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_concurrent_sessions_from_different_ips.yml b/detections/cloud/aws_concurrent_sessions_from_different_ips.yml index 9787083dff..694f2a2989 100644 --- a/detections/cloud/aws_concurrent_sessions_from_different_ips.yml +++ b/detections/cloud/aws_concurrent_sessions_from_different_ips.yml @@ -17,9 +17,8 @@ data_source: - AWS CloudTrail DescribeEventAggregates search: '`cloudtrail` eventName = DescribeEventAggregates src_ip!="AWS Internal" | bin span=5m _time - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats min(_time) as firstTime max(_time) as lastTime values(user_agent) as user_agent values(action) as action values(src) as src values(dest) as dest dc(src) as distinct_ip_count by _time user vendor_account vendor_region vendor_product + | rename user_name as user + | stats min(_time) as firstTime max(_time) as lastTime values(user_agent) as user_agent values(signature) as signature values(src) as src values(dest) as dest dc(src) as distinct_ip_count by _time user vendor_account vendor_region vendor_product | where distinct_ip_count > 1 | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `aws_concurrent_sessions_from_different_ips_filter`' diff --git a/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml b/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml index 6796bcc648..0f5a179514 100644 --- a/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml +++ b/detections/cloud/aws_console_login_failed_during_mfa_challenge.yml @@ -16,9 +16,8 @@ description: The following analytic identifies failed authentication attempts to data_source: - AWS CloudTrail ConsoleLogin search: '`cloudtrail` eventName= ConsoleLogin errorMessage="Failed authentication" additionalEventData.MFAUsed = "Yes" - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product additionalEventData.MFAUsed errorMessage + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product additionalEventData.MFAUsed errorMessage | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_console_login_failed_during_mfa_challenge_filter`' diff --git a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml index 9742f0ee35..68f5e47739 100644 --- a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml +++ b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml @@ -19,9 +19,8 @@ search: '`cloudtrail` eventName=CreatePolicyVersion eventSource = iam.amazonaws. | mvexpand key_policy_statements | spath input=key_policy_statements output=key_policy_action_1 path=Action | where key_policy_action_1 = "*" - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime values(key_policy_statements) as policy_added by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime values(key_policy_statements) as policy_added by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`aws_create_policy_version_to_allow_all_resources_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_createaccesskey.yml b/detections/cloud/aws_createaccesskey.yml index d8fb41afe5..f549bef8e2 100644 --- a/detections/cloud/aws_createaccesskey.yml +++ b/detections/cloud/aws_createaccesskey.yml @@ -17,9 +17,8 @@ data_source: search: '`cloudtrail` eventName = CreateAccessKey userAgent !=console.amazonaws.com errorCode = success | eval match=if(match(userIdentity.userName,requestParameters.userName),1,0) | search match=0 - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`aws_createaccesskey_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_createloginprofile.yml b/detections/cloud/aws_createloginprofile.yml index 2acc9beb62..48c0aaa588 100644 --- a/detections/cloud/aws_createloginprofile.yml +++ b/detections/cloud/aws_createloginprofile.yml @@ -20,10 +20,9 @@ search: '`cloudtrail` eventName = CreateLoginProfile | join new_login_profile src_ip [| search `cloudtrail` eventName = ConsoleLogin | rename userIdentity.userName as new_login_profile - | stats count values(eventName) min(_time) as firstTime max(_time) as lastTime by eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn new_login_profile src_ip + | stats count values(eventName) min(_time) as firstTime max(_time) as lastTime by eventSource aws_account_id errorCode user_agent eventID awsRegion userIdentity.principalId user_arn new_login_profile src_ip dest vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`] - | rename eventName as action, eventSource as dest, user_arn as user, userAgent as user_agent, src_ip as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" + | rename user_arn as user | `aws_createloginprofile_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. @@ -48,13 +47,13 @@ drilldown_searches: latest_offset: $info_max_time$ rba: message: User $user$ is attempting to create a login profile for $new_login_profile$ - and did a console login from this IP $src$ + and did a console login from this IP $src_ip$ risk_objects: - field: user type: user score: 72 threat_objects: - - field: src + - field: src_ip type: ip_address tags: analytic_story: diff --git a/detections/cloud/aws_credential_access_failed_login.yml b/detections/cloud/aws_credential_access_failed_login.yml index ccf26bb80e..8ca873ae73 100644 --- a/detections/cloud/aws_credential_access_failed_login.yml +++ b/detections/cloud/aws_credential_access_failed_login.yml @@ -16,9 +16,8 @@ description: The following analytic identifies unsuccessful login attempts to th data_source: - AWS CloudTrail ConsoleLogin search: '`cloudtrail` eventName = ConsoleLogin errorMessage="Failed authentication" - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_credential_access_failed_login_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_credential_access_getpassworddata.yml b/detections/cloud/aws_credential_access_getpassworddata.yml index f10dcbf896..280f2fd046 100644 --- a/detections/cloud/aws_credential_access_getpassworddata.yml +++ b/detections/cloud/aws_credential_access_getpassworddata.yml @@ -17,9 +17,8 @@ data_source: - AWS CloudTrail GetPasswordData search: '`cloudtrail` eventName=GetPasswordData eventSource = ec2.amazonaws.com | bin _time span=5m - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime dc(requestParameters.instanceId) as distinct_instance_ids by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime dc(requestParameters.instanceId) as distinct_instance_ids by signature dest user user_agent src vendor_account vendor_region vendor_product | where distinct_instance_ids > 10 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_credential_access_getpassworddata_filter`' diff --git a/detections/cloud/aws_credential_access_rds_password_reset.yml b/detections/cloud/aws_credential_access_rds_password_reset.yml index 1a6310fc2f..ce23361a3d 100644 --- a/detections/cloud/aws_credential_access_rds_password_reset.yml +++ b/detections/cloud/aws_credential_access_rds_password_reset.yml @@ -16,9 +16,8 @@ description: The following analytic detects the resetting of the master user pas data_source: - AWS CloudTrail ModifyDBInstance search: '`cloudtrail` eventSource="rds.amazonaws.com" eventName=ModifyDBInstance "requestParameters.masterUserPassword"=* - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.dBInstanceIdentifier) as database_id by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.dBInstanceIdentifier) as database_id by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `aws_credential_access_rds_password_reset_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml b/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml index c2c6adda25..a5d6a1069a 100644 --- a/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml +++ b/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml @@ -16,9 +16,8 @@ description: The following analytic detects the deletion of AWS CloudTrail logs data_source: - AWS CloudTrail DeleteTrail search: '`cloudtrail` eventName = DeleteTrail eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `aws_defense_evasion_delete_cloudtrail_filter`' how_to_implement: You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. diff --git a/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml b/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml index 3308368693..289229b26d 100644 --- a/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml +++ b/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml @@ -16,9 +16,8 @@ description: The following analytic detects the deletion of CloudWatch log group data_source: - AWS CloudTrail DeleteLogGroup search: '`cloudtrail` eventName = DeleteLogGroup eventSource = logs.amazonaws.com userAgent !=console.amazonaws.com errorCode = success - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `aws_defense_evasion_delete_cloudwatch_log_group_filter`' how_to_implement: You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. diff --git a/detections/cloud/aws_defense_evasion_impair_security_services.yml b/detections/cloud/aws_defense_evasion_impair_security_services.yml index 7dbfa9ad82..ba0d646ecb 100644 --- a/detections/cloud/aws_defense_evasion_impair_security_services.yml +++ b/detections/cloud/aws_defense_evasion_impair_security_services.yml @@ -23,9 +23,8 @@ data_source: - AWS CloudTrail DeleteLoggingConfiguration - AWS CloudTrail DeleteAlarms search: '`cloudtrail` eventName IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms") - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `aws_defense_evasion_impair_security_services_filter`' how_to_implement: You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. diff --git a/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml b/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml index 243134cb17..89a5e96ddd 100644 --- a/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml +++ b/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml @@ -17,9 +17,8 @@ data_source: search: '`cloudtrail` eventName=PutBucketLifecycle user_type=IAMUser errorCode=success | spath path=requestParameters{}.LifecycleConfiguration{}.Rule{}.Expiration{}.Days output=expiration_days | spath path=requestParameters{}.bucketName output=bucket_name - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product bucket_name expiration_days + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product bucket_name expiration_days | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_defense_evasion_putbucketlifecycle_filter`' how_to_implement: You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. We recommend our users to set the expiration days value according diff --git a/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml b/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml index 1373c8781b..cdc2bf356b 100644 --- a/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml +++ b/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml @@ -16,9 +16,8 @@ description: The following analytic detects `StopLogging` events in AWS CloudTra data_source: - AWS CloudTrail StopLogging search: '`cloudtrail` eventName = StopLogging eventSource = cloudtrail.amazonaws.com userAgent!=console.amazonaws.com errorCode = success - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_defense_evasion_stop_logging_cloudtrail_filter`' how_to_implement: You must install Splunk AWS Add on and enable Cloudtrail logs in your AWS Environment. diff --git a/detections/cloud/aws_defense_evasion_update_cloudtrail.yml b/detections/cloud/aws_defense_evasion_update_cloudtrail.yml index 71a3be13fb..8959939a27 100644 --- a/detections/cloud/aws_defense_evasion_update_cloudtrail.yml +++ b/detections/cloud/aws_defense_evasion_update_cloudtrail.yml @@ -16,9 +16,8 @@ description: The following analytic detects `UpdateTrail` events in AWS CloudTra data_source: - AWS CloudTrail UpdateTrail search: '`cloudtrail` eventName = UpdateTrail eventSource = cloudtrail.amazonaws.com userAgent !=console.amazonaws.com errorCode = success - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `aws_defense_evasion_update_cloudtrail_filter`' how_to_implement: You must install Splunk AWS Add on and enable CloudTrail logs in your AWS Environment. diff --git a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml index 52c5bb40a6..64417b6060 100644 --- a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml +++ b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml @@ -24,9 +24,8 @@ search: '`cloudtrail` eventName=CreateKey OR eventName=PutKeyPolicy | eval key_policy_action=mvappend(key_policy_action_1,key_policy_action_2) | spath input=key_policy_statements output=key_policy_principal path=Principal.AWS | search key_policy_action="kms:Encrypt" AND key_policy_principal="*" - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product key_policy_action key_policy_principal + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product key_policy_action key_policy_principal | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_detect_users_creating_keys_with_encrypt_policy_without_mfa_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs diff --git a/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml b/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml index 9296c2c437..519597fbdc 100644 --- a/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml +++ b/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml @@ -16,9 +16,8 @@ data_source: - AWS CloudTrail search: '`cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-encryption="aws:kms" | rename requestParameters.bucketName AS bucketName, requestParameters.x-amz-copy-source AS src_file, requestParameters.key AS dest_file - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product bucketName src_file dest_file + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product bucketName src_file dest_file | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `aws_detect_users_with_kms_keys_performing_encryption_s3_filter`' how_to_implement: You must install Splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs diff --git a/detections/cloud/aws_disable_bucket_versioning.yml b/detections/cloud/aws_disable_bucket_versioning.yml index 633072c453..9cf1b782c4 100644 --- a/detections/cloud/aws_disable_bucket_versioning.yml +++ b/detections/cloud/aws_disable_bucket_versioning.yml @@ -15,9 +15,8 @@ description: The following analytic detects when AWS S3 bucket versioning is sus lead to data loss and hinder recovery efforts, severely impacting data integrity and availability. search: '`cloudtrail` eventName= PutBucketVersioning "requestParameters.VersioningConfiguration.Status"=Suspended - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region, requestParameters.bucketName as bucket_name - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product bucket_name + | rename user_name as user, requestParameters.bucketName as bucket_name + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product bucket_name | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_disable_bucket_versioning_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_ec2_snapshot_shared_externally.yml b/detections/cloud/aws_ec2_snapshot_shared_externally.yml index 16499e4a92..359d152a38 100644 --- a/detections/cloud/aws_ec2_snapshot_shared_externally.yml +++ b/detections/cloud/aws_ec2_snapshot_shared_externally.yml @@ -20,9 +20,8 @@ search: '`cloudtrail` eventName=ModifySnapshotAttribute | search requested_account_id != NULL | eval match=if(requested_account_id==aws_account_id,"Match","No Match") | where match = "No Match" - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product requested_account_id + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product requested_account_id | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ec2_snapshot_shared_externally_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This diff --git a/detections/cloud/aws_ecr_container_scanning_findings_high.yml b/detections/cloud/aws_ecr_container_scanning_findings_high.yml index 3714ddbd98..fd84cd5a47 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_high.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_high.yml @@ -22,9 +22,8 @@ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanF | spath input=findings | search severity=HIGH | rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_high_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml index 106f0ae2ed..c2a4626cf0 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml @@ -21,9 +21,8 @@ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanF | spath input=findings | search severity IN ("LOW", "INFORMATIONAL", "UNKNOWN") | rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_low_informational_unknown_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This diff --git a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml index 4f7b7f2c14..4bc30f42d7 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml @@ -21,9 +21,8 @@ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanF | spath input=findings | search severity=MEDIUM | rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product finding_name finding_description imageDigest repository | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_medium_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml index ec7d22be55..06ffc02b79 100644 --- a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml +++ b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml @@ -19,9 +19,8 @@ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=PutImage date_hour OR date_hour<8 OR date_wday=saturday OR date_wday=sunday | rename requestParameters.* as * | rename repositoryName AS repository - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product repository + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature user user_agent src vendor_account vendor_region vendor_product repository | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_upload_outside_business_hours_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_ecr_container_upload_unknown_user.yml b/detections/cloud/aws_ecr_container_upload_unknown_user.yml index ecf00814e5..6efff0d27f 100644 --- a/detections/cloud/aws_ecr_container_upload_unknown_user.yml +++ b/detections/cloud/aws_ecr_container_upload_unknown_user.yml @@ -17,9 +17,8 @@ data_source: search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=PutImage NOT `aws_ecr_users` | rename requestParameters.* as * | rename repositoryName AS image - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product image + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature user user_agent src vendor_account vendor_region vendor_product image | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_upload_unknown_user_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This diff --git a/detections/cloud/aws_excessive_security_scanning.yml b/detections/cloud/aws_excessive_security_scanning.yml index 5451636bfb..437210a221 100644 --- a/detections/cloud/aws_excessive_security_scanning.yml +++ b/detections/cloud/aws_excessive_security_scanning.yml @@ -16,9 +16,8 @@ data_source: - AWS CloudTrail search: '`cloudtrail` eventName=Describe* OR eventName=List* OR eventName=Get* | fillnull - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats dc(action) as dc_events min(_time) as firstTime max(_time) as lastTime values(action) as action values(dest) as dest values(user_agent) as user_agent values(src) as src values(vendor_account) as vendor_account values(vendor_region) as vendor_region by user + | rename user_name as user + | stats dc(signature) as dc_events min(_time) as firstTime max(_time) as lastTime values(signature) as signature values(dest) as dest values(user_agent) as user_agent values(src) as src values(vendor_account) as vendor_account values(vendor_region) as vendor_region by user | where dc_events > 50 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`aws_excessive_security_scanning_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This @@ -42,7 +41,7 @@ drilldown_searches: latest_offset: $info_max_time$ rba: message: User $user$ has excessive number of api calls $dc_events$ from these IP - addresses $src$, violating the threshold of 50, using the following actions $action$. + addresses $src$, violating the threshold of 50, using the following actions $signature$. risk_objects: - field: user type: user diff --git a/detections/cloud/aws_exfiltration_via_anomalous_getobject_api_activity.yml b/detections/cloud/aws_exfiltration_via_anomalous_getobject_api_activity.yml index ac279b1848..7a7a3777b1 100644 --- a/detections/cloud/aws_exfiltration_via_anomalous_getobject_api_activity.yml +++ b/detections/cloud/aws_exfiltration_via_anomalous_getobject_api_activity.yml @@ -16,9 +16,8 @@ description: The following analytic identifies anomalous GetObject API activity exfiltrate sensitive data, leading to data breaches and compliance violations. search: '`cloudtrail` eventName=GetObject | bin _time span=10m - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count values(requestParameters.bucketName) as bucketName by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count values(requestParameters.bucketName) as bucketName by signature dest user user_agent src vendor_account vendor_region vendor_product | anomalydetection "count" "user" action=annotate | search probable_cause=* |`aws_exfiltration_via_anomalous_getobject_api_activity_filter`' diff --git a/detections/cloud/aws_exfiltration_via_batch_service.yml b/detections/cloud/aws_exfiltration_via_batch_service.yml index 4b76762dcb..b8d5a7fbd1 100644 --- a/detections/cloud/aws_exfiltration_via_batch_service.yml +++ b/detections/cloud/aws_exfiltration_via_batch_service.yml @@ -16,9 +16,8 @@ description: The following analytic identifies the creation of AWS Batch jobs th and loss of sensitive information. search: '`cloudtrail` eventName = JobCreated | fillnull - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_exfiltration_via_batch_service_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_exfiltration_via_bucket_replication.yml b/detections/cloud/aws_exfiltration_via_bucket_replication.yml index 93c4a38b18..4b51afcc02 100644 --- a/detections/cloud/aws_exfiltration_via_bucket_replication.yml +++ b/detections/cloud/aws_exfiltration_via_bucket_replication.yml @@ -15,9 +15,8 @@ description: The following analytic detects API calls to enable S3 bucket replic could replicate sensitive data to external accounts, leading to data breaches and compliance violations. search: '`cloudtrail` eventName = PutBucketReplication eventSource = s3.amazonaws.com - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region, requestParameters.bucketName as bucket_name - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product bucket_name + | rename user_name as user, requestParameters.ReplicationConfiguration.Rule.Destination.Bucket as bucket_name + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product bucket_name | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_exfiltration_via_bucket_replication_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_exfiltration_via_datasync_task.yml b/detections/cloud/aws_exfiltration_via_datasync_task.yml index b0e454b109..7d959dccfb 100644 --- a/detections/cloud/aws_exfiltration_via_datasync_task.yml +++ b/detections/cloud/aws_exfiltration_via_datasync_task.yml @@ -16,9 +16,8 @@ description: The following analytic detects the creation of an AWS DataSync task data breaches and compliance violations. search: '`cloudtrail` eventName = CreateTask eventSource="datasync.amazonaws.com" | rename requestParameters.* as * - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product destinationLocationArn sourceLocationArn + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product destinationLocationArn sourceLocationArn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_exfiltration_via_datasync_task_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_exfiltration_via_ec2_snapshot.yml b/detections/cloud/aws_exfiltration_via_ec2_snapshot.yml index 29dcbe0b67..5b182eaf4b 100644 --- a/detections/cloud/aws_exfiltration_via_ec2_snapshot.yml +++ b/detections/cloud/aws_exfiltration_via_ec2_snapshot.yml @@ -20,9 +20,8 @@ description: The following analytic detects a series of AWS API calls related to violations. search: '`cloudtrail` eventName IN ("CreateSnapshot", "DescribeSnapshotAttribute", "ModifySnapshotAttribute", "DeleteSnapshot") src_ip !="guardduty.amazonaws.com" | bin _time span=5m - | eval vendor_product = "AWS" - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | stats count dc(action) as distinct_api_calls values(action) as action values(dest) as dest values(requestParameters.attributeType) as attributeType values(requestParameters.createVolumePermission.add.items{}.userId) as aws_account_id_added values(user_agent) as user_agent by _time user src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count dc(signature) as distinct_api_calls values(signature) as signature values(dest) as dest values(requestParameters.attributeType) as attributeType values(requestParameters.createVolumePermission.add.items{}.userId) as aws_account_id_added values(user_agent) as user_agent by _time user src vendor_account vendor_region vendor_product | where distinct_api_calls >= 2 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_exfiltration_via_ec2_snapshot_filter`' diff --git a/detections/cloud/aws_high_number_of_failed_authentications_for_user.yml b/detections/cloud/aws_high_number_of_failed_authentications_for_user.yml index d9afb8b908..a522509486 100644 --- a/detections/cloud/aws_high_number_of_failed_authentications_for_user.yml +++ b/detections/cloud/aws_high_number_of_failed_authentications_for_user.yml @@ -16,9 +16,8 @@ data_source: - AWS CloudTrail ConsoleLogin search: '`cloudtrail` eventName=ConsoleLogin action=failure | bucket span=10m _time - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats dc(_raw) AS failed_attempts values(src) as src values(user_agent) as user_agent by _time, user, action, dest, vendor_account vendor_region, vendor_product + | rename user_name as user + | stats dc(_raw) AS failed_attempts values(src) as src values(user_agent) as user_agent by _time, user, signature, dest, vendor_account vendor_region, vendor_product | where failed_attempts > 20 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_high_number_of_failed_authentications_for_user_filter`' diff --git a/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml b/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml index 80213c5005..ead873137d 100644 --- a/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml +++ b/detections/cloud/aws_high_number_of_failed_authentications_from_ip.yml @@ -16,9 +16,8 @@ data_source: - AWS CloudTrail ConsoleLogin search: '`cloudtrail` eventName=ConsoleLogin action=failure | bucket span=10m _time - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats dc(_raw) AS failed_attempts values(user) as user values(user_agent) as user_agent by _time, src, action, dest, vendor_account vendor_region, vendor_product + | rename user_name as user + | stats dc(_raw) AS failed_attempts values(user) as user values(user_agent) as user_agent by _time, src, signature, dest, vendor_account vendor_region, vendor_product | where failed_attempts > 20 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_high_number_of_failed_authentications_from_ip_filter`' diff --git a/detections/cloud/aws_iam_accessdenied_discovery_events.yml b/detections/cloud/aws_iam_accessdenied_discovery_events.yml index f3f2d7600f..32ebb2a3f9 100644 --- a/detections/cloud/aws_iam_accessdenied_discovery_events.yml +++ b/detections/cloud/aws_iam_accessdenied_discovery_events.yml @@ -16,9 +16,8 @@ data_source: - AWS CloudTrail search: '`cloudtrail` (errorCode = "AccessDenied") user_type=IAMUser (userAgent!=*.amazonaws.com) | bucket _time span=1h - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count as failures min(_time) as firstTime max(_time) as lastTime, dc(action) as methods, dc(dest) as sources values(action) as action values(dest) as dest by src, user, vendor_account vendor_region, vendor_product + | rename user_name as user + | stats count as failures min(_time) as firstTime max(_time) as lastTime, dc(signature) as methods, dc(dest) as sources values(signature) as signature values(dest) as dest by src, user, vendor_account vendor_region, vendor_product | where failures >= 5 and methods >= 1 and sources >= 1 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_accessdenied_discovery_events_filter`' diff --git a/detections/cloud/aws_iam_assume_role_policy_brute_force.yml b/detections/cloud/aws_iam_assume_role_policy_brute_force.yml index 5950c7d510..59362ff946 100644 --- a/detections/cloud/aws_iam_assume_role_policy_brute_force.yml +++ b/detections/cloud/aws_iam_assume_role_policy_brute_force.yml @@ -16,9 +16,8 @@ description: The following analytic detects multiple failed attempts to assume a data_source: - AWS CloudTrail search: '`cloudtrail` (errorCode=MalformedPolicyDocumentException) status=failure (userAgent!=*.amazonaws.com) - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyName) as policy_name by src, user, vendor_account vendor_region, vendor_product, action, dest, errorCode + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyName) as policy_name by src, user, vendor_account vendor_region, vendor_product, signature, dest, errorCode | where count >= 2 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_assume_role_policy_brute_force_filter`' how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize diff --git a/detections/cloud/aws_iam_delete_policy.yml b/detections/cloud/aws_iam_delete_policy.yml index 9a1ff45d95..1144a49768 100644 --- a/detections/cloud/aws_iam_delete_policy.yml +++ b/detections/cloud/aws_iam_delete_policy.yml @@ -16,9 +16,8 @@ description: The following analytic detects the deletion of an IAM policy in AWS data_source: - AWS CloudTrail DeletePolicy search: '`cloudtrail` eventName=DeletePolicy (userAgent!=*.amazonaws.com) - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_delete_policy_filter`' how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS CloudTrail logs. diff --git a/detections/cloud/aws_iam_failure_group_deletion.yml b/detections/cloud/aws_iam_failure_group_deletion.yml index c2d7f3f6be..72960b4c4d 100644 --- a/detections/cloud/aws_iam_failure_group_deletion.yml +++ b/detections/cloud/aws_iam_failure_group_deletion.yml @@ -16,9 +16,8 @@ description: The following analytic identifies failed attempts to delete AWS IAM data_source: - AWS CloudTrail DeleteGroup search: '`cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode IN (NoSuchEntityException,DeleteConflictException, AccessDenied) (userAgent!=*.amazonaws.com) - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_failure_group_deletion_filter`' how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS CloudTrail logs. diff --git a/detections/cloud/aws_iam_successful_group_deletion.yml b/detections/cloud/aws_iam_successful_group_deletion.yml index 95b05b3e42..665e28a8f0 100644 --- a/detections/cloud/aws_iam_successful_group_deletion.yml +++ b/detections/cloud/aws_iam_successful_group_deletion.yml @@ -16,9 +16,8 @@ description: The following analytic identifies the successful deletion of an IAM data_source: - AWS CloudTrail DeleteGroup search: '`cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode=success (userAgent!=*.amazonaws.com) - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_successful_group_deletion_filter`' how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. The search requires AWS CloudTrail logs. diff --git a/detections/cloud/aws_lambda_updatefunctioncode.yml b/detections/cloud/aws_lambda_updatefunctioncode.yml index cead07f377..41391682b0 100644 --- a/detections/cloud/aws_lambda_updatefunctioncode.yml +++ b/detections/cloud/aws_lambda_updatefunctioncode.yml @@ -15,9 +15,8 @@ description: The following analytic identifies IAM users attempting to update or data_source: - AWS CloudTrail search: '`cloudtrail` eventSource=lambda.amazonaws.com eventName=UpdateFunctionCode* errorCode = success user_type=IAMUser - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`aws_lambda_updatefunctioncode_filter`' how_to_implement: You must install Splunk AWS Add on and enable Cloudtrail logs in your AWS Environment. diff --git a/detections/cloud/aws_multi_factor_authentication_disabled.yml b/detections/cloud/aws_multi_factor_authentication_disabled.yml index 89e34fd41d..20be3ffafa 100644 --- a/detections/cloud/aws_multi_factor_authentication_disabled.yml +++ b/detections/cloud/aws_multi_factor_authentication_disabled.yml @@ -16,9 +16,8 @@ data_source: - AWS CloudTrail DeleteVirtualMFADevice - AWS CloudTrail DeactivateMFADevice search: '`cloudtrail` (eventName= DeleteVirtualMFADevice OR eventName=DeactivateMFADevice) - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_multi_factor_authentication_disabled_filter`' how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search requires AWS CloudTrail logs. diff --git a/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml b/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml index 5364cabcce..258579585e 100644 --- a/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml +++ b/detections/cloud/aws_multiple_failed_mfa_requests_for_user.yml @@ -16,9 +16,8 @@ data_source: - AWS CloudTrail ConsoleLogin search: '`cloudtrail` eventName= ConsoleLogin "additionalEventData.MFAUsed"=Yes errorMessage="Failed authentication" | bucket span=5m _time - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats dc(_raw) as mfa_prompts min(_time) as firstTime max(_time) as lastTime values(user_agent) as user_agent values(src) as src by _time user dest action vendor_account vendor_region vendor_product errorMessage + | rename user_name as user + | stats dc(_raw) as mfa_prompts min(_time) as firstTime max(_time) as lastTime values(user_agent) as user_agent values(src) as src values(dest) as dest by _time user signature vendor_account vendor_region vendor_product errorMessage | where mfa_prompts > 10 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_multiple_failed_mfa_requests_for_user_filter`' how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search diff --git a/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml index 8430271670..4ab70632ac 100644 --- a/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml +++ b/detections/cloud/aws_multiple_users_failing_to_authenticate_from_ip.yml @@ -17,9 +17,8 @@ data_source: - AWS CloudTrail ConsoleLogin search: '`cloudtrail` eventName=ConsoleLogin action=failure | bucket span=10m _time - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats dc(user) AS unique_accounts values(user) as user values(user_agent) as user_agent by _time, src, action, dest, vendor_account, vendor_region, vendor_product + | rename user_name as user + | stats dc(user) AS unique_accounts values(user) as user values(user_agent) as user_agent by _time, src, signature, dest, vendor_account, vendor_region, vendor_product | where unique_accounts>30 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_multiple_users_failing_to_authenticate_from_ip_filter`' how_to_implement: You must install Splunk Add-on for AWS in order to ingest Cloudtrail. diff --git a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml index 53a0b53635..65b3e082ec 100644 --- a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml +++ b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml @@ -22,8 +22,8 @@ search: "`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetwor | eval port_range='requestParameters.portRange.to' - 'requestParameters.portRange.from' | where port_range>1024] | fillnull - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product requestParameters.ruleAction requestParameters.egress requestParameters.aclProtocol requestParameters.portRange.to requestParameters.portRange.from requestParameters.cidrBlock + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product requestParameters.ruleAction requestParameters.egress requestParameters.aclProtocol requestParameters.portRange.to requestParameters.portRange.from requestParameters.cidrBlock | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `aws_network_access_control_list_created_with_all_open_ports_filter`" how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS, version 4.4.0 or later, and configure your AWS CloudTrail diff --git a/detections/cloud/aws_network_access_control_list_deleted.yml b/detections/cloud/aws_network_access_control_list_deleted.yml index 8d91777aae..0fa6db478b 100644 --- a/detections/cloud/aws_network_access_control_list_deleted.yml +++ b/detections/cloud/aws_network_access_control_list_deleted.yml @@ -16,9 +16,8 @@ data_source: - AWS CloudTrail DeleteNetworkAclEntry search: '`cloudtrail` eventName=DeleteNetworkAclEntry requestParameters.egress=false | fillnull - | rename eventName as signature, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product signature + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_network_access_control_list_deleted_filter`' how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail diff --git a/detections/cloud/aws_new_mfa_method_registered_for_user.yml b/detections/cloud/aws_new_mfa_method_registered_for_user.yml index 9023487963..b7c524e1b0 100644 --- a/detections/cloud/aws_new_mfa_method_registered_for_user.yml +++ b/detections/cloud/aws_new_mfa_method_registered_for_user.yml @@ -15,9 +15,8 @@ description: The following analytic detects the registration of a new Multi-Fact data_source: - AWS CloudTrail CreateVirtualMFADevice search: '`cloudtrail` eventName=CreateVirtualMFADevice - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region, requestParameters.virtualMFADeviceName as virtualMFADeviceName - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product virtualMFADeviceName + | rename userName as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_new_mfa_method_registered_for_user_filter`' how_to_implement: You must install Splunk AWS add on and Splunk App for AWS. This @@ -44,7 +43,7 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: A new virtual device $virtualMFADeviceName$ is added to user $user$ + message: A new virtual device is added to user $user$ risk_objects: - field: user type: user diff --git a/detections/cloud/aws_password_policy_changes.yml b/detections/cloud/aws_password_policy_changes.yml index 441a3eeec2..4795411501 100644 --- a/detections/cloud/aws_password_policy_changes.yml +++ b/detections/cloud/aws_password_policy_changes.yml @@ -18,9 +18,8 @@ data_source: - AWS CloudTrail GetAccountPasswordPolicy - AWS CloudTrail DeleteAccountPasswordPolicy search: '`cloudtrail` eventName IN ("UpdateAccountPasswordPolicy","GetAccountPasswordPolicy","DeleteAccountPasswordPolicy") errorCode=success - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_password_policy_changes_filter`' how_to_implement: You must install Splunk AWS Add on and Splunk App for AWS. This search works with AWS CloudTrail logs. diff --git a/detections/cloud/aws_saml_update_identity_provider.yml b/detections/cloud/aws_saml_update_identity_provider.yml index 666cf8c96e..1cbc4848f6 100644 --- a/detections/cloud/aws_saml_update_identity_provider.yml +++ b/detections/cloud/aws_saml_update_identity_provider.yml @@ -16,9 +16,8 @@ description: The following analytic detects updates to the SAML provider in AWS. data_source: - AWS CloudTrail UpdateSAMLProvider search: '`cloudtrail` eventName=UpdateSAMLProvider - | rename requestParameters.sAMLProviderArn as request_parameters , eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime values(request_parameters) as request_parameters by action dest user user_agent src vendor_account vendor_region vendor_product signature + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime values(request_parameters) as request_parameters by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_saml_update_identity_provider_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This diff --git a/detections/cloud/aws_setdefaultpolicyversion.yml b/detections/cloud/aws_setdefaultpolicyversion.yml index 5d775a0401..6d5fb033e9 100644 --- a/detections/cloud/aws_setdefaultpolicyversion.yml +++ b/detections/cloud/aws_setdefaultpolicyversion.yml @@ -15,9 +15,8 @@ description: The following analytic detects when a user sets a default policy ve data_source: - AWS CloudTrail SetDefaultPolicyVersion search: '`cloudtrail` eventName=SetDefaultPolicyVersion eventSource = iam.amazonaws.com - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_setdefaultpolicyversion_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs. @@ -43,7 +42,7 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: From IP address $src$, user $user$ has trigged an action $action$ + message: From IP address $src$, user $user$ has trigged an action $signature$ for updating the the default policy version risk_objects: - field: user diff --git a/detections/cloud/aws_successful_console_authentication_from_multiple_ips.yml b/detections/cloud/aws_successful_console_authentication_from_multiple_ips.yml index c159754c61..d7ec66df03 100644 --- a/detections/cloud/aws_successful_console_authentication_from_multiple_ips.yml +++ b/detections/cloud/aws_successful_console_authentication_from_multiple_ips.yml @@ -16,9 +16,8 @@ data_source: - AWS CloudTrail ConsoleLogin search: '`cloudtrail` eventName = ConsoleLogin | bin span=5m _time - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats dc(src) as distinct_ip_count values(src) as src values(user_agent) as user_agent by _time, user, action, dest, vendor_account, vendor_region, vendor_product + | rename user_name as user + | stats dc(src) as distinct_ip_count values(src) as src values(user_agent) as user_agent values(dest) as dest by _time, user, signature, vendor_account, vendor_region, vendor_product | where distinct_ip_count>1 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_successful_console_authentication_from_multiple_ips_filter`' how_to_implement: You must install Splunk AWS add on and Splunk App for AWS. This diff --git a/detections/cloud/aws_successful_single_factor_authentication.yml b/detections/cloud/aws_successful_single_factor_authentication.yml index 9f326936db..798789c6c7 100644 --- a/detections/cloud/aws_successful_single_factor_authentication.yml +++ b/detections/cloud/aws_successful_single_factor_authentication.yml @@ -15,9 +15,8 @@ description: The following analytic identifies a successful Console Login authen data_source: - AWS CloudTrail ConsoleLogin search: '`cloudtrail` eventName= ConsoleLogin errorCode=success "additionalEventData.MFAUsed"=No - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_successful_single_factor_authentication_filter`' how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml index da468246ac..50948031d0 100644 --- a/detections/cloud/aws_updateloginprofile.yml +++ b/detections/cloud/aws_updateloginprofile.yml @@ -18,9 +18,8 @@ data_source: search: '`cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com errorCode = success | eval match=if(match(userIdentity.userName,requestParameters.userName), 1,0) | search match=0 - | rename eventName as action, eventSource as dest, userName as user, userAgent as user_agent, sourceIPAddress as src, userIdentity.accountId as vendor_account, awsRegion as vendor_region - | eval vendor_product = "AWS" - | stats count min(_time) as firstTime max(_time) as lastTime by action dest user user_agent src vendor_account vendor_region vendor_product + | rename user_name as user + | stats count min(_time) as firstTime max(_time) as lastTime by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_updateloginprofile_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This From 81e080182943d959536bb6fd2efe30e1149f865d Mon Sep 17 00:00:00 2001 From: Patrick Bareiss Date: Tue, 18 Mar 2025 13:55:20 +0100 Subject: [PATCH 56/67] rerun CI --- detections/cloud/aws_createloginprofile.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/detections/cloud/aws_createloginprofile.yml b/detections/cloud/aws_createloginprofile.yml index 48c0aaa588..aa3455544e 100644 --- a/detections/cloud/aws_createloginprofile.yml +++ b/detections/cloud/aws_createloginprofile.yml @@ -73,3 +73,5 @@ tests: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createloginprofile/aws_cloudtrail_events.json sourcetype: aws:cloudtrail source: aws_cloudtrail + + \ No newline at end of file From 6a53b8c61bf724a6f2b51d96da83d0fefeb417eb Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Tue, 18 Mar 2025 10:52:47 -0700 Subject: [PATCH 57/67] adding 2 splunk detections --- deprecated/deprecated_detection_mapping.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecated_detection_mapping.yml index 94813fd1da..e681484193 100644 --- a/deprecated/deprecated_detection_mapping.yml +++ b/deprecated/deprecated_detection_mapping.yml @@ -1,4 +1,10 @@ detections: + - deprecated_content: Open Redirect in Splunk Web + deprecated_in_version: 5.2.0 + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity + - deprecated_content: Splunk Enterprise Information Disclosure + deprecated_in_version: 5.2.0 + reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - deprecated_content: ASL AWS Excessive Security Scanning deprecated_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity From 86e7863669d628e53c181dde14c6de34b5cd1b6a Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Tue, 18 Mar 2025 11:16:32 -0700 Subject: [PATCH 58/67] updating file name --- .../{deprecated_detection_mapping.yml => deprecation_mapping.YML} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename deprecated/{deprecated_detection_mapping.yml => deprecation_mapping.YML} (100%) diff --git a/deprecated/deprecated_detection_mapping.yml b/deprecated/deprecation_mapping.YML similarity index 100% rename from deprecated/deprecated_detection_mapping.yml rename to deprecated/deprecation_mapping.YML From da5c9b9bbd7a6ec7ac65ccafc25e6a751ebe0e82 Mon Sep 17 00:00:00 2001 From: delgado-jacob <29643013+delgado-jacob@users.noreply.github.com> Date: Tue, 18 Mar 2025 11:37:35 -0700 Subject: [PATCH 59/67] fix separator_value field --- data_sources/aws_cloudtrail_copyobject.yml | 2 +- data_sources/aws_cloudtrail_createtask.yml | 2 +- data_sources/powershell_script_block_logging_4104.yml | 2 +- data_sources/sysmon_eventid_1.yml | 2 +- data_sources/sysmon_eventid_10.yml | 2 +- data_sources/sysmon_eventid_11.yml | 2 +- data_sources/sysmon_eventid_12.yml | 2 +- data_sources/sysmon_eventid_13.yml | 2 +- data_sources/sysmon_eventid_15.yml | 2 +- data_sources/sysmon_eventid_17.yml | 2 +- data_sources/sysmon_eventid_18.yml | 2 +- data_sources/sysmon_eventid_21.yml | 2 +- data_sources/sysmon_eventid_22.yml | 2 +- data_sources/sysmon_eventid_23.yml | 2 +- data_sources/sysmon_eventid_3.yml | 2 +- data_sources/sysmon_eventid_5.yml | 2 +- data_sources/sysmon_eventid_6.yml | 2 +- data_sources/sysmon_eventid_7.yml | 2 +- data_sources/sysmon_eventid_8.yml | 2 +- data_sources/sysmon_eventid_9.yml | 2 +- data_sources/sysmon_for_linux_eventid_1.yml | 2 +- data_sources/windows_event_log_application_3000.yml | 2 +- data_sources/windows_event_log_capi2_70.yml | 2 +- data_sources/windows_event_log_capi2_81.yml | 2 +- .../windows_event_log_certificateservicesclient_1007.yml | 2 +- data_sources/windows_event_log_defender_1121.yml | 2 +- data_sources/windows_event_log_defender_1122.yml | 2 +- data_sources/windows_event_log_defender_1129.yml | 2 +- data_sources/windows_event_log_printservice_316.yml | 2 +- data_sources/windows_event_log_printservice_808.yml | 2 +- data_sources/windows_event_log_remoteconnectionmanager_1149.yml | 2 +- data_sources/windows_event_log_security_1100.yml | 2 +- data_sources/windows_event_log_security_1102.yml | 2 +- data_sources/windows_event_log_security_4624.yml | 2 +- data_sources/windows_event_log_security_4625.yml | 2 +- data_sources/windows_event_log_security_4627.yml | 2 +- data_sources/windows_event_log_security_4648.yml | 2 +- data_sources/windows_event_log_security_4662.yml | 2 +- data_sources/windows_event_log_security_4663.yml | 2 +- data_sources/windows_event_log_security_4672.yml | 2 +- data_sources/windows_event_log_security_4688.yml | 2 +- data_sources/windows_event_log_security_4698.yml | 2 +- data_sources/windows_event_log_security_4699.yml | 2 +- data_sources/windows_event_log_security_4703.yml | 2 +- data_sources/windows_event_log_security_4719.yml | 2 +- data_sources/windows_event_log_security_4720.yml | 2 +- data_sources/windows_event_log_security_4724.yml | 2 +- data_sources/windows_event_log_security_4725.yml | 2 +- data_sources/windows_event_log_security_4726.yml | 2 +- data_sources/windows_event_log_security_4732.yml | 2 +- data_sources/windows_event_log_security_4738.yml | 2 +- data_sources/windows_event_log_security_4739.yml | 2 +- data_sources/windows_event_log_security_4741.yml | 2 +- data_sources/windows_event_log_security_4768.yml | 2 +- data_sources/windows_event_log_security_4769.yml | 2 +- data_sources/windows_event_log_security_4771.yml | 2 +- data_sources/windows_event_log_security_4776.yml | 2 +- data_sources/windows_event_log_security_4781.yml | 2 +- data_sources/windows_event_log_security_4876.yml | 2 +- data_sources/windows_event_log_security_4886.yml | 2 +- data_sources/windows_event_log_security_4887.yml | 2 +- data_sources/windows_event_log_security_5136.yml | 2 +- data_sources/windows_event_log_security_5137.yml | 2 +- data_sources/windows_event_log_security_5140.yml | 2 +- data_sources/windows_event_log_security_5141.yml | 2 +- data_sources/windows_event_log_security_5145.yml | 2 +- data_sources/windows_event_log_system_4720.yml | 2 +- data_sources/windows_event_log_system_4726.yml | 2 +- data_sources/windows_event_log_system_4728.yml | 2 +- data_sources/windows_event_log_system_7036.yml | 2 +- data_sources/windows_event_log_system_7040.yml | 2 +- data_sources/windows_event_log_system_7045.yml | 2 +- data_sources/windows_event_log_taskscheduler_200.yml | 2 +- data_sources/windows_iis_29.yml | 2 +- 74 files changed, 74 insertions(+), 74 deletions(-) diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml index 1a505ff56f..9e10225b8d 100644 --- a/data_sources/aws_cloudtrail_copyobject.yml +++ b/data_sources/aws_cloudtrail_copyobject.yml @@ -13,7 +13,7 @@ mitre_components: source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName -separator_values: CopyObject +separator_value: CopyObject supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml index f474925295..2cfea8e296 100644 --- a/data_sources/aws_cloudtrail_createtask.yml +++ b/data_sources/aws_cloudtrail_createtask.yml @@ -13,7 +13,7 @@ mitre_components: source: aws_cloudtrail sourcetype: aws:cloudtrail separator: eventName -separator_name: CreateTask +separator_value: CreateTask supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index 99f3ace10f..a92378edf7 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -14,7 +14,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 4104 +separator_value: '4104' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/sysmon_eventid_1.yml b/data_sources/sysmon_eventid_1.yml index ca295fd89b..82abab53f8 100644 --- a/data_sources/sysmon_eventid_1.yml +++ b/data_sources/sysmon_eventid_1.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 1 +separator_value: '1' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_10.yml b/data_sources/sysmon_eventid_10.yml index 844e023f1a..8afd1accf9 100644 --- a/data_sources/sysmon_eventid_10.yml +++ b/data_sources/sysmon_eventid_10.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 10 +separator_value: '10' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_11.yml b/data_sources/sysmon_eventid_11.yml index f0e6dee766..dc1c00aa6c 100644 --- a/data_sources/sysmon_eventid_11.yml +++ b/data_sources/sysmon_eventid_11.yml @@ -14,7 +14,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 11 +separator_value: '11' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_12.yml b/data_sources/sysmon_eventid_12.yml index 5a2c89c0ec..d7253a27ee 100644 --- a/data_sources/sysmon_eventid_12.yml +++ b/data_sources/sysmon_eventid_12.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 12 +separator_value: '12' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_13.yml b/data_sources/sysmon_eventid_13.yml index 9af2d0673d..fa07a786fd 100644 --- a/data_sources/sysmon_eventid_13.yml +++ b/data_sources/sysmon_eventid_13.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 13 +separator_value: '13' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_15.yml b/data_sources/sysmon_eventid_15.yml index e679fb1ad9..c819cb661e 100644 --- a/data_sources/sysmon_eventid_15.yml +++ b/data_sources/sysmon_eventid_15.yml @@ -14,7 +14,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 15 +separator_value: '15' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_17.yml b/data_sources/sysmon_eventid_17.yml index b871828540..efb671d8c5 100644 --- a/data_sources/sysmon_eventid_17.yml +++ b/data_sources/sysmon_eventid_17.yml @@ -9,7 +9,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 17 +separator_value: '17' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_18.yml b/data_sources/sysmon_eventid_18.yml index f3b7854c2f..8447f15541 100644 --- a/data_sources/sysmon_eventid_18.yml +++ b/data_sources/sysmon_eventid_18.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 18 +separator_value: '18' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_21.yml b/data_sources/sysmon_eventid_21.yml index 8caa81e1bc..7cc11830ee 100644 --- a/data_sources/sysmon_eventid_21.yml +++ b/data_sources/sysmon_eventid_21.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 21 +separator_value: '21' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_22.yml b/data_sources/sysmon_eventid_22.yml index bcd9721dd8..fffc3f518a 100644 --- a/data_sources/sysmon_eventid_22.yml +++ b/data_sources/sysmon_eventid_22.yml @@ -14,7 +14,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 22 +separator_value: '22' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_23.yml b/data_sources/sysmon_eventid_23.yml index 7dc515f54a..7e148df04e 100644 --- a/data_sources/sysmon_eventid_23.yml +++ b/data_sources/sysmon_eventid_23.yml @@ -14,7 +14,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 23 +separator_value: '23' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_3.yml b/data_sources/sysmon_eventid_3.yml index b548310e17..04af350bfd 100644 --- a/data_sources/sysmon_eventid_3.yml +++ b/data_sources/sysmon_eventid_3.yml @@ -14,7 +14,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 3 +separator_value: '3' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_5.yml b/data_sources/sysmon_eventid_5.yml index 946a3c0551..7b8abba8e9 100644 --- a/data_sources/sysmon_eventid_5.yml +++ b/data_sources/sysmon_eventid_5.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 5 +separator_value: '5' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_6.yml b/data_sources/sysmon_eventid_6.yml index c9d0d5d247..053de2de1d 100644 --- a/data_sources/sysmon_eventid_6.yml +++ b/data_sources/sysmon_eventid_6.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 6 +separator_value: '6' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_7.yml b/data_sources/sysmon_eventid_7.yml index 8c5dcd335e..8a67c2fab7 100644 --- a/data_sources/sysmon_eventid_7.yml +++ b/data_sources/sysmon_eventid_7.yml @@ -14,7 +14,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 7 +separator_value: '7' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_8.yml b/data_sources/sysmon_eventid_8.yml index bb8b3a983b..1ee7641643 100644 --- a/data_sources/sysmon_eventid_8.yml +++ b/data_sources/sysmon_eventid_8.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 8 +separator_value: '8' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_eventid_9.yml b/data_sources/sysmon_eventid_9.yml index ba5499ae5b..f73b040876 100644 --- a/data_sources/sysmon_eventid_9.yml +++ b/data_sources/sysmon_eventid_9.yml @@ -14,7 +14,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID -separator_value: 9 +separator_value: '9' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon diff --git a/data_sources/sysmon_for_linux_eventid_1.yml b/data_sources/sysmon_for_linux_eventid_1.yml index 2027f90431..d8a01f3d5d 100644 --- a/data_sources/sysmon_for_linux_eventid_1.yml +++ b/data_sources/sysmon_for_linux_eventid_1.yml @@ -14,7 +14,7 @@ mitre_components: source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux separator: EventID -separator_value: 1 +separator_value: '1' supported_TA: - name: Splunk Add-on for Sysmon for Linux url: https://splunkbase.splunk.com/app/6652 diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index a3dcec0bda..8f24d2587e 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Application sourcetype: XmlWinEventLog separator: EventCode -separator_value: 3000 +separator_value: '3000' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index cc9a329fac..eb570c28a9 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -14,7 +14,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational sourcetype: xmlwineventlog separator: EventCode -separator_value: 70 +separator_value: '70' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml index e6641f83f8..12ef5132b5 100644 --- a/data_sources/windows_event_log_capi2_81.yml +++ b/data_sources/windows_event_log_capi2_81.yml @@ -14,7 +14,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational sourcetype: xmlwineventlog separator: EventCode -separator_value: 81 +separator_value: '81' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml index edc911da2a..f3ba7e5eaa 100644 --- a/data_sources/windows_event_log_certificateservicesclient_1007.yml +++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml @@ -14,7 +14,7 @@ mitre_components: source: XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational sourcetype: XmlWinEventLog separator: EventCode -separator_value: 1007 +separator_value: '1007' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml index c1185da5d8..d24a5e359e 100644 --- a/data_sources/windows_event_log_defender_1121.yml +++ b/data_sources/windows_event_log_defender_1121.yml @@ -12,7 +12,7 @@ mitre_components: source: WinEventLog:Microsoft-Windows-Windows Defender/Operational sourcetype: xmlwineventlog separator: EventCode -separator_value: 1121 +separator_value: '1121' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml index 708c4a09aa..8c16ab4757 100644 --- a/data_sources/windows_event_log_defender_1122.yml +++ b/data_sources/windows_event_log_defender_1122.yml @@ -12,7 +12,7 @@ mitre_components: source: WinEventLog:Microsoft-Windows-Windows Defender/Operational sourcetype: xmlwineventlog separator: EventCode -separator_value: 1122 +separator_value: '1122' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml index 1e4fd843ff..41c76a99c0 100644 --- a/data_sources/windows_event_log_defender_1129.yml +++ b/data_sources/windows_event_log_defender_1129.yml @@ -12,7 +12,7 @@ mitre_components: source: WinEventLog:Microsoft-Windows-Windows Defender/Operational sourcetype: xmlwineventlog separator: EventCode -separator_value: 1129 +separator_value: '1129' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index a13491e365..46e5fea881 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -10,7 +10,7 @@ mitre_components: source: WinEventLog:Microsoft-Windows-PrintService/Admin sourcetype: WinEventLog separator: EventCode -separator_value: 316 +separator_value: '316' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index 2f1c1363e4..c989e88ce2 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -12,7 +12,7 @@ mitre_components: source: WinEventLog:Microsoft-Windows-PrintService/Admin sourcetype: WinEventLog separator: EventCode -separator_value: 808 +separator_value: '808' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index 17e1e81b90..c3352c16bd 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -11,7 +11,7 @@ mitre_components: source: WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational sourcetype: wineventlog separator: EventCode -separator_value: 1149 +separator_value: '1149' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index f926bde8c2..1034fc5e50 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -10,7 +10,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 1100 +separator_value: '1100' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index d66920335f..b6209e3136 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -11,7 +11,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 1102 +separator_value: '1102' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index 823b6f2dee..c27cbde9e8 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -11,7 +11,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4624 +separator_value: '4624' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml index 5fdd9b3c21..e37413ca43 100644 --- a/data_sources/windows_event_log_security_4625.yml +++ b/data_sources/windows_event_log_security_4625.yml @@ -10,7 +10,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4625 +separator_value: '4625' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml index 85b2053016..428fea6638 100644 --- a/data_sources/windows_event_log_security_4627.yml +++ b/data_sources/windows_event_log_security_4627.yml @@ -12,7 +12,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4627 +separator_value: '4627' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml index 41b1ea111d..204ee0a6ea 100644 --- a/data_sources/windows_event_log_security_4648.yml +++ b/data_sources/windows_event_log_security_4648.yml @@ -11,7 +11,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4648 +separator_value: '4648' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml index e7ab4e16cb..72241152a5 100644 --- a/data_sources/windows_event_log_security_4662.yml +++ b/data_sources/windows_event_log_security_4662.yml @@ -11,7 +11,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4662 +separator_value: '4662' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml index 0a9d7bc423..8464167492 100644 --- a/data_sources/windows_event_log_security_4663.yml +++ b/data_sources/windows_event_log_security_4663.yml @@ -11,7 +11,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4663 +separator_value: '4663' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index b56a07aae1..c4ae46c0f1 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -11,7 +11,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4672 +separator_value: '4672' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml index 11371fe6ff..16b11249c1 100644 --- a/data_sources/windows_event_log_security_4688.yml +++ b/data_sources/windows_event_log_security_4688.yml @@ -10,7 +10,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4688 +separator_value: '4688' configuration: Enabling Windows event log process command line logging via group policy object https://lantern.splunk.com/Security/Product_Tips/Enterprise_Security/Enabling_Windows_event_log_process_command_line_logging_via_group_policy_object supported_TA: diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml index 27406cada2..b8c7911455 100644 --- a/data_sources/windows_event_log_security_4698.yml +++ b/data_sources/windows_event_log_security_4698.yml @@ -10,7 +10,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4698 +separator_value: '4698' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml index dc83e20aa6..7f05064a8f 100644 --- a/data_sources/windows_event_log_security_4699.yml +++ b/data_sources/windows_event_log_security_4699.yml @@ -10,7 +10,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4699 +separator_value: '4699' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml index 972a05a8d9..16ea3afc90 100644 --- a/data_sources/windows_event_log_security_4703.yml +++ b/data_sources/windows_event_log_security_4703.yml @@ -10,7 +10,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4703 +separator_value: '4703' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml index 37a72cc312..6edde73b99 100644 --- a/data_sources/windows_event_log_security_4719.yml +++ b/data_sources/windows_event_log_security_4719.yml @@ -10,7 +10,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4719 +separator_value: '4719' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml index ddd763d21b..e6bca434f1 100644 --- a/data_sources/windows_event_log_security_4720.yml +++ b/data_sources/windows_event_log_security_4720.yml @@ -9,7 +9,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4720 +separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml index 133f957f91..ed2d278c99 100644 --- a/data_sources/windows_event_log_security_4724.yml +++ b/data_sources/windows_event_log_security_4724.yml @@ -10,7 +10,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4724 +separator_value: '4724' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml index 129eafcb4f..5b91ceeb40 100644 --- a/data_sources/windows_event_log_security_4725.yml +++ b/data_sources/windows_event_log_security_4725.yml @@ -9,7 +9,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4725 +separator_value: '4725' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml index 201285eee9..8ee6b298fd 100644 --- a/data_sources/windows_event_log_security_4726.yml +++ b/data_sources/windows_event_log_security_4726.yml @@ -9,7 +9,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4726 +separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml index 5cab030eb0..5f312c3965 100644 --- a/data_sources/windows_event_log_security_4732.yml +++ b/data_sources/windows_event_log_security_4732.yml @@ -10,7 +10,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4732 +separator_value: '4732' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml index 45a903eb05..b42d8f7fa2 100644 --- a/data_sources/windows_event_log_security_4738.yml +++ b/data_sources/windows_event_log_security_4738.yml @@ -10,7 +10,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4738 +separator_value: '4738' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml index 30b07c99ee..7fb6bdc459 100644 --- a/data_sources/windows_event_log_security_4739.yml +++ b/data_sources/windows_event_log_security_4739.yml @@ -11,7 +11,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4739 +separator_value: '4739' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml index 8729366be5..2caa69385e 100644 --- a/data_sources/windows_event_log_security_4741.yml +++ b/data_sources/windows_event_log_security_4741.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4741 +separator_value: '4741' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml index c391a51cfe..599f027991 100644 --- a/data_sources/windows_event_log_security_4768.yml +++ b/data_sources/windows_event_log_security_4768.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4768 +separator_value: '4768' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml index d8c0cf195b..518f49f8da 100644 --- a/data_sources/windows_event_log_security_4769.yml +++ b/data_sources/windows_event_log_security_4769.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4769 +separator_value: '4769' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml index 7b6e030b23..0e18ca2298 100644 --- a/data_sources/windows_event_log_security_4771.yml +++ b/data_sources/windows_event_log_security_4771.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4771 +separator_value: '4771' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml index 59ae2a4748..d6581e3afc 100644 --- a/data_sources/windows_event_log_security_4776.yml +++ b/data_sources/windows_event_log_security_4776.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4776 +separator_value: '4776' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index 2e6adff3c4..9daa1781ae 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4781 +separator_value: '4781' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml index 2340e3fb35..8d16e695d2 100644 --- a/data_sources/windows_event_log_security_4876.yml +++ b/data_sources/windows_event_log_security_4876.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4876 +separator_value: '4876' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml index bf7533d343..a38f31f8cc 100644 --- a/data_sources/windows_event_log_security_4886.yml +++ b/data_sources/windows_event_log_security_4886.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4886 +separator_value: '4886' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml index 0bac032d6b..4b8188cb5d 100644 --- a/data_sources/windows_event_log_security_4887.yml +++ b/data_sources/windows_event_log_security_4887.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 4887 +separator_value: '4887' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml index 1cc73e726e..048eaf46f7 100644 --- a/data_sources/windows_event_log_security_5136.yml +++ b/data_sources/windows_event_log_security_5136.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 5136 +separator_value: '5136' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index b7da687fc2..1aa19af1d7 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 5137 +separator_value: '5137' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index 537ad5db65..d8c6bd2297 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 5140 +separator_value: '5140' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml index cc5825f11b..d507ac5298 100644 --- a/data_sources/windows_event_log_security_5141.yml +++ b/data_sources/windows_event_log_security_5141.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 5141 +separator_value: '5141' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index aadb0c15ea..5346b703d7 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode -separator_value: 5145 +separator_value: '5145' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml index de3cea6a37..e5a0d75f83 100644 --- a/data_sources/windows_event_log_system_4720.yml +++ b/data_sources/windows_event_log_system_4720.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode -separator_value: 4720 +separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml index 2a4c9d93e3..b76450a928 100644 --- a/data_sources/windows_event_log_system_4726.yml +++ b/data_sources/windows_event_log_system_4726.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode -separator_value: 4726 +separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml index bf93ff45f0..b7d5ada0c2 100644 --- a/data_sources/windows_event_log_system_4728.yml +++ b/data_sources/windows_event_log_system_4728.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode -separator_value: 4728 +separator_value: '4728' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml index 2d84bd44d8..c5eade1a31 100644 --- a/data_sources/windows_event_log_system_7036.yml +++ b/data_sources/windows_event_log_system_7036.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode -separator_value: 7036 +separator_value: '7036' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index 0f26b121a0..8c17c4cec7 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode -separator_value: 7040 +separator_value: '7040' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index 87c78b1a51..e019802f0c 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -13,7 +13,7 @@ mitre_components: source: XmlWinEventLog:System sourcetype: xmlwineventlog separator: EventCode -separator_value: 7045 +separator_value: '7045' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index 2348f6b3f8..16cec6a1f0 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -13,7 +13,7 @@ mitre_components: source: WinEventLog:Microsoft-Windows-TaskScheduler/Operational sourcetype: wineventlog separator: EventCode -separator_value: 200 +separator_value: '200' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml index 9ab6d3794a..7eeb8eeb79 100644 --- a/data_sources/windows_iis_29.yml +++ b/data_sources/windows_iis_29.yml @@ -13,7 +13,7 @@ mitre_components: source: IIS:Configuration:Operational sourcetype: IIS:Configuration:Operational separator: EventID -separator_value: 29 +separator_value: '29' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 From 5e0d59e186c213c393e13a6b610deb328b1fae7a Mon Sep 17 00:00:00 2001 From: Eric Date: Tue, 18 Mar 2025 12:07:47 -0700 Subject: [PATCH 60/67] bump version in prep for release and so that deprecation stuff works properly. --- contentctl.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/contentctl.yml b/contentctl.yml index 0fcd575b4a..0fec06f9bf 100644 --- a/contentctl.yml +++ b/contentctl.yml @@ -3,7 +3,7 @@ app: uid: 3449 title: ES Content Updates appid: DA-ESS-ContentUpdate - version: 5.1.1 + version: 5.2.0 description: Explore the Analytic Stories included with ES Content Updates. prefix: ESCU label: ESCU From ad55d26fe4ce165475fe3f8f368c8930223970ce Mon Sep 17 00:00:00 2001 From: Eric Date: Tue, 18 Mar 2025 12:33:06 -0700 Subject: [PATCH 61/67] add 'status: removed' instead of 'status: deprecated' to removed detections --- .../add_prohibited_processes_to_enterprise_security.yml | 2 +- deprecated/baselines/baseline_of_api_calls_per_user_arn.yml | 2 +- ...eline_of_excessive_aws_instances_launched_by_user___mltk.yml | 2 +- ...ine_of_excessive_aws_instances_terminated_by_user___mltk.yml | 2 +- deprecated/baselines/monitor_successful_backups.yml | 2 +- deprecated/baselines/monitor_unsuccessful_backups.yml | 2 +- .../previously_seen_api_call_per_user_roles_in_cloudtrail.yml | 2 +- .../previously_seen_aws_provisioning_activity_sources.yml | 2 +- deprecated/baselines/previously_seen_aws_regions.yml | 2 +- deprecated/baselines/previously_seen_ec2_amis.yml | 2 +- deprecated/baselines/previously_seen_ec2_instance_types.yml | 2 +- deprecated/baselines/previously_seen_ec2_launches_by_user.yml | 2 +- .../baselines/previously_seen_ec2_modifications_by_user.yml | 2 +- deprecated/baselines/previously_seen_users_in_cloudtrail.yml | 2 +- .../systems_ready_for_spectre_meltdown_windows_patch.yml | 2 +- .../baselines/update_previously_seen_users_in_cloudtrail.yml | 2 +- .../abnormally_high_aws_instances_launched_by_user.yml | 2 +- .../abnormally_high_aws_instances_launched_by_user___mltk.yml | 2 +- .../abnormally_high_aws_instances_terminated_by_user.yml | 2 +- .../abnormally_high_aws_instances_terminated_by_user___mltk.yml | 2 +- deprecated/detections/account_discovery_with_net_app.yml | 2 +- deprecated/detections/asl_aws_createaccesskey.yml | 2 +- deprecated/detections/asl_aws_excessive_security_scanning.yml | 2 +- deprecated/detections/asl_aws_password_policy_changes.yml | 2 +- deprecated/detections/attempt_to_stop_security_service.yml | 2 +- .../attempted_credential_dump_from_registry_via_reg_exe.yml | 2 +- .../aws_cloud_provisioning_from_previously_unseen_city.yml | 2 +- .../aws_cloud_provisioning_from_previously_unseen_country.yml | 2 +- ...aws_cloud_provisioning_from_previously_unseen_ip_address.yml | 2 +- .../aws_cloud_provisioning_from_previously_unseen_region.yml | 2 +- .../aws_eks_kubernetes_cluster_sensitive_object_access.yml | 2 +- deprecated/detections/change_default_file_association.yml | 2 +- .../detections/clients_connecting_to_multiple_dns_servers.yml | 2 +- .../detections/cloud_network_access_control_list_deleted.yml | 2 +- .../detections/cmdline_tool_not_executed_in_cmd_shell.yml | 2 +- deprecated/detections/correlation_by_repository_and_risk.yml | 2 +- deprecated/detections/correlation_by_user_and_risk.yml | 2 +- .../detections/create_local_admin_accounts_using_net_exe.yml | 2 +- deprecated/detections/deleting_of_net_users.yml | 2 +- .../detect_activity_related_to_pass_the_hash_attacks.yml | 2 +- .../detections/detect_api_activity_from_users_without_mfa.yml | 2 +- .../detect_aws_api_activities_from_unapproved_accounts.yml | 2 +- .../detections/detect_critical_alerts_from_security_tools.yml | 2 +- ...tect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml | 2 +- deprecated/detections/detect_long_dns_txt_record_response.yml | 2 +- deprecated/detections/detect_mimikatz_using_loaded_images.yml | 2 +- .../detect_mimikatz_via_powershell_and_eventcode_4703.yml | 2 +- deprecated/detections/detect_new_api_calls_from_user_roles.yml | 2 +- deprecated/detections/detect_new_user_aws_console_login.yml | 2 +- ...rocesses_used_for_system_network_configuration_discovery.yml | 2 +- deprecated/detections/detect_spike_in_aws_api_activity.yml | 2 +- deprecated/detections/detect_spike_in_network_acl_activity.yml | 2 +- .../detections/detect_spike_in_security_group_activity.yml | 2 +- deprecated/detections/detect_usb_device_insertion.yml | 2 +- .../detect_web_traffic_to_dynamic_domain_providers.yml | 2 +- deprecated/detections/detect_webshell_exploit_behavior.yml | 2 +- deprecated/detections/detection_of_dns_tunnels.yml | 2 +- deprecated/detections/disabling_net_user_account.yml | 2 +- .../dns_query_requests_resolved_by_unauthorized_dns_servers.yml | 2 +- deprecated/detections/dns_record_changed.yml | 2 +- deprecated/detections/domain_account_discovery_with_net_app.yml | 2 +- deprecated/detections/domain_group_discovery_with_net.yml | 2 +- deprecated/detections/dump_lsass_via_procdump_rename.yml | 2 +- .../ec2_instance_modified_with_previously_unseen_user.yml | 2 +- .../ec2_instance_started_in_previously_unseen_region.yml | 2 +- .../ec2_instance_started_with_previously_unseen_ami.yml | 2 +- ...c2_instance_started_with_previously_unseen_instance_type.yml | 2 +- .../ec2_instance_started_with_previously_unseen_user.yml | 2 +- deprecated/detections/elevated_group_discovery_with_net.yml | 2 +- deprecated/detections/excel_spawning_powershell.yml | 2 +- deprecated/detections/excel_spawning_windows_script_host.yml | 2 +- deprecated/detections/excessive_service_stop_attempt.yml | 2 +- deprecated/detections/excessive_usage_of_net_app.yml | 2 +- .../execution_of_file_with_spaces_before_extension.yml | 2 +- .../extended_period_without_successful_netbackup_backups.yml | 2 +- deprecated/detections/extraction_of_registry_hives.yml | 2 +- deprecated/detections/first_time_seen_command_line_argument.yml | 2 +- .../gcp_detect_accounts_with_high_risk_roles_by_project.yml | 2 +- ...gcp_detect_high_risk_permissions_by_resource_and_account.yml | 2 +- deprecated/detections/gcp_detect_oauth_token_abuse.yml | 2 +- deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml | 2 +- deprecated/detections/identify_new_user_accounts.yml | 2 +- ...ubernetes_aws_detect_most_active_service_accounts_by_pod.yml | 2 +- .../kubernetes_aws_detect_rbac_authorization_by_account.yml | 2 +- .../detections/kubernetes_aws_detect_sensitive_role_access.yml | 2 +- ...tes_aws_detect_service_accounts_forbidden_failure_access.yml | 2 +- ...ubernetes_azure_active_service_accounts_by_pod_namespace.yml | 2 +- .../kubernetes_azure_detect_rbac_authorization_by_account.yml | 2 +- .../kubernetes_azure_detect_sensitive_object_access.yml | 2 +- .../kubernetes_azure_detect_sensitive_role_access.yml | 2 +- ...s_azure_detect_service_accounts_forbidden_failure_access.yml | 2 +- .../kubernetes_azure_detect_suspicious_kubectl_calls.yml | 2 +- deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml | 2 +- deprecated/detections/kubernetes_azure_scan_fingerprint.yml | 2 +- ...ubernetes_gcp_detect_most_active_service_accounts_by_pod.yml | 2 +- .../kubernetes_gcp_detect_rbac_authorizations_by_account.yml | 2 +- .../kubernetes_gcp_detect_sensitive_object_access.yml | 2 +- .../detections/kubernetes_gcp_detect_sensitive_role_access.yml | 2 +- ...tes_gcp_detect_service_accounts_forbidden_failure_access.yml | 2 +- .../kubernetes_gcp_detect_suspicious_kubectl_calls.yml | 2 +- deprecated/detections/linux_auditd_find_private_keys.yml | 2 +- deprecated/detections/local_account_discovery_with_net.yml | 2 +- deprecated/detections/monitor_dns_for_brand_abuse.yml | 2 +- deprecated/detections/mshtml_module_load_in_office_product.yml | 2 +- ...ple_okta_users_with_invalid_credentials_from_the_same_ip.yml | 2 +- deprecated/detections/net_localgroup_discovery.yml | 2 +- deprecated/detections/network_connection_discovery_with_net.yml | 2 +- .../detections/o365_suspicious_admin_email_forwarding.yml | 2 +- deprecated/detections/o365_suspicious_rights_delegation.yml | 2 +- deprecated/detections/o365_suspicious_user_email_forwarding.yml | 2 +- deprecated/detections/office_application_drop_executable.yml | 2 +- .../detections/office_application_spawn_regsvr32_process.yml | 2 +- .../detections/office_application_spawn_rundll32_process.yml | 2 +- .../detections/office_document_creating_schedule_task.yml | 2 +- deprecated/detections/office_document_executing_macro_code.yml | 2 +- .../office_document_spawned_child_process_to_download.yml | 2 +- deprecated/detections/office_product_spawn_cmd_process.yml | 2 +- deprecated/detections/office_product_spawning_bitsadmin.yml | 2 +- deprecated/detections/office_product_spawning_certutil.yml | 2 +- deprecated/detections/office_product_spawning_mshta.yml | 2 +- .../detections/office_product_spawning_rundll32_with_no_dll.yml | 2 +- .../detections/office_product_spawning_windows_script_host.yml | 2 +- deprecated/detections/office_product_spawning_wmic.yml | 2 +- deprecated/detections/office_product_writing_cab_or_inf.yml | 2 +- deprecated/detections/office_spawning_control.yml | 2 +- deprecated/detections/okta_account_locked_out.yml | 2 +- deprecated/detections/okta_account_lockout_events.yml | 2 +- deprecated/detections/okta_failed_sso_attempts.yml | 2 +- ...okta_threatinsight_login_failure_with_high_unknown_users.yml | 2 +- .../okta_threatinsight_suspected_passwordspray_attack.yml | 2 +- deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml | 2 +- deprecated/detections/osquery_pack___coldroot_detection.yml | 2 +- deprecated/detections/password_policy_discovery_with_net.yml | 2 +- deprecated/detections/processes_created_by_netsh.yml | 2 +- deprecated/detections/prohibited_software_on_endpoint.yml | 2 +- ...reg_exe_used_to_hide_files_directories_via_registry_keys.yml | 2 +- deprecated/detections/remote_registry_key_modifications.yml | 2 +- deprecated/detections/remote_system_discovery_with_net.yml | 2 +- .../detections/scheduled_tasks_used_in_badrabbit_ransomware.yml | 2 +- .../detections/spectre_and_meltdown_vulnerable_systems.yml | 2 +- .../detections/suspicious_changes_to_file_associations.yml | 2 +- deprecated/detections/suspicious_email___uba_anomaly.yml | 2 +- deprecated/detections/suspicious_file_write.yml | 2 +- .../detections/suspicious_powershell_command_line_arguments.yml | 2 +- deprecated/detections/suspicious_rundll32_rename.yml | 2 +- .../suspicious_writes_to_system_volume_information.yml | 2 +- deprecated/detections/uncommon_processes_on_endpoint.yml | 2 +- deprecated/detections/unsigned_image_loaded_by_lsass.yml | 2 +- deprecated/detections/unsuccessful_netbackup_backups.yml | 2 +- deprecated/detections/web_fraud___account_harvesting.yml | 2 +- deprecated/detections/web_fraud___anomalous_user_clickspeed.yml | 2 +- .../detections/web_fraud___password_sharing_across_accounts.yml | 2 +- .../detections/windows_command_shell_fetch_env_variables.yml | 2 +- .../detections/windows_connhost_exe_started_forcefully.yml | 2 +- .../detections/windows_dll_search_order_hijacking_hunt.yml | 2 +- deprecated/detections/windows_hosts_file_modification.yml | 2 +- deprecated/detections/windows_lateral_tool_transfer_remcom.yml | 2 +- deprecated/detections/windows_modify_registry_reg_restore.yml | 2 +- .../detections/windows_msiexec_with_network_connections.yml | 2 +- .../detections/windows_network_share_interaction_with_net.yml | 2 +- deprecated/detections/windows_office_product_spawning_msdt.yml | 2 +- deprecated/detections/windows_query_registry_reg_save.yml | 2 +- .../windows_service_stop_via_net__and_sc_application.yml | 2 +- .../windows_valid_account_with_never_expires_password.yml | 2 +- deprecated/detections/winword_spawning_cmd.yml | 2 +- deprecated/detections/winword_spawning_powershell.yml | 2 +- deprecated/detections/winword_spawning_windows_script_host.yml | 2 +- deprecated/investigations/all_backup_logs_for_host.yml | 2 +- .../investigations/amazon_eks_kubernetes_activity_by_src_ip.yml | 2 +- .../aws_investigate_security_hub_alerts_by_dest.yml | 2 +- .../aws_investigate_user_activities_by_accesskeyid.yml | 2 +- .../investigations/aws_investigate_user_activities_by_arn.yml | 2 +- deprecated/investigations/aws_network_acl_details_from_id.yml | 2 +- .../aws_network_interface_details_via_resourceid.yml | 2 +- .../investigations/aws_s3_bucket_details_via_bucketname.yml | 2 +- deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml | 2 +- deprecated/investigations/get_all_aws_activity_from_city.yml | 2 +- deprecated/investigations/get_all_aws_activity_from_country.yml | 2 +- .../investigations/get_all_aws_activity_from_ip_address.yml | 2 +- deprecated/investigations/get_all_aws_activity_from_region.yml | 2 +- deprecated/investigations/get_backup_logs_for_endpoint.yml | 2 +- deprecated/investigations/get_certificate_logs_for_a_domain.yml | 2 +- deprecated/investigations/get_dns_server_history_for_a_host.yml | 2 +- deprecated/investigations/get_dns_traffic_ratio.yml | 2 +- .../investigations/get_ec2_instance_details_by_instanceid.yml | 2 +- deprecated/investigations/get_ec2_launch_details.yml | 2 +- deprecated/investigations/get_email_info.yml | 2 +- deprecated/investigations/get_emails_from_specific_sender.yml | 2 +- ...et_first_occurrence_and_last_occurrence_of_a_mac_address.yml | 2 +- deprecated/investigations/get_history_of_email_sources.yml | 2 +- .../get_logon_rights_modifications_for_endpoint.yml | 2 +- .../investigations/get_logon_rights_modifications_for_user.yml | 2 +- deprecated/investigations/get_notable_history.yml | 2 +- .../get_outbound_emails_to_hidden_cobra_threat_actors.yml | 2 +- deprecated/investigations/get_parent_process_info.yml | 2 +- deprecated/investigations/get_process_file_activity.yml | 2 +- deprecated/investigations/get_process_info.yml | 2 +- .../get_process_information_for_port_activity.yml | 2 +- .../get_process_responsible_for_the_dns_traffic.yml | 2 +- deprecated/investigations/get_sysmon_wmi_activity_for_host.yml | 2 +- .../get_web_session_information_via_session_id.yml | 2 +- .../investigate_aws_activities_via_region_name.yml | 2 +- .../investigate_aws_user_activities_by_user_field.yml | 2 +- .../investigate_failed_logins_for_multiple_destinations.yml | 2 +- .../investigations/investigate_network_traffic_from_src_ip.yml | 2 +- deprecated/investigations/investigate_okta_activity_by_app.yml | 2 +- .../investigations/investigate_okta_activity_by_ip_address.yml | 2 +- .../investigations/investigate_pass_the_hash_attempts.yml | 2 +- .../investigations/investigate_pass_the_ticket_attempts.yml | 2 +- deprecated/investigations/investigate_previous_unseen_user.yml | 2 +- .../investigate_successful_remote_desktop_authentications.yml | 2 +- .../investigate_suspicious_strings_in_http_header.yml | 2 +- .../investigations/investigate_user_activities_in_okta.yml | 2 +- deprecated/investigations/investigate_web_posts_from_src.yml | 2 +- deprecated/stories/aws_cryptomining.yml | 2 +- deprecated/stories/aws_suspicious_provisioning_activities.yml | 2 +- deprecated/stories/common_phishing_frameworks.yml | 2 +- .../container_implantation_monitoring_and_investigation.yml | 2 +- deprecated/stories/host_redirection.yml | 2 +- deprecated/stories/kubernetes_sensitive_role_activity.yml | 2 +- deprecated/stories/lateral_movement.yml | 2 +- deprecated/stories/monitor_backup_solution.yml | 2 +- deprecated/stories/monitor_for_unauthorized_software.yml | 2 +- deprecated/stories/office_365_detections.yml | 2 +- deprecated/stories/spectre_and_meltdown_vulnerabilities.yml | 2 +- deprecated/stories/suspicious_aws_ec2_activities.yml | 2 +- deprecated/stories/unusual_aws_ec2_modifications.yml | 2 +- deprecated/stories/web_fraud_detection.yml | 2 +- 228 files changed, 228 insertions(+), 228 deletions(-) diff --git a/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml b/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml index 607a5f9829..571031fc48 100644 --- a/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml +++ b/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-09-15' author: David Dorsey, Splunk type: Baseline -status: deprecated +status: removed description: This search takes the existing interesting process table from ES, filters out any existing additions added by ESCU and then updates the table with processes identified by ESCU that should be prohibited on your endpoints. diff --git a/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml b/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml index 461b657a67..2673563607 100644 --- a/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml +++ b/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-04-09' author: David Dorsey, Splunk type: Baseline -status: deprecated +status: removed description: This search establishes, on a per-hour basis, the average and the standard deviation of the number of API calls made by each user. Also recorded is the number of data points for each user. This table is then outputted to a lookup file to allow diff --git a/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml b/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml index ade1932593..f239369ff1 100644 --- a/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml +++ b/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-11-14' author: Jason Brewer, Splunk type: Baseline -status: deprecated +status: removed description: This search is used to build a Machine Learning Toolkit (MLTK) model for how many RunInstances users do in the environment. By default, the search uses the last 90 days of data to build the model. The model created by this search is diff --git a/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml b/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml index a6d890da08..66859b3998 100644 --- a/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml +++ b/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-11-14' author: Jason Brewer, Splunk type: Baseline -status: deprecated +status: removed description: This search is used to build a Machine Learning Toolkit (MLTK) model for how many TerminateInstances users do in the environment. By default, the search uses the last 90 days of data to build the model. The model created by this search diff --git a/deprecated/baselines/monitor_successful_backups.yml b/deprecated/baselines/monitor_successful_backups.yml index f178992d32..ab88e7b269 100644 --- a/deprecated/baselines/monitor_successful_backups.yml +++ b/deprecated/baselines/monitor_successful_backups.yml @@ -4,7 +4,7 @@ version: 2 date: '2025-02-27' author: David Dorsey, Splunk type: Baseline -status: deprecated +status: removed description: This search is intended to give you a feel for how often successful backups are conducted in your environment. Fluctuations in these numbers will allow you to determine when you should investigate. diff --git a/deprecated/baselines/monitor_unsuccessful_backups.yml b/deprecated/baselines/monitor_unsuccessful_backups.yml index bd694ee2b0..19c0d4ca73 100644 --- a/deprecated/baselines/monitor_unsuccessful_backups.yml +++ b/deprecated/baselines/monitor_unsuccessful_backups.yml @@ -4,7 +4,7 @@ version: 2 date: '2025-02-27' author: David Dorsey, Splunk type: Baseline -status: deprecated +status: removed description: This search is intended to give you a feel for how often backup failures happen in your environments. Fluctuations in these numbers will allow you to determine when you should investigate. diff --git a/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml b/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml index 71a860c70b..8725c77478 100644 --- a/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml +++ b/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-04-16' author: Bhavin Patel, Splunk type: Baseline -status: deprecated +status: removed description: This search looks for successful API calls made by different user roles, then creates a baseline of the earliest and latest times we have encountered this user role. It also returns the name of the API call in our dataset--grouped by user diff --git a/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml b/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml index b0c5e90290..96f8dccd31 100644 --- a/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml +++ b/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-03-16' author: David Dorsey, Splunk type: Baseline -status: deprecated +status: removed description: This search builds a table of the first and last times seen for every IP address (along with its physical location) previously associated with cloud-provisioning activity. This is broadly defined as any event that runs or creates something. diff --git a/deprecated/baselines/previously_seen_aws_regions.yml b/deprecated/baselines/previously_seen_aws_regions.yml index 24fd59423f..c64933b437 100644 --- a/deprecated/baselines/previously_seen_aws_regions.yml +++ b/deprecated/baselines/previously_seen_aws_regions.yml @@ -4,7 +4,7 @@ version: 2 date: '2025-02-27' author: Bhavin Patel, Splunk type: Baseline -status: deprecated +status: removed description: This search looks for CloudTrail events where an AWS instance is started and creates a baseline of most recent time (latest) and the first time (earliest) we've seen this region in our dataset grouped by the value awsRegion for the last diff --git a/deprecated/baselines/previously_seen_ec2_amis.yml b/deprecated/baselines/previously_seen_ec2_amis.yml index 1550cdf588..bc7c7ec00e 100644 --- a/deprecated/baselines/previously_seen_ec2_amis.yml +++ b/deprecated/baselines/previously_seen_ec2_amis.yml @@ -4,7 +4,7 @@ version: 2 date: '2025-01-16' author: David Dorsey, Splunk type: Baseline -status: deprecated +status: removed description: This search builds a table of previously seen AMIs used to launch EC2 instances search: '`cloudtrail` eventName=RunInstances errorCode=success | rename requestParameters.instancesSet.items{}.imageId diff --git a/deprecated/baselines/previously_seen_ec2_instance_types.yml b/deprecated/baselines/previously_seen_ec2_instance_types.yml index cfff4e6d58..4c1f2fa439 100644 --- a/deprecated/baselines/previously_seen_ec2_instance_types.yml +++ b/deprecated/baselines/previously_seen_ec2_instance_types.yml @@ -4,7 +4,7 @@ version: 2 date: '2025-01-16' author: David Dorsey, Splunk type: Baseline -status: deprecated +status: removed description: This search builds a table of previously seen EC2 instance types search: '`cloudtrail` eventName=RunInstances errorCode=success | rename requestParameters.instanceType as instanceType | fillnull value="m1.small" instanceType | stats earliest(_time) diff --git a/deprecated/baselines/previously_seen_ec2_launches_by_user.yml b/deprecated/baselines/previously_seen_ec2_launches_by_user.yml index d1aa8e8045..d90c9b44cc 100644 --- a/deprecated/baselines/previously_seen_ec2_launches_by_user.yml +++ b/deprecated/baselines/previously_seen_ec2_launches_by_user.yml @@ -4,7 +4,7 @@ version: 2 date: '2025-01-16' author: David Dorsey, Splunk type: Baseline -status: deprecated +status: removed description: This search builds a table of previously seen ARNs that have launched a EC2 instance. search: '`cloudtrail` eventName=RunInstances errorCode=success | rename userIdentity.arn diff --git a/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml b/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml index 426a1181ad..09a26dca86 100644 --- a/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml +++ b/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml @@ -4,7 +4,7 @@ version: 2 date: '2025-02-27' author: David Dorsey, Splunk type: Baseline -status: deprecated +status: removed description: This search builds a table of previously seen ARNs that have launched a EC2 instance. search: '`cloudtrail` `ec2_modification_api_calls` errorCode=success | spath output=arn diff --git a/deprecated/baselines/previously_seen_users_in_cloudtrail.yml b/deprecated/baselines/previously_seen_users_in_cloudtrail.yml index f8e40480d7..2e3a762c8d 100644 --- a/deprecated/baselines/previously_seen_users_in_cloudtrail.yml +++ b/deprecated/baselines/previously_seen_users_in_cloudtrail.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-04-30' author: Jason Brewer, Splunk type: Baseline -status: deprecated +status: removed description: This search looks for CloudTrail events where a user logs into the console, then creates a baseline of the latest and earliest times, City, Region, and Country we have encountered this user in our dataset, grouped by ARN, within the last 30 diff --git a/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml b/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml index 763652d0e0..54085fb1b2 100644 --- a/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml +++ b/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml @@ -4,7 +4,7 @@ version: 2 date: '2025-02-27' author: David Dorsey, Splunk type: Baseline -status: deprecated +status: removed description: Some AV applications can cause the Spectre/Meltdown patch for Windows not to install successfully. This registry key is supposed to be created by the AV engine when it has been patched to be able to handle the Windows patch. If this diff --git a/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml b/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml index 063ad93dcc..b12c1c002f 100644 --- a/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml +++ b/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml @@ -4,7 +4,7 @@ version: 2 date: '2025-01-16' author: Jason Brewer, Splunk type: Baseline -status: deprecated +status: removed description: This search looks for CloudTrail events where a user logs into the console, then updates the baseline of the latest and earliest times, City, Region, and Country we have encountered this user in our dataset, grouped by ARN, within the last hour. diff --git a/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml b/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml index e46dec6369..595bc299da 100644 --- a/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml +++ b/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml @@ -3,7 +3,7 @@ id: 2a9b80d3-6340-4345-b5ad-290bf5d0dac4 version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for AWS CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have diff --git a/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml b/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml index 9acc4411b2..d70e23808e 100644 --- a/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml +++ b/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml @@ -3,7 +3,7 @@ id: dec41ad5-d579-42cb-b4c6-f5dbb778bbe5 version: 5 date: '2024-11-14' author: Jason Brewer, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for AWS CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have diff --git a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml index ae3c15024b..7ce46aff25 100644 --- a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml +++ b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml @@ -3,7 +3,7 @@ id: 8d301246-fccf-45e2-a8e7-3655fd14379c version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for AWS CloudTrail events where an abnormally high number of instances were successfully terminated by a user in a 10-minute window. diff --git a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml index 04f88a704a..4581feda8f 100644 --- a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml +++ b/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml @@ -3,7 +3,7 @@ id: 1c02b86a-cd85-473e-a50b-014a9ac8fe3e version: 5 date: '2024-11-14' author: Jason Brewer, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for AWS CloudTrail events where a user successfully terminates an abnormally high number of instances. This search is deprecated and diff --git a/deprecated/detections/account_discovery_with_net_app.yml b/deprecated/detections/account_discovery_with_net_app.yml index 074b4fba7a..ddb1846f2e 100644 --- a/deprecated/detections/account_discovery_with_net_app.yml +++ b/deprecated/detections/account_discovery_with_net_app.yml @@ -3,7 +3,7 @@ id: 339805ce-ac30-11eb-b87d-acde48001122 version: 9 date: '2025-02-10' author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of the more generic "45e52536-ae42-11eb-b5c6-acde48001122". The following analytic detects potential diff --git a/deprecated/detections/asl_aws_createaccesskey.yml b/deprecated/detections/asl_aws_createaccesskey.yml index e7588388f6..a4fe172ca3 100644 --- a/deprecated/detections/asl_aws_createaccesskey.yml +++ b/deprecated/detections/asl_aws_createaccesskey.yml @@ -3,7 +3,7 @@ id: ccb3e4af-23d6-407f-9842-a26212816c9e version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk -status: deprecated +status: removed type: Hunting description: This detection rule monitors for the creation of AWS Identity and Access Management (IAM) access keys. An IAM access key consists of an access key ID and diff --git a/deprecated/detections/asl_aws_excessive_security_scanning.yml b/deprecated/detections/asl_aws_excessive_security_scanning.yml index 0ee3a463e3..6f8c8c2cf2 100644 --- a/deprecated/detections/asl_aws_excessive_security_scanning.yml +++ b/deprecated/detections/asl_aws_excessive_security_scanning.yml @@ -3,7 +3,7 @@ id: ff2bfdbc-65b7-4434-8f08-d55761d1d446 version: 4 date: '2024-11-14' author: Patrick Bareiss, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for AWS CloudTrail events and analyse the amount of eventNames which starts with Describe by a single user. This indicates that this diff --git a/deprecated/detections/asl_aws_password_policy_changes.yml b/deprecated/detections/asl_aws_password_policy_changes.yml index d791f17208..faa1c0ef93 100644 --- a/deprecated/detections/asl_aws_password_policy_changes.yml +++ b/deprecated/detections/asl_aws_password_policy_changes.yml @@ -3,7 +3,7 @@ id: 5ade5937-11a2-4363-ba6b-39a3ee8d5b1a version: 3 date: '2024-11-14' author: Patrick Bareiss, Splunk -status: deprecated +status: removed type: Hunting description: This search looks for AWS CloudTrail events from Amazon Security Lake where a user is making successful API calls to view/update/delete the existing password diff --git a/deprecated/detections/attempt_to_stop_security_service.yml b/deprecated/detections/attempt_to_stop_security_service.yml index 1964d9b110..0fca86d98e 100644 --- a/deprecated/detections/attempt_to_stop_security_service.yml +++ b/deprecated/detections/attempt_to_stop_security_service.yml @@ -3,7 +3,7 @@ id: c8e349c6-b97c-486e-8949-bd7bcd1f3910 version: 11 date: '2025-02-10' author: Rico Valdez, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects attempts to stop security-related services on an endpoint, which may indicate malicious diff --git a/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml b/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml index 65c188a991..5dfdbf1e49 100644 --- a/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -3,7 +3,7 @@ id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911 version: 14 date: '2025-02-10' author: Patrick Bareiss, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of "8bbb7d58-b360-11eb-ba21-acde48001122". The following analytic detects the execution of reg.exe with parameters that export diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml index 91a576d2f0..93e513cc2c 100644 --- a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml +++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml @@ -3,7 +3,7 @@ id: 344a1778-0b25-490c-adb1-de8beddf59cd version: 5 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for AWS provisioning activities from previously unseen cities. Provisioning activities are defined broadly as any event that begins with diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml index 986a31d1f0..5c7257858e 100644 --- a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml +++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml @@ -3,7 +3,7 @@ id: ceb8d3d8-06cb-49eb-beaf-829526e33ff0 version: 5 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for AWS provisioning activities from previously unseen countries. Provisioning activities are defined broadly as any event that begins diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml index 5568175da0..13a7f90294 100644 --- a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml @@ -3,7 +3,7 @@ id: 42e15012-ac14-4801-94f4-f1acbe64880b version: 5 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for AWS provisioning activities from previously unseen IP addresses. Provisioning activities are defined broadly as any event that begins diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml index 5efa68a449..039f1cd76c 100644 --- a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml +++ b/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml @@ -3,7 +3,7 @@ id: 7971d3df-da82-4648-a6e5-b5637bea5253 version: 4 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for AWS provisioning activities from previously unseen regions. Region in this context is similar to a state in the United States. Provisioning diff --git a/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml index 866bca7809..c337fae5d0 100644 --- a/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml +++ b/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml @@ -3,7 +3,7 @@ id: 7f227943-2196-4d4d-8d6a-ac8cb308e61c version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets diff --git a/deprecated/detections/change_default_file_association.yml b/deprecated/detections/change_default_file_association.yml index e5e583848a..3025b5adeb 100644 --- a/deprecated/detections/change_default_file_association.yml +++ b/deprecated/detections/change_default_file_association.yml @@ -3,7 +3,7 @@ id: 462d17d8-1f71-11ec-ad07-acde48001122 version: 6 date: '2025-02-10' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects suspicious registry modifications that change the default file association to execute diff --git a/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml b/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml index eb01c32ea2..d5371b4c99 100644 --- a/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml +++ b/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml @@ -3,7 +3,7 @@ id: 74ec6f18-604b-4202-a567-86b2066be3ce version: 6 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: TTP description: This search allows you to identify the endpoints that have connected to more than five DNS servers and made DNS Queries over the time frame of the search. diff --git a/deprecated/detections/cloud_network_access_control_list_deleted.yml b/deprecated/detections/cloud_network_access_control_list_deleted.yml index 8a9036b76a..bb84da3f50 100644 --- a/deprecated/detections/cloud_network_access_control_list_deleted.yml +++ b/deprecated/detections/cloud_network_access_control_list_deleted.yml @@ -3,7 +3,7 @@ id: 021abc51-1862-41dd-ad43-43c739c0a983 version: 4 date: '2024-11-14' author: Peter Gael, Splunk -status: deprecated +status: removed type: Anomaly description: Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker diff --git a/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml b/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml index 74087020ed..772d5444d8 100644 --- a/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml @@ -3,7 +3,7 @@ id: 6c3f7dd8-153c-11ec-ac2d-acde48001122 version: 9 date: '2025-02-10' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic identifies instances where `ipconfig.exe`, `systeminfo.exe`, or similar tools are executed by a non-standard parent process, excluding CMD, PowerShell, diff --git a/deprecated/detections/correlation_by_repository_and_risk.yml b/deprecated/detections/correlation_by_repository_and_risk.yml index 681f046bf4..a3e5fea3e7 100644 --- a/deprecated/detections/correlation_by_repository_and_risk.yml +++ b/deprecated/detections/correlation_by_repository_and_risk.yml @@ -3,7 +3,7 @@ id: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687 version: 4 date: '2025-02-10' author: Patrick Bareiss, Splunk -status: deprecated +status: removed type: Correlation description: |- This search has been deprecated and updated with Risk Rule for Dev Sec Ops by Repository detection. The following analytic detects by correlating repository and risk score to identify patterns and trends in the data based on the level of risk associated. The analytic adds any null values and calculates the sum of the risk scores for each detection. Then, the analytic captures the source and user information for each detection and sorts the results in ascending order based on the risk score. Finally, the analytic filters the detections with a risk score below 80 and focuses only on high-risk detections.This detection is important because it provides valuable insights into the distribution of high-risk activities across different repositories. It also identifies the most vulnerable repositories that are frequently targeted by potential threats. Additionally, it proactively detects and responds to potential threats, thereby minimizing the impact of attacks and safeguarding critical assets. Finally, it provides a comprehensive view of the risk landscape and helps to make informed decisions to protect the organization's data and infrastructure. False positives might occur so it is important to identify the impact of the attack and prioritize response and mitigation efforts. diff --git a/deprecated/detections/correlation_by_user_and_risk.yml b/deprecated/detections/correlation_by_user_and_risk.yml index d121453be9..95a4e50e10 100644 --- a/deprecated/detections/correlation_by_user_and_risk.yml +++ b/deprecated/detections/correlation_by_user_and_risk.yml @@ -3,7 +3,7 @@ id: 610e12dc-b6fa-4541-825e-4a0b3b6f6773 version: 4 date: '2025-02-10' author: Patrick Bareiss, Splunk -status: deprecated +status: removed type: Correlation description: |- The following analytic detects the correlation between the user and risk score and identifies users with a high risk score that pose a significant security risk such as unauthorized access attempts, suspicious behavior, or potential insider threats. Next, the analytic calculates the sum of the risk scores and groups the results by user, the corresponding signals, and the repository. The results are sorted in descending order based on the risk score and filtered to include records with a risk score greater than 80. Finally, the results are passed through a correlation filter specific to the user and risk. This detection is important because it identifies users who have a high risk score and helps to prioritize investigations and allocate resources. False positives might occur but the impact of such an attack can vary depending on the specific scenario such as data exfiltration, system compromise, or the disruption of critical services. Please investigate this notable event. diff --git a/deprecated/detections/create_local_admin_accounts_using_net_exe.yml b/deprecated/detections/create_local_admin_accounts_using_net_exe.yml index 05bd612ba3..5534cdc2d0 100644 --- a/deprecated/detections/create_local_admin_accounts_using_net_exe.yml +++ b/deprecated/detections/create_local_admin_accounts_using_net_exe.yml @@ -3,7 +3,7 @@ id: b89919ed-fe5f-492c-b139-151bb162040e version: 17 date: '2025-02-10' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects the creation of local administrator accounts using the net.exe command. It leverages diff --git a/deprecated/detections/deleting_of_net_users.yml b/deprecated/detections/deleting_of_net_users.yml index 379264584f..48c661fd73 100644 --- a/deprecated/detections/deleting_of_net_users.yml +++ b/deprecated/detections/deleting_of_net_users.yml @@ -3,7 +3,7 @@ id: 1c8c6f66-acce-11eb-aafb-acde48001122 version: 8 date: '2025-01-24' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects the use of net.exe or net1.exe command-line diff --git a/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml b/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml index 9b6c9aec2c..c57b95da42 100644 --- a/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml @@ -3,7 +3,7 @@ id: f5939373-8054-40ad-8c64-cec478a22a4b version: 10 date: '2025-02-10' author: Bhavin Patel, Patrick Bareiss, Splunk -status: deprecated +status: removed type: Hunting description: This search looks for specific authentication events from the Windows Security Event logs to detect potential attempts at using the Pass-the-Hash technique. diff --git a/deprecated/detections/detect_api_activity_from_users_without_mfa.yml b/deprecated/detections/detect_api_activity_from_users_without_mfa.yml index e0ad2efcfc..f7da7f035d 100644 --- a/deprecated/detections/detect_api_activity_from_users_without_mfa.yml +++ b/deprecated/detections/detect_api_activity_from_users_without_mfa.yml @@ -3,7 +3,7 @@ id: 4d46e8bd-4072-48e4-92db-0325889ef894 version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Hunting description: This search looks for AWS CloudTrail events where a user logged into the AWS account, is making API calls and has not enabled Multi Factor authentication. diff --git a/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml b/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml index 23e833aac1..98b40ed434 100644 --- a/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml +++ b/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml @@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a3f1-d82362d4bd55 version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Hunting description: This search looks for successful AWS CloudTrail activity by user accounts that are not listed in the identity table or `aws_service_accounts.csv`. It returns diff --git a/deprecated/detections/detect_critical_alerts_from_security_tools.yml b/deprecated/detections/detect_critical_alerts_from_security_tools.yml index 79ba56809d..a1bdeec87e 100644 --- a/deprecated/detections/detect_critical_alerts_from_security_tools.yml +++ b/deprecated/detections/detect_critical_alerts_from_security_tools.yml @@ -3,7 +3,7 @@ id: 483e8a68-f2f7-45be-8fc9-bf725f0e22fd version: 2 date: '2025-01-13' author: Gowthamaraj Rajendran, Patrick Bareiss, Bhavin Patel, Bryan Pluta, Splunk -status: deprecated +status: removed type: TTP data_source: - Windows Defender Alerts diff --git a/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml index 2d4975f3ec..05a6f77ef4 100644 --- a/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml +++ b/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml @@ -3,7 +3,7 @@ id: 24dd17b1-e2fb-4c31-878c-d4f226595bfa version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: TTP description: This search looks for DNS requests for phishing domains that are leveraging EvilGinx tools to mimic websites. diff --git a/deprecated/detections/detect_long_dns_txt_record_response.yml b/deprecated/detections/detect_long_dns_txt_record_response.yml index 57a2fb80be..1329c3bf26 100644 --- a/deprecated/detections/detect_long_dns_txt_record_response.yml +++ b/deprecated/detections/detect_long_dns_txt_record_response.yml @@ -3,7 +3,7 @@ id: 05437c07-62f5-452e-afdc-04dd44815bb9 version: 5 date: '2024-11-14' author: Rico Valdez, Splunk -status: deprecated +status: removed type: TTP description: This search is used to detect attempts to use DNS tunneling, by calculating the length of responses to DNS TXT queries. Endpoints using DNS as a method of transmission diff --git a/deprecated/detections/detect_mimikatz_using_loaded_images.yml b/deprecated/detections/detect_mimikatz_using_loaded_images.yml index 75e66c0061..6fbe7ff5e7 100644 --- a/deprecated/detections/detect_mimikatz_using_loaded_images.yml +++ b/deprecated/detections/detect_mimikatz_using_loaded_images.yml @@ -3,7 +3,7 @@ id: 29e307ba-40af-4ab2-91b2-3c6b392bbba0 version: 4 date: '2025-02-10' author: Patrick Bareiss, Splunk -status: deprecated +status: removed type: TTP description: This search looks for reading loaded Images unique to credential dumping with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon diff --git a/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml index aa9cabe8d3..a97cc408bb 100644 --- a/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml +++ b/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml @@ -3,7 +3,7 @@ id: 98917be2-bfc8-475a-8618-a9bb06575188 version: 5 date: '2024-11-14' author: Rico Valdez, Splunk -status: deprecated +status: removed type: TTP description: This search looks for PowerShell requesting privileges consistent with credential dumping. Deprecated, looks like things changed from a logging perspective. diff --git a/deprecated/detections/detect_new_api_calls_from_user_roles.yml b/deprecated/detections/detect_new_api_calls_from_user_roles.yml index 5ed0943c52..6875898fc1 100644 --- a/deprecated/detections/detect_new_api_calls_from_user_roles.yml +++ b/deprecated/detections/detect_new_api_calls_from_user_roles.yml @@ -3,7 +3,7 @@ id: 22773e84-bac0-4595-b086-20d3f335b4f1 version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Anomaly description: This search detects new API calls that have either never been seen before or that have not been seen in the previous hour, where the identity type is `AssumedRole`. diff --git a/deprecated/detections/detect_new_user_aws_console_login.yml b/deprecated/detections/detect_new_user_aws_console_login.yml index 1713d3b52d..75f7756e52 100644 --- a/deprecated/detections/detect_new_user_aws_console_login.yml +++ b/deprecated/detections/detect_new_user_aws_console_login.yml @@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a3f3-d82362dffd75 version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Hunting description: This search looks for AWS CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup diff --git a/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml b/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml index d0851935d2..e46c595fe9 100644 --- a/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml +++ b/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml @@ -3,7 +3,7 @@ id: a51bfe1a-94f0-48cc-b1e4-16ae10145893 version: 8 date: '2025-01-24' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic identifies the rapid execution of processes used diff --git a/deprecated/detections/detect_spike_in_aws_api_activity.yml b/deprecated/detections/detect_spike_in_aws_api_activity.yml index 5a7efe7007..97feb48d8b 100644 --- a/deprecated/detections/detect_spike_in_aws_api_activity.yml +++ b/deprecated/detections/detect_spike_in_aws_api_activity.yml @@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a3f1-d32362d4bd55 version: 5 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: Anomaly description: This search will detect users creating spikes of API activity in your AWS environment. It will also update the cache file that factors in the latest diff --git a/deprecated/detections/detect_spike_in_network_acl_activity.yml b/deprecated/detections/detect_spike_in_network_acl_activity.yml index a7e693bf9e..fa43ca2e7d 100644 --- a/deprecated/detections/detect_spike_in_network_acl_activity.yml +++ b/deprecated/detections/detect_spike_in_network_acl_activity.yml @@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a1f1-e32372d4bd53 version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Anomaly description: This search will detect users creating spikes in API activity related to network access-control lists (ACLs)in your AWS environment. This search is deprecated diff --git a/deprecated/detections/detect_spike_in_security_group_activity.yml b/deprecated/detections/detect_spike_in_security_group_activity.yml index de1cad3b6d..a6c75ede25 100644 --- a/deprecated/detections/detect_spike_in_security_group_activity.yml +++ b/deprecated/detections/detect_spike_in_security_group_activity.yml @@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a3f1-e32372d4bd53 version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Anomaly description: This search will detect users creating spikes in API activity related to security groups in your AWS environment. It will also update the cache file diff --git a/deprecated/detections/detect_usb_device_insertion.yml b/deprecated/detections/detect_usb_device_insertion.yml index 2d6dd088f5..98ea80b3e0 100644 --- a/deprecated/detections/detect_usb_device_insertion.yml +++ b/deprecated/detections/detect_usb_device_insertion.yml @@ -3,7 +3,7 @@ id: 104658f4-afdc-499f-9719-17a43f9826f5 version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: TTP description: The search is used to detect hosts that generate Windows Event ID 4663 for successful attempts to write to or read from a removable storage and Event ID diff --git a/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml b/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml index deadd5d14b..7b61741b56 100644 --- a/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml +++ b/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml @@ -3,7 +3,7 @@ id: 134da869-e264-4a8f-8d7e-fcd01c18f301 version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: TTP description: This search looks for web connections to dynamic DNS providers. data_source: [] diff --git a/deprecated/detections/detect_webshell_exploit_behavior.yml b/deprecated/detections/detect_webshell_exploit_behavior.yml index a460946a1a..679f7cfd64 100644 --- a/deprecated/detections/detect_webshell_exploit_behavior.yml +++ b/deprecated/detections/detect_webshell_exploit_behavior.yml @@ -3,7 +3,7 @@ id: 22597426-6dbd-49bd-bcdc-4ec19857192f version: 8 date: '2025-02-10' author: Steven Dick -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic identifies the execution of suspicious processes typically associated with webshell activity diff --git a/deprecated/detections/detection_of_dns_tunnels.yml b/deprecated/detections/detection_of_dns_tunnels.yml index e903bf4d9a..cabfa19b64 100644 --- a/deprecated/detections/detection_of_dns_tunnels.yml +++ b/deprecated/detections/detection_of_dns_tunnels.yml @@ -3,7 +3,7 @@ id: 104658f4-afdc-499f-9719-17a43f9826f4 version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: TTP description: "This search is used to detect DNS tunneling, by calculating the sum of the length of DNS queries and DNS answers. The search also filters out potential diff --git a/deprecated/detections/disabling_net_user_account.yml b/deprecated/detections/disabling_net_user_account.yml index 409e89854a..56936042e3 100644 --- a/deprecated/detections/disabling_net_user_account.yml +++ b/deprecated/detections/disabling_net_user_account.yml @@ -3,7 +3,7 @@ id: c0325326-acd6-11eb-98c2-acde48001122 version: 8 date: '2025-01-24' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects the use of the `net.exe` utility to disable diff --git a/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml index b52f87457a..680f232852 100644 --- a/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml +++ b/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml @@ -3,7 +3,7 @@ id: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f6 version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: TTP description: This search will detect DNS requests resolved by unauthorized DNS servers. Legitimate DNS servers should be identified in the Enterprise Security Assets and diff --git a/deprecated/detections/dns_record_changed.yml b/deprecated/detections/dns_record_changed.yml index 1da12999ba..d620468bcf 100644 --- a/deprecated/detections/dns_record_changed.yml +++ b/deprecated/detections/dns_record_changed.yml @@ -3,7 +3,7 @@ id: 44d3a43e-dcd5-49f7-8356-5209bb369065 version: 6 date: '2024-11-14' author: Jose Hernandez, Splunk -status: deprecated +status: removed type: TTP description: The search takes the DNS records and their answers results of the discovered_dns_records lookup and finds if any records have changed by searching DNS response from the diff --git a/deprecated/detections/domain_account_discovery_with_net_app.yml b/deprecated/detections/domain_account_discovery_with_net_app.yml index a1518a4c1f..98dfe89c93 100644 --- a/deprecated/detections/domain_account_discovery_with_net_app.yml +++ b/deprecated/detections/domain_account_discovery_with_net_app.yml @@ -3,7 +3,7 @@ id: 98f6a534-04c2-11ec-96b2-acde48001122 version: 6 date: '2025-02-10' author: Teoderick Contreras, Mauricio Velazco, Splunk -status: deprecated +status: removed type: TTP description: This following analytic has been deprecated in favour of the generic version "5d0d4830-0133-11ec-bae3-acde48001122". The following analytic detects the diff --git a/deprecated/detections/domain_group_discovery_with_net.yml b/deprecated/detections/domain_group_discovery_with_net.yml index 928dec10e8..cdb1b85e11 100644 --- a/deprecated/detections/domain_group_discovery_with_net.yml +++ b/deprecated/detections/domain_group_discovery_with_net.yml @@ -3,7 +3,7 @@ id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349 version: 7 date: '2025-02-10' author: Mauricio Velazco, Splunk -status: deprecated +status: removed type: Hunting description: This search has been deprecated in favour of the more generic analytic "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic identifies the execution diff --git a/deprecated/detections/dump_lsass_via_procdump_rename.yml b/deprecated/detections/dump_lsass_via_procdump_rename.yml index db67928fa4..646606d2fa 100644 --- a/deprecated/detections/dump_lsass_via_procdump_rename.yml +++ b/deprecated/detections/dump_lsass_via_procdump_rename.yml @@ -3,7 +3,7 @@ id: 21276daa-663d-11eb-ae93-0242ac130002 version: 4 date: '2024-11-14' author: Michael Haag, Splunk -status: deprecated +status: removed type: Hunting description: "Detect a renamed instance of procdump.exe dumping the lsass process. This query looks for both -mm and -ma usage. -mm will produce a mini dump file and diff --git a/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml b/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml index c0dddee3ca..c41e9ef0f2 100644 --- a/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml +++ b/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml @@ -3,7 +3,7 @@ id: 56f91724-cf3f-4666-84e1-e3712fb41e76 version: 6 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for EC2 instances being modified by users who have not previously modified them. This search is deprecated and have been translated diff --git a/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml b/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml index 0d7e62b234..0ddc56e39b 100644 --- a/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml +++ b/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml @@ -3,7 +3,7 @@ id: ada0f478-84a8-4641-a3f3-d82362d6fd75 version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Hunting description: This search looks for AWS CloudTrail events where an instance is started in a particular region in the last one hour and then compares it to a lookup file diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml index 80a929eefb..a801015f2d 100644 --- a/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml +++ b/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml @@ -3,7 +3,7 @@ id: 347ec301-601b-48b9-81aa-9ddf9c829dd3 version: 5 date: '2025-01-16' author: David Dorsey, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for EC2 instances being created with previously unseen AMIs. This search is deprecated and have been translated to use the latest Change diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml index e1a95404a0..1f549688bd 100644 --- a/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml +++ b/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml @@ -3,7 +3,7 @@ id: 65541c80-03c7-4e05-83c8-1dcd57a2e1ad version: 6 date: '2025-01-16' author: David Dorsey, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for EC2 instances being created with previously unseen instance types. This search is deprecated and have been translated to use the latest diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml b/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml index d43786da55..e2b75f6b5d 100644 --- a/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml +++ b/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml @@ -3,7 +3,7 @@ id: 22773e84-bac0-4595-b086-20d3f735b4f1 version: 6 date: '2025-01-16' author: David Dorsey, Splunk -status: deprecated +status: removed type: Anomaly description: This search looks for EC2 instances being created by users who have not created them before. This search is deprecated and have been translated to use the diff --git a/deprecated/detections/elevated_group_discovery_with_net.yml b/deprecated/detections/elevated_group_discovery_with_net.yml index a941649159..d2239f33b0 100644 --- a/deprecated/detections/elevated_group_discovery_with_net.yml +++ b/deprecated/detections/elevated_group_discovery_with_net.yml @@ -3,7 +3,7 @@ id: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a version: 7 date: '2025-02-10' author: Mauricio Velazco, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects the execution of `net.exe` or `net1.exe` with command-line arguments used to query diff --git a/deprecated/detections/excel_spawning_powershell.yml b/deprecated/detections/excel_spawning_powershell.yml index 764de86234..10332d5d80 100644 --- a/deprecated/detections/excel_spawning_powershell.yml +++ b/deprecated/detections/excel_spawning_powershell.yml @@ -3,7 +3,7 @@ id: 42d40a22-9be3-11eb-8f08-acde48001122 version: 9 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/deprecated/detections/excel_spawning_windows_script_host.yml b/deprecated/detections/excel_spawning_windows_script_host.yml index 40deb89c49..404e72e788 100644 --- a/deprecated/detections/excel_spawning_windows_script_host.yml +++ b/deprecated/detections/excel_spawning_windows_script_host.yml @@ -3,7 +3,7 @@ id: 57fe880a-9be3-11eb-9bf3-acde48001122 version: 10 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach. The following analytic identifies instances where Microsoft Excel spawns diff --git a/deprecated/detections/excessive_service_stop_attempt.yml b/deprecated/detections/excessive_service_stop_attempt.yml index 3e27dc456b..c1d3ad9f3c 100644 --- a/deprecated/detections/excessive_service_stop_attempt.yml +++ b/deprecated/detections/excessive_service_stop_attempt.yml @@ -3,7 +3,7 @@ id: ae8d3f4a-acd7-11eb-8846-acde48001122 version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: Anomaly description: The following analytic has been deprecated. The following analytic detects multiple attempts to stop or delete services diff --git a/deprecated/detections/excessive_usage_of_net_app.yml b/deprecated/detections/excessive_usage_of_net_app.yml index 1b3556f57b..c993f62522 100644 --- a/deprecated/detections/excessive_usage_of_net_app.yml +++ b/deprecated/detections/excessive_usage_of_net_app.yml @@ -3,7 +3,7 @@ id: 45e52536-ae42-11eb-b5c6-acde48001122 version: 7 date: '2025-01-24' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: Anomaly description: The following analytic has been deprecated. The following analytic detects excessive usage of `net.exe` or `net1.exe` diff --git a/deprecated/detections/execution_of_file_with_spaces_before_extension.yml b/deprecated/detections/execution_of_file_with_spaces_before_extension.yml index 6e453a7f03..ef42aea3b4 100644 --- a/deprecated/detections/execution_of_file_with_spaces_before_extension.yml +++ b/deprecated/detections/execution_of_file_with_spaces_before_extension.yml @@ -3,7 +3,7 @@ id: ab0353e6-a956-420b-b724-a8b4846d5d5a version: 6 date: '2024-11-14' author: Rico Valdez, Splunk -status: deprecated +status: removed type: TTP description: This search looks for processes launched from files with at least five spaces in the name before the extension. This is typically done to obfuscate the diff --git a/deprecated/detections/extended_period_without_successful_netbackup_backups.yml b/deprecated/detections/extended_period_without_successful_netbackup_backups.yml index c72e3977a2..fa3e78bc00 100644 --- a/deprecated/detections/extended_period_without_successful_netbackup_backups.yml +++ b/deprecated/detections/extended_period_without_successful_netbackup_backups.yml @@ -3,7 +3,7 @@ id: a34aae96-ccf8-4aef-952c-3ea214444440 version: 4 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: Hunting description: This search returns a list of hosts that have not successfully completed a backup in over a week. Deprecated because it's a infrastructure monitoring. diff --git a/deprecated/detections/extraction_of_registry_hives.yml b/deprecated/detections/extraction_of_registry_hives.yml index ceb5264fa6..ed19f50850 100644 --- a/deprecated/detections/extraction_of_registry_hives.yml +++ b/deprecated/detections/extraction_of_registry_hives.yml @@ -3,7 +3,7 @@ id: 8bbb7d58-b360-11eb-ba21-acde48001122 version: 8 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects the use of `reg.exe` to export Windows Registry hives, which may contain sensitive diff --git a/deprecated/detections/first_time_seen_command_line_argument.yml b/deprecated/detections/first_time_seen_command_line_argument.yml index 5df827cada..b11889326f 100644 --- a/deprecated/detections/first_time_seen_command_line_argument.yml +++ b/deprecated/detections/first_time_seen_command_line_argument.yml @@ -3,7 +3,7 @@ id: a1b6e73f-98d5-470f-99ac-77aacd578473 version: 8 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Hunting description: This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. diff --git a/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml index 10a412fbc9..e1ff155ab4 100644 --- a/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml +++ b/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml @@ -3,7 +3,7 @@ id: 27af8c15-38b0-4408-b339-920170724adb version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides detection of accounts with high risk roles by projects. Compromised accounts with high risk roles can move laterally or even scalate privileges diff --git a/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml index 1291444493..4082bc1b56 100644 --- a/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml +++ b/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml @@ -3,7 +3,7 @@ id: 2e70ef35-2187-431f-aedc-4503dc9b06ba version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides detection of high risk permissions by resource and accounts. These are permissions that can allow attackers with compromised accounts diff --git a/deprecated/detections/gcp_detect_oauth_token_abuse.yml b/deprecated/detections/gcp_detect_oauth_token_abuse.yml index 25144dd436..16b1471ac1 100644 --- a/deprecated/detections/gcp_detect_oauth_token_abuse.yml +++ b/deprecated/detections/gcp_detect_oauth_token_abuse.yml @@ -3,7 +3,7 @@ id: a7e9f7bb-8901-4ad0-8d88-0a4ab07b1972 version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides detection of possible GCP Oauth token abuse. GCP Oauth token without time limit can be exfiltrated and reused for keeping access diff --git a/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml b/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml index f8fabad5ff..414be67679 100644 --- a/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml +++ b/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml @@ -3,7 +3,7 @@ id: db5957ec-0144-4c56-b512-9dccbe7a2d26 version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: TTP description: This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster diff --git a/deprecated/detections/identify_new_user_accounts.yml b/deprecated/detections/identify_new_user_accounts.yml index 55b528d72a..89e8250b82 100644 --- a/deprecated/detections/identify_new_user_accounts.yml +++ b/deprecated/detections/identify_new_user_accounts.yml @@ -3,7 +3,7 @@ id: 475b9e27-17e4-46e2-b7e2-648221be3b89 version: 4 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Hunting description: This detection search will help profile user accounts in your environment by identifying newly created accounts that have been added to your network in the diff --git a/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml index 8aed9288a5..20458780df 100644 --- a/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml +++ b/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml @@ -3,7 +3,7 @@ id: 5b30b25d-7d32-42d8-95ca-64dfcd9076e6 version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision diff --git a/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml b/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml index 6d04bf8d94..5f424be025 100644 --- a/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml +++ b/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml @@ -3,7 +3,7 @@ id: de7264ed-3ed9-4fef-bb01-6eefc87cefe8 version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC diff --git a/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml index bb7b707a96..ed19c6d3f0 100644 --- a/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml +++ b/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml @@ -3,7 +3,7 @@ id: b6013a7b-85e0-4a45-b051-10b252d69569 version: 5 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml index 17722e0587..9dd04f706e 100644 --- a/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml +++ b/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml @@ -3,7 +3,7 @@ id: a6959c57-fa8f-4277-bb86-7c32fba579d5 version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or diff --git a/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml index ef9d02ecbe..900b6fd517 100644 --- a/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml +++ b/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml @@ -3,7 +3,7 @@ id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72 version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes service accounts,accessing pods and namespaces by IP address and verb diff --git a/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml b/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml index 0adc47769d..a40aa3b80e 100644 --- a/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml +++ b/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml @@ -3,7 +3,7 @@ id: 47af7d20-0607-4079-97d7-7a29af58b54e version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding rare or top to see both extremes diff --git a/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml b/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml index 8ae1ee647e..d06b658319 100644 --- a/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml +++ b/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml @@ -3,7 +3,7 @@ id: 1bba382b-07fd-4ffa-b390-8002739b76e8 version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml index 9993a0a115..a42d6e5acd 100644 --- a/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml +++ b/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml @@ -3,7 +3,7 @@ id: f27349e5-1641-4f6a-9e68-30402be0ad4c version: 5 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml index ccbf5daf0c..502f1644b6 100644 --- a/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml +++ b/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml @@ -3,7 +3,7 @@ id: 019690d7-420f-4da0-b320-f27b09961514 version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes service accounts with failure or forbidden access status diff --git a/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml index ef3fed2b2d..f213575ef1 100644 --- a/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml +++ b/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml @@ -3,7 +3,7 @@ id: 4b6d1ba8-0000-4cec-87e6-6cbbd71651b5 version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on rare Kubectl calls with IP, verb namespace and object access context diff --git a/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml b/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml index 1b1378b2f7..715ad90996 100644 --- a/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml +++ b/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml @@ -3,7 +3,7 @@ id: 86aad3e0-732f-4f66-bbbc-70df448e461d version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster pod diff --git a/deprecated/detections/kubernetes_azure_scan_fingerprint.yml b/deprecated/detections/kubernetes_azure_scan_fingerprint.yml index 8a6b44473d..1604bee2ce 100644 --- a/deprecated/detections/kubernetes_azure_scan_fingerprint.yml +++ b/deprecated/detections/kubernetes_azure_scan_fingerprint.yml @@ -3,7 +3,7 @@ id: c5e5bd5c-1013-4841-8b23-e7b3253c840a version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster in diff --git a/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml index 0d3a4cdf11..32d73fe7a4 100644 --- a/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml +++ b/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml @@ -3,7 +3,7 @@ id: 7f5c2779-88a0-4824-9caa-0f606c8f260f version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision diff --git a/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml index 09a26684ce..a73ac757ba 100644 --- a/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml +++ b/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml @@ -3,7 +3,7 @@ id: 99487de3-7192-4b41-939d-fbe9acfb1340 version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC diff --git a/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml b/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml index 557ab8a5c3..f6d58fb55d 100644 --- a/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml +++ b/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml @@ -3,7 +3,7 @@ id: bdb6d596-86a0-4aba-8369-418ae8b9963a version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets diff --git a/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml b/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml index da1b2cf148..97f65baf4a 100644 --- a/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml +++ b/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml @@ -3,7 +3,7 @@ id: a46923f6-36b9-4806-a681-31f314907c30 version: 5 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets diff --git a/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml index fff4730076..830d71836c 100644 --- a/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml +++ b/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml @@ -3,7 +3,7 @@ id: 7094808d-432a-48e7-bb3c-77e96c894f3b version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or diff --git a/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml index a78e967c70..d3893b3ba1 100644 --- a/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml +++ b/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml @@ -3,7 +3,7 @@ id: a5bed417-070a-41f2-a1e4-82b6aa281557 version: 4 date: '2024-11-14' author: Rod Soto, Splunk -status: deprecated +status: removed type: Hunting description: This search provides information on anonymous Kubectl calls with IP, verb namespace and object access context diff --git a/deprecated/detections/linux_auditd_find_private_keys.yml b/deprecated/detections/linux_auditd_find_private_keys.yml index d45b98a890..225211371a 100644 --- a/deprecated/detections/linux_auditd_find_private_keys.yml +++ b/deprecated/detections/linux_auditd_find_private_keys.yml @@ -3,7 +3,7 @@ id: 80bb9988-190b-4ee0-a3c3-509545a8f678 version: 6 date: '2025-02-10' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects suspicious attempts to find private keys, which may indicate an attacker's effort diff --git a/deprecated/detections/local_account_discovery_with_net.yml b/deprecated/detections/local_account_discovery_with_net.yml index 69f3af6598..2203098764 100644 --- a/deprecated/detections/local_account_discovery_with_net.yml +++ b/deprecated/detections/local_account_discovery_with_net.yml @@ -3,7 +3,7 @@ id: 5d0d4830-0133-11ec-bae3-acde48001122 version: 7 date: '2025-02-10' author: Mauricio Velazco, Splunk -status: deprecated +status: removed type: Hunting description: The following analytic has been deprecated. The following analytic detects the execution of `net.exe` or `net1.exe` with command-line arguments `user` or `users` diff --git a/deprecated/detections/monitor_dns_for_brand_abuse.yml b/deprecated/detections/monitor_dns_for_brand_abuse.yml index 9ad520f284..23a96ac7d0 100644 --- a/deprecated/detections/monitor_dns_for_brand_abuse.yml +++ b/deprecated/detections/monitor_dns_for_brand_abuse.yml @@ -3,7 +3,7 @@ id: 24dd17b1-e2fb-4c31-878c-d4f746595bfa version: 4 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: TTP description: This search looks for DNS requests for faux domains similar to the domains that you want to have monitored for abuse. diff --git a/deprecated/detections/mshtml_module_load_in_office_product.yml b/deprecated/detections/mshtml_module_load_in_office_product.yml index 833a24a872..03be60e1c7 100644 --- a/deprecated/detections/mshtml_module_load_in_office_product.yml +++ b/deprecated/detections/mshtml_module_load_in_office_product.yml @@ -3,7 +3,7 @@ id: 5f1c168e-118b-11ec-84ff-acde48001122 version: 8 date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects the loading of the mshtml.dll module into an Office product, which is indicative diff --git a/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml index 1ebadf8ebc..96b3b69893 100644 --- a/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml +++ b/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml @@ -3,7 +3,7 @@ id: 19cba45f-cad3-4032-8911-0c09e0444552 version: 6 date: '2025-02-10' author: Michael Haag, Mauricio Velazco, Rico Valdez, Splunk -status: deprecated +status: removed type: TTP description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Users Failing To Authenticate From Ip`. This analytic identifies diff --git a/deprecated/detections/net_localgroup_discovery.yml b/deprecated/detections/net_localgroup_discovery.yml index 31b775f015..261b7b7902 100644 --- a/deprecated/detections/net_localgroup_discovery.yml +++ b/deprecated/detections/net_localgroup_discovery.yml @@ -3,7 +3,7 @@ id: 54f5201e-155b-11ec-a6e2-acde48001122 version: 6 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: Hunting description: This search has been deprecated in favour of the more generic analytic "c5c8e0f3-147a-43da-bf04-4cfaec27dc44". The following analytic detects the execution diff --git a/deprecated/detections/network_connection_discovery_with_net.yml b/deprecated/detections/network_connection_discovery_with_net.yml index 0002699f31..b90d9bdde6 100644 --- a/deprecated/detections/network_connection_discovery_with_net.yml +++ b/deprecated/detections/network_connection_discovery_with_net.yml @@ -3,7 +3,7 @@ id: 640337e5-6e41-4b7f-af06-9d9eab5e1e2d version: 6 date: '2025-01-24' author: Mauricio Velazco, Splunk -status: deprecated +status: removed type: Hunting description: The following analytic has been deprecated. The following analytic identifies the execution of `net.exe` or `net1.exe` diff --git a/deprecated/detections/o365_suspicious_admin_email_forwarding.yml b/deprecated/detections/o365_suspicious_admin_email_forwarding.yml index b706b2d0a8..7d67c799b3 100644 --- a/deprecated/detections/o365_suspicious_admin_email_forwarding.yml +++ b/deprecated/detections/o365_suspicious_admin_email_forwarding.yml @@ -3,7 +3,7 @@ id: 7f398cfb-918d-41f4-8db8-2e2474e02c28 version: 4 date: '2025-02-10' author: Patrick Bareiss, Splunk -status: deprecated +status: removed type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Mailbox Email Forwarding Enabled`. This search detects when an admin diff --git a/deprecated/detections/o365_suspicious_rights_delegation.yml b/deprecated/detections/o365_suspicious_rights_delegation.yml index 716fd6289c..f2ed6c205b 100644 --- a/deprecated/detections/o365_suspicious_rights_delegation.yml +++ b/deprecated/detections/o365_suspicious_rights_delegation.yml @@ -3,7 +3,7 @@ id: b25d2973-303e-47c8-bacd-52b61604c6a7 version: 5 date: '2025-02-10' author: Patrick Bareiss, Mauricio Velazco, Splunk -status: deprecated +status: removed type: TTP description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Elevated Mailbox Permission Assigned`. This analytic identifies instances diff --git a/deprecated/detections/o365_suspicious_user_email_forwarding.yml b/deprecated/detections/o365_suspicious_user_email_forwarding.yml index 4ea5ecc88d..534b319903 100644 --- a/deprecated/detections/o365_suspicious_user_email_forwarding.yml +++ b/deprecated/detections/o365_suspicious_user_email_forwarding.yml @@ -3,7 +3,7 @@ id: f8dfe015-dbb3-4569-ba75-b13787e06aa4 version: 5 date: '2025-02-10' author: Patrick Bareiss, Splunk -status: deprecated +status: removed type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `O365 Mailbox Email Forwarding Enabled`. The following analytic detects when diff --git a/deprecated/detections/office_application_drop_executable.yml b/deprecated/detections/office_application_drop_executable.yml index c87210ccf6..6289572cc2 100644 --- a/deprecated/detections/office_application_drop_executable.yml +++ b/deprecated/detections/office_application_drop_executable.yml @@ -3,7 +3,7 @@ id: 73ce70c4-146d-11ec-9184-acde48001122 version: 10 date: '2025-02-10' author: Teoderick Contreras, Michael Haag, Splunk, TheLawsOfChaos, Github -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects Microsoft Office applications dropping or creating executables or scripts on a Windows diff --git a/deprecated/detections/office_application_spawn_regsvr32_process.yml b/deprecated/detections/office_application_spawn_regsvr32_process.yml index 8aa07a2de3..305da934ed 100644 --- a/deprecated/detections/office_application_spawn_regsvr32_process.yml +++ b/deprecated/detections/office_application_spawn_regsvr32_process.yml @@ -3,7 +3,7 @@ id: 2d9fc90c-f11f-11eb-9300-acde48001122 version: 9 date: '2025-02-10' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/deprecated/detections/office_application_spawn_rundll32_process.yml b/deprecated/detections/office_application_spawn_rundll32_process.yml index e648095cc9..6fb15cde36 100644 --- a/deprecated/detections/office_application_spawn_rundll32_process.yml +++ b/deprecated/detections/office_application_spawn_rundll32_process.yml @@ -3,7 +3,7 @@ id: 958751e4-9c5f-11eb-b103-acde48001122 version: 9 date: '2025-02-10' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/deprecated/detections/office_document_creating_schedule_task.yml b/deprecated/detections/office_document_creating_schedule_task.yml index ef59131ecc..75fbcf448d 100644 --- a/deprecated/detections/office_document_creating_schedule_task.yml +++ b/deprecated/detections/office_document_creating_schedule_task.yml @@ -3,7 +3,7 @@ id: cc8b7b74-9d0f-11eb-8342-acde48001122 version: 11 date: '2025-02-10' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects an Office document creating a scheduled task, either through a macro VBA API or diff --git a/deprecated/detections/office_document_executing_macro_code.yml b/deprecated/detections/office_document_executing_macro_code.yml index 8d74ea1aa2..503de3d2b6 100644 --- a/deprecated/detections/office_document_executing_macro_code.yml +++ b/deprecated/detections/office_document_executing_macro_code.yml @@ -3,7 +3,7 @@ id: b12c89bc-9d06-11eb-a592-acde48001122 version: 10 date: '2025-02-10' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic identifies office documents executing macro code. It leverages Sysmon EventCode 7 to detect diff --git a/deprecated/detections/office_document_spawned_child_process_to_download.yml b/deprecated/detections/office_document_spawned_child_process_to_download.yml index 2e78ed372c..9579d186f0 100644 --- a/deprecated/detections/office_document_spawned_child_process_to_download.yml +++ b/deprecated/detections/office_document_spawned_child_process_to_download.yml @@ -3,7 +3,7 @@ id: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3 version: 11 date: '2025-02-10' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic identifies Office applications spawning child processes to download content via HTTP/HTTPS. diff --git a/deprecated/detections/office_product_spawn_cmd_process.yml b/deprecated/detections/office_product_spawn_cmd_process.yml index 4893d60d9f..949962d43e 100644 --- a/deprecated/detections/office_product_spawn_cmd_process.yml +++ b/deprecated/detections/office_product_spawn_cmd_process.yml @@ -3,7 +3,7 @@ id: b8b19420-e892-11eb-9244-acde48001122 version: 10 date: '2025-02-10' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/deprecated/detections/office_product_spawning_bitsadmin.yml b/deprecated/detections/office_product_spawning_bitsadmin.yml index 28ee0cc811..e4a1cd88ff 100644 --- a/deprecated/detections/office_product_spawning_bitsadmin.yml +++ b/deprecated/detections/office_product_spawning_bitsadmin.yml @@ -3,7 +3,7 @@ id: e8c591f4-a6d7-11eb-8cf7-acde48001122 version: 10 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/deprecated/detections/office_product_spawning_certutil.yml b/deprecated/detections/office_product_spawning_certutil.yml index 698343c8ae..d1819873df 100644 --- a/deprecated/detections/office_product_spawning_certutil.yml +++ b/deprecated/detections/office_product_spawning_certutil.yml @@ -3,7 +3,7 @@ id: 6925fe72-a6d5-11eb-9e17-acde48001122 version: 10 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/deprecated/detections/office_product_spawning_mshta.yml b/deprecated/detections/office_product_spawning_mshta.yml index 9c8c8ae1ce..e21d9688c5 100644 --- a/deprecated/detections/office_product_spawning_mshta.yml +++ b/deprecated/detections/office_product_spawning_mshta.yml @@ -3,7 +3,7 @@ id: 6078fa20-a6d2-11eb-b662-acde48001122 version: 9 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml b/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml index 41f3f9df66..2e4c38fdd5 100644 --- a/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml +++ b/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml @@ -3,7 +3,7 @@ id: c661f6be-a38c-11eb-be57-acde48001122 version: 11 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects any Windows Office Product spawning `rundll32.exe` without a `.dll` file extension. diff --git a/deprecated/detections/office_product_spawning_windows_script_host.yml b/deprecated/detections/office_product_spawning_windows_script_host.yml index b4da3bfa8e..b33dc038c5 100644 --- a/deprecated/detections/office_product_spawning_windows_script_host.yml +++ b/deprecated/detections/office_product_spawning_windows_script_host.yml @@ -3,7 +3,7 @@ id: b3628a5b-8d02-42fa-a891-eebf2351cbe1 version: 12 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/deprecated/detections/office_product_spawning_wmic.yml b/deprecated/detections/office_product_spawning_wmic.yml index 0e60c6e32f..f8f0be00c5 100644 --- a/deprecated/detections/office_product_spawning_wmic.yml +++ b/deprecated/detections/office_product_spawning_wmic.yml @@ -3,7 +3,7 @@ id: ffc236d6-a6c9-11eb-95f1-acde48001122 version: 11 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/deprecated/detections/office_product_writing_cab_or_inf.yml b/deprecated/detections/office_product_writing_cab_or_inf.yml index 9d29d2a888..7b6f06bb42 100644 --- a/deprecated/detections/office_product_writing_cab_or_inf.yml +++ b/deprecated/detections/office_product_writing_cab_or_inf.yml @@ -3,7 +3,7 @@ id: f48cd1d4-125a-11ec-a447-acde48001122 version: 11 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation. diff --git a/deprecated/detections/office_spawning_control.yml b/deprecated/detections/office_spawning_control.yml index f141b89519..37487e24a7 100644 --- a/deprecated/detections/office_spawning_control.yml +++ b/deprecated/detections/office_spawning_control.yml @@ -3,7 +3,7 @@ id: 053e027c-10c7-11ec-8437-acde48001122 version: 12 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic identifies instances where `control.exe` is spawned by a Microsoft Office product. It leverages diff --git a/deprecated/detections/okta_account_locked_out.yml b/deprecated/detections/okta_account_locked_out.yml index 0ad8243973..827f3fd86a 100644 --- a/deprecated/detections/okta_account_locked_out.yml +++ b/deprecated/detections/okta_account_locked_out.yml @@ -3,7 +3,7 @@ id: d650c0ae-bdc5-400e-9f0f-f7aa0a010ef1 version: 3 date: '2024-11-14' author: Michael Haag, Splunk -status: deprecated +status: removed type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Accounts Locked Out`. The following analytic utilizes the user.acount.lock diff --git a/deprecated/detections/okta_account_lockout_events.yml b/deprecated/detections/okta_account_lockout_events.yml index b2ec1f14ef..cacf38cb37 100644 --- a/deprecated/detections/okta_account_lockout_events.yml +++ b/deprecated/detections/okta_account_lockout_events.yml @@ -3,7 +3,7 @@ id: 62b70968-a0a5-4724-8ac4-67871e6f544d version: 5 date: '2025-02-10' author: Michael Haag, Rico Valdez, Splunk -status: deprecated +status: removed type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Accounts Locked Out`. The following anomaly will generate based diff --git a/deprecated/detections/okta_failed_sso_attempts.yml b/deprecated/detections/okta_failed_sso_attempts.yml index 3c1d92c759..7ab6ebad6c 100644 --- a/deprecated/detections/okta_failed_sso_attempts.yml +++ b/deprecated/detections/okta_failed_sso_attempts.yml @@ -3,7 +3,7 @@ id: 371a6545-2618-4032-ad84-93386b8698c5 version: 6 date: '2025-02-10' author: Michael Haag, Rico Valdez, Splunk -status: deprecated +status: removed type: Anomaly description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with this detection `Okta Unauthorized Access to Application - DM`. The following diff --git a/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml b/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml index 00af9d0aa5..865053caa9 100644 --- a/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml +++ b/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml @@ -4,7 +4,7 @@ version: 5 date: '2025-02-10' author: Okta, Inc, Michael Haag, Splunk type: TTP -status: deprecated +status: removed data_source: [] description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas diff --git a/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml b/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml index e68cf87729..4a6f29d878 100644 --- a/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml +++ b/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml @@ -4,7 +4,7 @@ version: 5 date: '2025-02-10' author: Okta, Inc, Michael Haag, Splunk type: TTP -status: deprecated +status: removed data_source: [] description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta ThreatInsight Threat Detected`. The following analytic utilizes Oktas diff --git a/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml b/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml index 9817b5f845..cd09e9e972 100644 --- a/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml +++ b/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml @@ -3,7 +3,7 @@ id: d93f785e-4c2c-4262-b8c7-12b77a13fd39 version: 4 date: '2024-11-14' author: Michael Haag, Marissa Bower, Splunk -status: deprecated +status: removed type: TTP description: '**DEPRECATION NOTE** - This search has been deprecated and replaced with `Okta Multiple Failed MFA Requests For User`. The following analytic identifies diff --git a/deprecated/detections/osquery_pack___coldroot_detection.yml b/deprecated/detections/osquery_pack___coldroot_detection.yml index 369173b8fd..7b3a494261 100644 --- a/deprecated/detections/osquery_pack___coldroot_detection.yml +++ b/deprecated/detections/osquery_pack___coldroot_detection.yml @@ -3,7 +3,7 @@ id: a6fffe5e-05c3-4c04-badc-887607fbb8dc version: 5 date: '2024-11-14' author: Rico Valdez, Splunk -status: deprecated +status: removed type: TTP description: This search looks for ColdRoot events from the osx-attacks osquery pack. data_source: [] diff --git a/deprecated/detections/password_policy_discovery_with_net.yml b/deprecated/detections/password_policy_discovery_with_net.yml index 0656e661c8..527907ea6f 100644 --- a/deprecated/detections/password_policy_discovery_with_net.yml +++ b/deprecated/detections/password_policy_discovery_with_net.yml @@ -3,7 +3,7 @@ id: 09336538-065a-11ec-8665-acde48001122 version: 7 date: '2025-01-24' author: Teoderick Contreras, Mauricio Velazco, Splunk -status: deprecated +status: removed type: Hunting description: The following analytic has been deprecated. The following analytic identifies the execution of `net.exe` or `net1.exe` diff --git a/deprecated/detections/processes_created_by_netsh.yml b/deprecated/detections/processes_created_by_netsh.yml index cb947299d8..a7ff65c024 100644 --- a/deprecated/detections/processes_created_by_netsh.yml +++ b/deprecated/detections/processes_created_by_netsh.yml @@ -3,7 +3,7 @@ id: b89919ed-fe5f-492c-b139-95dbb162041e version: 8 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: TTP description: This search looks for processes launching netsh.exe to execute various commands via the netsh command-line utility. Netsh.exe is a command-line scripting diff --git a/deprecated/detections/prohibited_software_on_endpoint.yml b/deprecated/detections/prohibited_software_on_endpoint.yml index 243c1c8374..0572b6f2bf 100644 --- a/deprecated/detections/prohibited_software_on_endpoint.yml +++ b/deprecated/detections/prohibited_software_on_endpoint.yml @@ -3,7 +3,7 @@ id: a51bfe1a-94f0-48cc-b4e4-b6ae50145893 version: 5 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: Hunting description: This search looks for applications on the endpoint that you have marked as prohibited. diff --git a/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml index b003f3bd58..bc776d7e9a 100644 --- a/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml +++ b/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml @@ -3,7 +3,7 @@ id: 61a7d1e6-f5d4-41d9-a9be-39a1ffe69459 version: 5 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: TTP description: The search looks for command-line arguments used to hide a file or directory using the reg add command. diff --git a/deprecated/detections/remote_registry_key_modifications.yml b/deprecated/detections/remote_registry_key_modifications.yml index 71f902a8ad..ffd7eff675 100644 --- a/deprecated/detections/remote_registry_key_modifications.yml +++ b/deprecated/detections/remote_registry_key_modifications.yml @@ -3,7 +3,7 @@ id: c9f4b923-f8af-4155-b697-1354f5dcbc5e version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: TTP description: This search monitors for remote modifications to registry keys. data_source: diff --git a/deprecated/detections/remote_system_discovery_with_net.yml b/deprecated/detections/remote_system_discovery_with_net.yml index 2377264b52..8961d33627 100644 --- a/deprecated/detections/remote_system_discovery_with_net.yml +++ b/deprecated/detections/remote_system_discovery_with_net.yml @@ -3,7 +3,7 @@ id: 9df16706-04a2-41e2-bbfe-9b38b34409d3 version: 5 date: '2025-01-13' author: Mauricio Velazco, Splunk -status: deprecated +status: removed type: Hunting description: The following analytic has been deprecated in favour of two dedicated analytics "4dc3951f-b3f8-4f46-b412-76a483f72277" and "a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" .The following analytic identifies the execution of `net.exe` or `net1.exe` with command-line arguments used to discover remote systems, such as `domain computers /domain`. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as it indicates potential reconnaissance efforts by adversaries or Red Teams to map out networked systems and Active Directory structures. If confirmed malicious, this behavior could lead to further network exploitation, privilege escalation, or lateral movement within the environment. data_source: diff --git a/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml b/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml index 0197ba45a3..19aaa1b2c4 100644 --- a/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml +++ b/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml @@ -3,7 +3,7 @@ id: 1297fb80-f42a-4b4a-9c8b-78c066437cf6 version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: TTP description: This search looks for flags passed to schtasks.exe on the command-line that indicate that task names related to the execution of Bad Rabbit ransomware diff --git a/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml b/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml index 1f4a043402..1859af0f86 100644 --- a/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml +++ b/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml @@ -3,7 +3,7 @@ id: 354be8e0-32cd-4da0-8c47-796de13b60ea version: 4 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: TTP description: The search is used to detect systems that are still vulnerable to the Spectre and Meltdown vulnerabilities. diff --git a/deprecated/detections/suspicious_changes_to_file_associations.yml b/deprecated/detections/suspicious_changes_to_file_associations.yml index e9438be5a1..9b9a6fa348 100644 --- a/deprecated/detections/suspicious_changes_to_file_associations.yml +++ b/deprecated/detections/suspicious_changes_to_file_associations.yml @@ -3,7 +3,7 @@ id: 1b989a0e-0129-4446-a695-f193a5b746fc version: 7 date: '2024-11-14' author: Rico Valdez, Splunk -status: deprecated +status: removed type: TTP description: This search looks for changes to registry values that control Windows file associations, executed by a process that is not typical for legitimate, routine diff --git a/deprecated/detections/suspicious_email___uba_anomaly.yml b/deprecated/detections/suspicious_email___uba_anomaly.yml index 0e3a3f31d6..7399390137 100644 --- a/deprecated/detections/suspicious_email___uba_anomaly.yml +++ b/deprecated/detections/suspicious_email___uba_anomaly.yml @@ -3,7 +3,7 @@ id: 56e877a6-1455-4479-ad16-0550dc1e33f8 version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk -status: deprecated +status: removed type: Anomaly description: This detection looks for emails that are suspicious because of their sender, domain rareness, or behavior differences. This is an anomaly generated by diff --git a/deprecated/detections/suspicious_file_write.yml b/deprecated/detections/suspicious_file_write.yml index 8630632e57..12e9533132 100644 --- a/deprecated/detections/suspicious_file_write.yml +++ b/deprecated/detections/suspicious_file_write.yml @@ -3,7 +3,7 @@ id: 57f76b8a-32f0-42ed-b358-d9fa3ca7bac8 version: 6 date: '2024-11-14' author: Rico Valdez, Splunk -status: deprecated +status: removed type: Hunting description: The search looks for files created with names that have been linked to malicious activity. diff --git a/deprecated/detections/suspicious_powershell_command_line_arguments.yml b/deprecated/detections/suspicious_powershell_command_line_arguments.yml index b2efc4ee51..c7a8ffa35b 100644 --- a/deprecated/detections/suspicious_powershell_command_line_arguments.yml +++ b/deprecated/detections/suspicious_powershell_command_line_arguments.yml @@ -3,7 +3,7 @@ id: 2cdb91d2-542c-497f-b252-be495e71f38c version: 9 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: TTP description: This search looks for PowerShell processes started with a base64 encoded command-line passed to it, with parameters to modify the execution policy for the diff --git a/deprecated/detections/suspicious_rundll32_rename.yml b/deprecated/detections/suspicious_rundll32_rename.yml index eee4228129..81ead5651f 100644 --- a/deprecated/detections/suspicious_rundll32_rename.yml +++ b/deprecated/detections/suspicious_rundll32_rename.yml @@ -3,7 +3,7 @@ id: 7360137f-abad-473e-8189-acbdaa34d114 version: 8 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: Hunting description: The following hunting analytic identifies renamed instances of rundll32.exe executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. diff --git a/deprecated/detections/suspicious_writes_to_system_volume_information.yml b/deprecated/detections/suspicious_writes_to_system_volume_information.yml index 866160575b..e9c1f20721 100644 --- a/deprecated/detections/suspicious_writes_to_system_volume_information.yml +++ b/deprecated/detections/suspicious_writes_to_system_volume_information.yml @@ -3,7 +3,7 @@ id: cd6297cd-2bdd-4aa1-84aa-5d2f84228fac version: 5 date: '2024-11-14' author: Rico Valdez, Splunk -status: deprecated +status: removed type: Hunting description: This search detects writes to the 'System Volume Information' folder by something other than the System process. diff --git a/deprecated/detections/uncommon_processes_on_endpoint.yml b/deprecated/detections/uncommon_processes_on_endpoint.yml index e0378b0e1f..fa6e1d6c2d 100644 --- a/deprecated/detections/uncommon_processes_on_endpoint.yml +++ b/deprecated/detections/uncommon_processes_on_endpoint.yml @@ -3,7 +3,7 @@ id: 29ccce64-a10c-4389-a45f-337cb29ba1f7 version: 7 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: Hunting description: This search looks for applications on the endpoint that you have marked as uncommon. diff --git a/deprecated/detections/unsigned_image_loaded_by_lsass.yml b/deprecated/detections/unsigned_image_loaded_by_lsass.yml index db021a2bf3..bda913376f 100644 --- a/deprecated/detections/unsigned_image_loaded_by_lsass.yml +++ b/deprecated/detections/unsigned_image_loaded_by_lsass.yml @@ -3,7 +3,7 @@ id: 56ef054c-76ef-45f9-af4a-a634695dcd65 version: 4 date: '2024-11-14' author: Patrick Bareiss, Splunk -status: deprecated +status: removed type: TTP description: This search detects loading of unsigned images by LSASS. Deprecated because too noisy. diff --git a/deprecated/detections/unsuccessful_netbackup_backups.yml b/deprecated/detections/unsuccessful_netbackup_backups.yml index 3e8fc0b5af..afa6f95673 100644 --- a/deprecated/detections/unsuccessful_netbackup_backups.yml +++ b/deprecated/detections/unsuccessful_netbackup_backups.yml @@ -3,7 +3,7 @@ id: a34aae96-ccf8-4aaa-952c-3ea21444444f version: 4 date: '2024-11-14' author: David Dorsey, Splunk -status: deprecated +status: removed type: Hunting description: This search gives you the hosts where a backup was attempted and then failed. diff --git a/deprecated/detections/web_fraud___account_harvesting.yml b/deprecated/detections/web_fraud___account_harvesting.yml index 4fb3b3b784..ba78a3fa1a 100644 --- a/deprecated/detections/web_fraud___account_harvesting.yml +++ b/deprecated/detections/web_fraud___account_harvesting.yml @@ -3,7 +3,7 @@ id: bf1d7b5c-df2f-4249-a401-c09fdc221ddf version: 4 date: '2024-11-14' author: Jim Apger, Splunk -status: deprecated +status: removed type: TTP description: This search is used to identify the creation of multiple user accounts using the same email domain name. diff --git a/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml b/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml index 518a5be28e..c084525674 100644 --- a/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml +++ b/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml @@ -3,7 +3,7 @@ id: 31337bbb-bc22-4752-b599-ef192df2dc7a version: 4 date: '2024-11-14' author: Jim Apger, Splunk -status: deprecated +status: removed type: Anomaly description: This search is used to examine web sessions to identify those where the clicks are occurring too quickly for a human or are occurring with a near-perfect diff --git a/deprecated/detections/web_fraud___password_sharing_across_accounts.yml b/deprecated/detections/web_fraud___password_sharing_across_accounts.yml index 48c9b3908c..c1ac8d3080 100644 --- a/deprecated/detections/web_fraud___password_sharing_across_accounts.yml +++ b/deprecated/detections/web_fraud___password_sharing_across_accounts.yml @@ -3,7 +3,7 @@ id: 31337a1a-53b9-4e05-96e9-55c934cb71d3 version: 4 date: '2024-11-14' author: Jim Apger, Splunk -status: deprecated +status: removed type: Anomaly description: This search is used to identify user accounts that share a common password. data_source: [] diff --git a/deprecated/detections/windows_command_shell_fetch_env_variables.yml b/deprecated/detections/windows_command_shell_fetch_env_variables.yml index 90618ba3e5..f604adbab8 100644 --- a/deprecated/detections/windows_command_shell_fetch_env_variables.yml +++ b/deprecated/detections/windows_command_shell_fetch_env_variables.yml @@ -3,7 +3,7 @@ id: 048839e4-1eaa-43ff-8a22-86d17f6fcc13 version: 5 date: '2025-01-24' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic identifies a suspicious process command line fetching diff --git a/deprecated/detections/windows_connhost_exe_started_forcefully.yml b/deprecated/detections/windows_connhost_exe_started_forcefully.yml index 2718083864..5574cb0440 100644 --- a/deprecated/detections/windows_connhost_exe_started_forcefully.yml +++ b/deprecated/detections/windows_connhost_exe_started_forcefully.yml @@ -3,7 +3,7 @@ id: c114aaca-68ee-41c2-ad8c-32bf21db8769 version: 5 date: '2024-11-14' author: Rod Soto, Jose Hernandez, Splunk -status: deprecated +status: removed type: TTP description: The search looks for the Console Window Host process (connhost.exe) executed using the force flag -ForceV1. This is not regular behavior in the Windows OS and diff --git a/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml b/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml index 6149fc746d..a2b4d5bffc 100644 --- a/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml +++ b/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml @@ -3,7 +3,7 @@ id: 79c7d0fc-60c7-41be-a616-ccda752efe89 version: 6 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: Hunting description: The following hunting analytic is an experimental query built against a accidental feature using the latest Sysmon TA 3.0 (https://splunkbase.splunk.com/app/5709/) diff --git a/deprecated/detections/windows_hosts_file_modification.yml b/deprecated/detections/windows_hosts_file_modification.yml index 0c7453eab3..7f40e5ea32 100644 --- a/deprecated/detections/windows_hosts_file_modification.yml +++ b/deprecated/detections/windows_hosts_file_modification.yml @@ -3,7 +3,7 @@ id: 06a6fc63-a72d-41dc-8736-7e3dd9612116 version: 4 date: '2024-11-14' author: Rico Valdez, Splunk -status: deprecated +status: removed type: TTP description: The search looks for modifications to the hosts file on all Windows endpoints across your environment. diff --git a/deprecated/detections/windows_lateral_tool_transfer_remcom.yml b/deprecated/detections/windows_lateral_tool_transfer_remcom.yml index 47789c6b30..e1d64bf004 100644 --- a/deprecated/detections/windows_lateral_tool_transfer_remcom.yml +++ b/deprecated/detections/windows_lateral_tool_transfer_remcom.yml @@ -4,7 +4,7 @@ version: 6 date: '2024-12-10' author: Michael Haag, Splunk type: TTP -status: deprecated +status: removed data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 diff --git a/deprecated/detections/windows_modify_registry_reg_restore.yml b/deprecated/detections/windows_modify_registry_reg_restore.yml index f63d1b0214..8045b06c1e 100644 --- a/deprecated/detections/windows_modify_registry_reg_restore.yml +++ b/deprecated/detections/windows_modify_registry_reg_restore.yml @@ -3,7 +3,7 @@ id: d0072bd2-6d73-4c1b-bc77-ded6d2da3a4e version: 5 date: '2025-01-24' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: Hunting description: The following analytic has been deprecated. The following analytic detects the execution of reg.exe with the "restore" diff --git a/deprecated/detections/windows_msiexec_with_network_connections.yml b/deprecated/detections/windows_msiexec_with_network_connections.yml index 5c17518468..e8ace70d6d 100644 --- a/deprecated/detections/windows_msiexec_with_network_connections.yml +++ b/deprecated/detections/windows_msiexec_with_network_connections.yml @@ -3,7 +3,7 @@ id: 827409a1-5393-4d8d-8da4-bbb297c262a7 version: 7 date: '2025-01-24' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects MSIExec making network connections over diff --git a/deprecated/detections/windows_network_share_interaction_with_net.yml b/deprecated/detections/windows_network_share_interaction_with_net.yml index fea71519c1..d07e5475c4 100644 --- a/deprecated/detections/windows_network_share_interaction_with_net.yml +++ b/deprecated/detections/windows_network_share_interaction_with_net.yml @@ -3,7 +3,7 @@ id: 4dc3951f-b3f8-4f46-b412-76a483f72277 version: 6 date: '2025-01-24' author: Dean Luxton -status: deprecated +status: removed type: TTP data_source: - Sysmon EventID 1 diff --git a/deprecated/detections/windows_office_product_spawning_msdt.yml b/deprecated/detections/windows_office_product_spawning_msdt.yml index 9415352231..7938c379ea 100644 --- a/deprecated/detections/windows_office_product_spawning_msdt.yml +++ b/deprecated/detections/windows_office_product_spawning_msdt.yml @@ -3,7 +3,7 @@ id: 127eba64-c981-40bf-8589-1830638864a7 version: 11 date: '2025-02-10' author: Michael Haag, Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects a Microsoft Office product spawning the Windows msdt.exe process. This detection diff --git a/deprecated/detections/windows_query_registry_reg_save.yml b/deprecated/detections/windows_query_registry_reg_save.yml index 291c0cf7a0..b72b968b31 100644 --- a/deprecated/detections/windows_query_registry_reg_save.yml +++ b/deprecated/detections/windows_query_registry_reg_save.yml @@ -3,7 +3,7 @@ id: cbee60c1-b776-456f-83c2-faa56bdbe6c6 version: 6 date: '2025-01-24' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: Hunting description: The following analytic has been deprecated. The following analytic detects the execution of the reg.exe process with diff --git a/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml b/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml index 00ff416650..2a90df0a04 100644 --- a/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml +++ b/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml @@ -3,7 +3,7 @@ id: 827af04b-0d08-479b-9b84-b7d4644e4b80 version: 5 date: '2025-01-24' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: Anomaly description: The following analytic has been deprecated. The following analytic identifies attempts to stop services on a system diff --git a/deprecated/detections/windows_valid_account_with_never_expires_password.yml b/deprecated/detections/windows_valid_account_with_never_expires_password.yml index 01b416d1d5..3e3a6be6b4 100644 --- a/deprecated/detections/windows_valid_account_with_never_expires_password.yml +++ b/deprecated/detections/windows_valid_account_with_never_expires_password.yml @@ -3,7 +3,7 @@ id: 73a931db-1830-48b3-8296-cd9cfa09c3c8 version: 6 date: '2025-01-24' author: Teoderick Contreras, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated. The following analytic detects the use of net.exe to update user account diff --git a/deprecated/detections/winword_spawning_cmd.yml b/deprecated/detections/winword_spawning_cmd.yml index 2d65e01f22..b9ec89bd35 100644 --- a/deprecated/detections/winword_spawning_cmd.yml +++ b/deprecated/detections/winword_spawning_cmd.yml @@ -3,7 +3,7 @@ id: 6fcbaedc-a37b-11eb-956b-acde48001122 version: 8 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/deprecated/detections/winword_spawning_powershell.yml b/deprecated/detections/winword_spawning_powershell.yml index 4164d64cf7..d9dd1b7902 100644 --- a/deprecated/detections/winword_spawning_powershell.yml +++ b/deprecated/detections/winword_spawning_powershell.yml @@ -3,7 +3,7 @@ id: b2c950b8-9be2-11eb-8658-acde48001122 version: 8 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach in "Windows Office Product Spawned Uncommon Process". The following analytic diff --git a/deprecated/detections/winword_spawning_windows_script_host.yml b/deprecated/detections/winword_spawning_windows_script_host.yml index 47feee0635..736daa38b8 100644 --- a/deprecated/detections/winword_spawning_windows_script_host.yml +++ b/deprecated/detections/winword_spawning_windows_script_host.yml @@ -3,7 +3,7 @@ id: 637e1b5c-9be1-11eb-9c32-acde48001122 version: 7 date: '2025-02-10' author: Michael Haag, Splunk -status: deprecated +status: removed type: TTP description: The following analytic has been deprecated in favour of a more generic approach. The following analytic identifies instances where Microsoft Winword.exe diff --git a/deprecated/investigations/all_backup_logs_for_host.yml b/deprecated/investigations/all_backup_logs_for_host.yml index 526e0760f2..b6bfc3dfb0 100644 --- a/deprecated/investigations/all_backup_logs_for_host.yml +++ b/deprecated/investigations/all_backup_logs_for_host.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-09-12' author: Rico Valdez, Splunk type: Investigation -status: deprecated +status: removed description: Retrieve the backup logs for the last 2 weeks for a specific host in order to investigate why backups are not completing successfully. search: '| search `netbackup` dest=$dest$' diff --git a/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml b/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml index fdd85fd8e0..e1462cd64e 100644 --- a/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml +++ b/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-04-13' author: Rod Soto, Splunk type: Investigation -status: deprecated +status: removed description: This search provides investigation data about requests via user agent, authentication request URI, verb and cluster name data against Kubernetes cluster from a specific IP address diff --git a/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml b/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml index c68fadb66c..2159c1a135 100644 --- a/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml +++ b/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-06-08' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search retrieves the all the alerts created by AWS Security Hub for a specific dest(instance_id). search: '`aws_securityhub_firehose` "findings{}.Resources{}.Type"=AWSEC2Instance | diff --git a/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml b/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml index c9523dd2fd..59a95196e1 100644 --- a/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml +++ b/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-06-08' author: David Dorsey, Splunk type: Investigation -status: deprecated +status: removed description: This search retrieves the times, ARN, source IPs, AWS regions, event names, and the result of the event for specific credentials. search: '`cloudtrail` | rename userIdentity.accessKeyId as accessKeyId| search accessKeyId=$accessKeyId$ diff --git a/deprecated/investigations/aws_investigate_user_activities_by_arn.yml b/deprecated/investigations/aws_investigate_user_activities_by_arn.yml index d15290547a..4646dfe30a 100644 --- a/deprecated/investigations/aws_investigate_user_activities_by_arn.yml +++ b/deprecated/investigations/aws_investigate_user_activities_by_arn.yml @@ -4,7 +4,7 @@ version: 2 date: '2019-04-30' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search lists all the logged CloudTrail activities by a specific user ARN and will create a table containing the source of the user, the region of the activity, the name and type of the event, the action taken, and all the user's diff --git a/deprecated/investigations/aws_network_acl_details_from_id.yml b/deprecated/investigations/aws_network_acl_details_from_id.yml index 71ef17baf8..de00a587d7 100644 --- a/deprecated/investigations/aws_network_acl_details_from_id.yml +++ b/deprecated/investigations/aws_network_acl_details_from_id.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-01-22' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search queries AWS description logs and returns all the information about a specific network ACL via network ACL ID search: '`aws_description` | rename id as networkAclId | search networkAclId=$networkAclId$ diff --git a/deprecated/investigations/aws_network_interface_details_via_resourceid.yml b/deprecated/investigations/aws_network_interface_details_via_resourceid.yml index 081ba1bdc4..6ae2a743e0 100644 --- a/deprecated/investigations/aws_network_interface_details_via_resourceid.yml +++ b/deprecated/investigations/aws_network_interface_details_via_resourceid.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-05-07' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search queries AWS configuration logs and returns the information about a specific network interface via network interface ID. The information will include the ARN of the network interface, its relationships with other AWS resources, diff --git a/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml b/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml index 86946b4438..30ba740556 100644 --- a/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml +++ b/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-06-26' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search queries AWS configuration logs and returns the information about a specific S3 bucket. The information returned includes the time the S3 bucket was created, the resource ID, the region it belongs to, the value of action performed, diff --git a/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml b/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml index d4359faeb0..ea800a69ab 100644 --- a/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml +++ b/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-04-13' author: Rod Soto, Splunk type: Investigation -status: deprecated +status: removed description: This search provides investigation data about requests via user agent, authentication request URI, resource path and cluster name data against Kubernetes cluster from a specific IP address diff --git a/deprecated/investigations/get_all_aws_activity_from_city.yml b/deprecated/investigations/get_all_aws_activity_from_city.yml index 4e9d0f79a9..53a66d3aa7 100644 --- a/deprecated/investigations/get_all_aws_activity_from_city.yml +++ b/deprecated/investigations/get_all_aws_activity_from_city.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-03-19' author: David Dorsey, Splunk type: Investigation -status: deprecated +status: removed description: This search retrieves all the activity from a specific city and will create a table containing the time, city, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not diff --git a/deprecated/investigations/get_all_aws_activity_from_country.yml b/deprecated/investigations/get_all_aws_activity_from_country.yml index aef67b8395..de55cb7b02 100644 --- a/deprecated/investigations/get_all_aws_activity_from_country.yml +++ b/deprecated/investigations/get_all_aws_activity_from_country.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-03-19' author: David Dorsey, Splunk type: Investigation -status: deprecated +status: removed description: This search retrieves all the activity from a specific country and will create a table containing the time, country, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether diff --git a/deprecated/investigations/get_all_aws_activity_from_ip_address.yml b/deprecated/investigations/get_all_aws_activity_from_ip_address.yml index ad00e31621..52af123579 100644 --- a/deprecated/investigations/get_all_aws_activity_from_ip_address.yml +++ b/deprecated/investigations/get_all_aws_activity_from_ip_address.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-03-19' author: David Dorsey, Splunk type: Investigation -status: deprecated +status: removed description: This search retrieves all the activity from a specific IP address and will create a table containing the time, ARN, username, the type of user, the IP address, the AWS region the activity was in, the API called, and whether or not diff --git a/deprecated/investigations/get_all_aws_activity_from_region.yml b/deprecated/investigations/get_all_aws_activity_from_region.yml index a9be04ab63..383729b151 100644 --- a/deprecated/investigations/get_all_aws_activity_from_region.yml +++ b/deprecated/investigations/get_all_aws_activity_from_region.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-03-19' author: David Dorsey, Splunk type: Investigation -status: deprecated +status: removed description: This search retrieves all the activity from a specific geographic region and will create a table containing the time, geographic region, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API diff --git a/deprecated/investigations/get_backup_logs_for_endpoint.yml b/deprecated/investigations/get_backup_logs_for_endpoint.yml index 92c86ed03a..ba01f79f92 100644 --- a/deprecated/investigations/get_backup_logs_for_endpoint.yml +++ b/deprecated/investigations/get_backup_logs_for_endpoint.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-09-14' author: David Dorsey, Splunk type: Investigation -status: deprecated +status: removed description: This search will tell you the backup status from your netbackup_logs of a specific endpoint for the last week. search: '`netbackup` COMPUTERNAME=$dest$ | rename COMPUTERNAME as dest, MESSAGE as diff --git a/deprecated/investigations/get_certificate_logs_for_a_domain.yml b/deprecated/investigations/get_certificate_logs_for_a_domain.yml index f0b2aa4a3d..1dc65d87e5 100644 --- a/deprecated/investigations/get_certificate_logs_for_a_domain.yml +++ b/deprecated/investigations/get_certificate_logs_for_a_domain.yml @@ -4,7 +4,7 @@ version: 2 date: '2019-04-29' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search queries the Certificates datamodel and give you all the information for a specific domain. Please note that the certificates issued by "Let's Encrypt" are widely used by attackers. diff --git a/deprecated/investigations/get_dns_server_history_for_a_host.yml b/deprecated/investigations/get_dns_server_history_for_a_host.yml index 58ba43d1c1..f6b7e5c1c0 100644 --- a/deprecated/investigations/get_dns_server_history_for_a_host.yml +++ b/deprecated/investigations/get_dns_server_history_for_a_host.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-11-09' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: While investigating any detections it is important to understand which and how many DNS servers a host has connected to in the past. This search uses data that is tagged as DNS and gives you a count and list of DNS servers that a particular diff --git a/deprecated/investigations/get_dns_traffic_ratio.yml b/deprecated/investigations/get_dns_traffic_ratio.yml index ede0480799..99247a4007 100644 --- a/deprecated/investigations/get_dns_traffic_ratio.yml +++ b/deprecated/investigations/get_dns_traffic_ratio.yml @@ -4,7 +4,7 @@ version: 2 date: '2024-09-24' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search calculates the ratio of DNS traffic originating and coming from a host to a list of DNS servers over the last 24 hours. A high value of this ratio could be very useful to quickly understand if a src_ip (host) is sending a diff --git a/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml b/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml index ed0ddf0c52..800e16d849 100644 --- a/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml +++ b/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-02-12' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search queries AWS description logs and returns all the information about a specific instance via the instanceId field search: '`aws_description` | dedup id sortby -_time |rename id as instanceId| search diff --git a/deprecated/investigations/get_ec2_launch_details.yml b/deprecated/investigations/get_ec2_launch_details.yml index 46432d9945..e9b715feb1 100644 --- a/deprecated/investigations/get_ec2_launch_details.yml +++ b/deprecated/investigations/get_ec2_launch_details.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-03-12' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search returns some of the launch details for a EC2 instance. search: '`cloudtrail` dest=$dest$ |rename userIdentity.arn as arn, responseElements.instancesSet.items{}.instanceId as dest, responseElements.instancesSet.items{}.privateIpAddress as privateIpAddress, diff --git a/deprecated/investigations/get_email_info.yml b/deprecated/investigations/get_email_info.yml index 247576a7cc..fc572aad29 100644 --- a/deprecated/investigations/get_email_info.yml +++ b/deprecated/investigations/get_email_info.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-11-09' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search returns all the information Splunk might have collected a specific email message over the last 2 hours. search: '| from datamodel Email.All_Email | search message_id=$message_id$' diff --git a/deprecated/investigations/get_emails_from_specific_sender.yml b/deprecated/investigations/get_emails_from_specific_sender.yml index c4e5b0389a..b10b60a45a 100644 --- a/deprecated/investigations/get_emails_from_specific_sender.yml +++ b/deprecated/investigations/get_emails_from_specific_sender.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-11-09' author: David Dorsey, Splunk type: Investigation -status: deprecated +status: removed description: This search returns all the emails from a specific sender over the last 24 and next hours. search: '| from datamodel Email.All_Email | search src_user=$src_user$' diff --git a/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml b/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml index 22da000f97..d1f48ff599 100644 --- a/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml +++ b/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-09-13' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search allows you to gather more context around a notable which has detected a new device connecting to your network. Use this search to determine the first and last occurrences of the suspicious device attempting to connect with diff --git a/deprecated/investigations/get_history_of_email_sources.yml b/deprecated/investigations/get_history_of_email_sources.yml index 6b5b7d83af..8b03896433 100644 --- a/deprecated/investigations/get_history_of_email_sources.yml +++ b/deprecated/investigations/get_history_of_email_sources.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-02-21' author: Rico Valdez, Splunk type: Investigation -status: deprecated +status: removed description: This search returns a list of all email sources seen in the 48 hours prior to the notable event to 24 hours after, and the number of emails from each source. diff --git a/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml b/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml index 42405d395a..55a7a805d3 100644 --- a/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml +++ b/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml @@ -4,7 +4,7 @@ version: 2 date: '2017-09-12' author: David Dorsey, Splunk type: Investigation -status: deprecated +status: removed description: This search allows you to retrieve any modifications to logon rights associated with a specific host. search: '`wineventlog_security` (signature_id=4718 OR signature_id=4717) dest=$dest$ diff --git a/deprecated/investigations/get_logon_rights_modifications_for_user.yml b/deprecated/investigations/get_logon_rights_modifications_for_user.yml index 10d81579af..5ef3f59e75 100644 --- a/deprecated/investigations/get_logon_rights_modifications_for_user.yml +++ b/deprecated/investigations/get_logon_rights_modifications_for_user.yml @@ -4,7 +4,7 @@ version: 2 date: '2019-02-27' author: David Dorsey, Splunk type: Investigation -status: deprecated +status: removed description: This search allows you to retrieve any modifications to logon rights for a specific user account. search: '`wineventlog_security` (signature_id=4718 OR signature_id=4717) user=$user$ diff --git a/deprecated/investigations/get_notable_history.yml b/deprecated/investigations/get_notable_history.yml index 0263940a86..fdd158e5a3 100644 --- a/deprecated/investigations/get_notable_history.yml +++ b/deprecated/investigations/get_notable_history.yml @@ -4,7 +4,7 @@ version: 2 date: '2017-09-20' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search queries the notable index and returns all the Notable Events for the particular destination host, giving the analyst an overview of the incidents that may have occurred with the host under investigation. diff --git a/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml b/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml index eb30eaa867..3ba36659b0 100644 --- a/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml +++ b/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-06-14' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: 'This search returns the information of the users that sent emails to the accounts controlled by the Hidden Cobra Threat Actors: specifically to `misswang8107@gmail.com`, and from `redhat@gmail.com`.' diff --git a/deprecated/investigations/get_parent_process_info.yml b/deprecated/investigations/get_parent_process_info.yml index 54a97aea2b..e42faa26af 100644 --- a/deprecated/investigations/get_parent_process_info.yml +++ b/deprecated/investigations/get_parent_process_info.yml @@ -4,7 +4,7 @@ version: 2 date: '2019-02-28' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest diff --git a/deprecated/investigations/get_process_file_activity.yml b/deprecated/investigations/get_process_file_activity.yml index 04450db005..88dc720dac 100644 --- a/deprecated/investigations/get_process_file_activity.yml +++ b/deprecated/investigations/get_process_file_activity.yml @@ -4,7 +4,7 @@ version: 2 date: '2019-11-06' author: David Dorsey, Splunk type: Investigation -status: deprecated +status: removed description: This search returns the file activity for a specific process on a specific endpoint search: '| tstats `security_content_summariesonly` values(Filesystem.file_name) as diff --git a/deprecated/investigations/get_process_info.yml b/deprecated/investigations/get_process_info.yml index c5e6c10d84..8d03f447e0 100644 --- a/deprecated/investigations/get_process_info.yml +++ b/deprecated/investigations/get_process_info.yml @@ -4,7 +4,7 @@ version: 2 date: '2019-04-01' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search queries the Endpoint data model to give you details about the process running on a host which is under investigation. To gather the process info, enter the values for the process name in question and the destination IP address. diff --git a/deprecated/investigations/get_process_information_for_port_activity.yml b/deprecated/investigations/get_process_information_for_port_activity.yml index de14541ff3..4b0ae45559 100644 --- a/deprecated/investigations/get_process_information_for_port_activity.yml +++ b/deprecated/investigations/get_process_information_for_port_activity.yml @@ -4,7 +4,7 @@ version: 2 date: '2019-04-01' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search will return information about the process associated with observed network traffic to a specific destination port from a specific host. search: '| tstats `security_content_summariesonly` count min(_time) max(_time) as diff --git a/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml b/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml index 09b50690c7..86e2ad11be 100644 --- a/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml +++ b/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml @@ -4,7 +4,7 @@ version: 2 date: '2019-04-01' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: While investigating, an analyst will want to know what process and parent_process is responsible for generating suspicious DNS traffic. Use the following search and enter the value of `dest` in the search to get specific details on the process responsible diff --git a/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml b/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml index e066466664..166013dd2a 100644 --- a/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml +++ b/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-10-23' author: Rico Valdez, Splunk type: Investigation -status: deprecated +status: removed description: This search queries Sysmon WMI events for the host of interest. search: '`sysmon` EventCode>18 EventCode<22 | rename host as dest | search dest=$dest$| table _time, dest, user, Name, Operation, EventType, Type, Query, Consumer, Filter' diff --git a/deprecated/investigations/get_web_session_information_via_session_id.yml b/deprecated/investigations/get_web_session_information_via_session_id.yml index 955b678802..5952077391 100644 --- a/deprecated/investigations/get_web_session_information_via_session_id.yml +++ b/deprecated/investigations/get_web_session_information_via_session_id.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-10-08' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search helps an analyst investigate a notable event to find out more about a specific web session. The search looks for a specific web session ID in the HTTP web traffic and outputs the URL and user agents, grouped by source IP diff --git a/deprecated/investigations/investigate_aws_activities_via_region_name.yml b/deprecated/investigations/investigate_aws_activities_via_region_name.yml index d1f8bd0bbb..335daad51e 100644 --- a/deprecated/investigations/investigate_aws_activities_via_region_name.yml +++ b/deprecated/investigations/investigate_aws_activities_via_region_name.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-02-09' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search lists all the user activities logged by CloudTrail for a specific region in question and will create a table of the values of parameters requested, the type of the event and the response from the AWS API by each user diff --git a/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml b/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml index 84f4231bcd..d0932da712 100644 --- a/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml +++ b/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml @@ -4,7 +4,7 @@ version: 2 date: '2024-09-24' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search lists all the logged CloudTrail activities by a specific user and will create a table containing the source of the user, the region of the activity, the name and type of the event, the action taken, and the user's identity diff --git a/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml b/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml index 929d971fd4..fbd88dcfb6 100644 --- a/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml +++ b/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-12-10' author: Patrick Bareiss, Splunk type: Investigation -status: deprecated +status: removed description: This search returns failed logins to multiple destinations by user. search: '| tstats count `security_content_summariesonly` earliest(_time) as first_login latest(_time) as last_login dc(Authentication.dest) AS distinct_count_dest values(Authentication.dest) diff --git a/deprecated/investigations/investigate_network_traffic_from_src_ip.yml b/deprecated/investigations/investigate_network_traffic_from_src_ip.yml index ba7875b78f..3fc46d2dbe 100644 --- a/deprecated/investigations/investigate_network_traffic_from_src_ip.yml +++ b/deprecated/investigations/investigate_network_traffic_from_src_ip.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-06-15' author: David Dorsey, Splunk type: Investigation -status: deprecated +status: removed description: This search allows you to find all the network traffic from a specific IP address. search: '| from datamodel Network_Traffic.All_Traffic | search src_ip=$src_ip$' diff --git a/deprecated/investigations/investigate_okta_activity_by_app.yml b/deprecated/investigations/investigate_okta_activity_by_app.yml index 9c9111a9aa..40a8e95697 100644 --- a/deprecated/investigations/investigate_okta_activity_by_app.yml +++ b/deprecated/investigations/investigate_okta_activity_by_app.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-04-02' author: Rico Valdez, Splunk type: Investigation -status: deprecated +status: removed description: This search returns all okta events associated with a specific app search: '`okta` app=$app$ | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city diff --git a/deprecated/investigations/investigate_okta_activity_by_ip_address.yml b/deprecated/investigations/investigate_okta_activity_by_ip_address.yml index a3a945fed5..0f5fbab9f9 100644 --- a/deprecated/investigations/investigate_okta_activity_by_ip_address.yml +++ b/deprecated/investigations/investigate_okta_activity_by_ip_address.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-04-02' author: Rico Valdez, Splunk type: Investigation -status: deprecated +status: removed description: This search returns all okta events from a specific IP address. search: '`okta` src_ip={src_ip} | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city diff --git a/deprecated/investigations/investigate_pass_the_hash_attempts.yml b/deprecated/investigations/investigate_pass_the_hash_attempts.yml index e4a495f05f..5f62609ac9 100644 --- a/deprecated/investigations/investigate_pass_the_hash_attempts.yml +++ b/deprecated/investigations/investigate_pass_the_hash_attempts.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-12-10' author: Patrick Bareiss, Splunk type: Investigation -status: deprecated +status: removed description: This search hunts for dumped NTLM hashes used for pass the hash. search: '`wineventlog_security` EventCode=4624 Logon_Type=9 AuthenticationPackageName=Negotiate | stats count earliest(_time) as first_login latest(_time) as last_login by src_user diff --git a/deprecated/investigations/investigate_pass_the_ticket_attempts.yml b/deprecated/investigations/investigate_pass_the_ticket_attempts.yml index 3e971419a5..e341b89e92 100644 --- a/deprecated/investigations/investigate_pass_the_ticket_attempts.yml +++ b/deprecated/investigations/investigate_pass_the_ticket_attempts.yml @@ -4,7 +4,7 @@ version: 2 date: '2024-09-24' author: Patrick Bareiss, Splunk type: Investigation -status: deprecated +status: removed description: This search hunts for dumped kerberos ticket from LSASS memory. search: '`wineventlog_security` EventCode=4768 OR EventCode=4769 | rex field=user "(?[^\@]+)" | stats count BY new_user, dest, EventCode | stats max(count) diff --git a/deprecated/investigations/investigate_previous_unseen_user.yml b/deprecated/investigations/investigate_previous_unseen_user.yml index 1e70b07b01..9b9e865fc4 100644 --- a/deprecated/investigations/investigate_previous_unseen_user.yml +++ b/deprecated/investigations/investigate_previous_unseen_user.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-12-10' author: Patrick Bareiss, Splunk type: Investigation -status: deprecated +status: removed description: This search returns previous unseen user, which didn't log in for 30 days. search: '| tstats count `security_content_summariesonly` earliest(_time) as first_login diff --git a/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml b/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml index b5c02044c6..5f4109c67c 100644 --- a/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml +++ b/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml @@ -4,7 +4,7 @@ version: 2 date: '2024-09-24' author: Jose Hernandez, Splunk type: Investigation -status: deprecated +status: removed description: This search returns the source, destination, and user for all successful remote-desktop authentications. A successful authentication after a brute-force attack on a destination machine is suspicious behavior. diff --git a/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml b/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml index d2d83857e1..6aa7a6cefd 100644 --- a/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml +++ b/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-10-20' author: Bhavin Patel, Splunk type: Investigation -status: deprecated +status: removed description: This search helps an analyst investigate a notable event related to a potential Apache Struts exploitation. To investigate, we will want to isolate and analyze the "payload" or the commands that were passed to the vulnerable hosts by diff --git a/deprecated/investigations/investigate_user_activities_in_okta.yml b/deprecated/investigations/investigate_user_activities_in_okta.yml index 522e019822..cb133eb7e5 100644 --- a/deprecated/investigations/investigate_user_activities_in_okta.yml +++ b/deprecated/investigations/investigate_user_activities_in_okta.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-04-02' author: Rico Valdez, Splunk type: Investigation -status: deprecated +status: removed description: This search returns all okta events by a specific user search: '`okta` user=$user$ | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city diff --git a/deprecated/investigations/investigate_web_posts_from_src.yml b/deprecated/investigations/investigate_web_posts_from_src.yml index 89d2b23432..0ca5d92202 100644 --- a/deprecated/investigations/investigate_web_posts_from_src.yml +++ b/deprecated/investigations/investigate_web_posts_from_src.yml @@ -4,7 +4,7 @@ version: 2 date: '2024-09-24' author: Jose Hernandez, Splunk type: Investigation -status: deprecated +status: removed description: This investigative search retrieves POST requests from a specified source IP or hostname. Identifying the POST requests, as well as their associated destination URLs and user agent(s), may help you scope and characterize the suspicious traffic. diff --git a/deprecated/stories/aws_cryptomining.yml b/deprecated/stories/aws_cryptomining.yml index abd30eff4d..67599b5632 100644 --- a/deprecated/stories/aws_cryptomining.yml +++ b/deprecated/stories/aws_cryptomining.yml @@ -3,7 +3,7 @@ id: ced74200-8465-4bc3-bd2c-9a782eec6750 version: 1 date: '2018-03-08' author: David Dorsey, Splunk -status: deprecated +status: removed description: Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or EC2 instances started by previously unseen users are diff --git a/deprecated/stories/aws_suspicious_provisioning_activities.yml b/deprecated/stories/aws_suspicious_provisioning_activities.yml index c5403b49fa..d6d7def438 100644 --- a/deprecated/stories/aws_suspicious_provisioning_activities.yml +++ b/deprecated/stories/aws_suspicious_provisioning_activities.yml @@ -3,7 +3,7 @@ id: 3338b567-3804-4261-9889-cf0ca4753c7f version: 1 date: '2018-03-16' author: David Dorsey, Splunk -status: deprecated +status: removed description: Monitor your AWS provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your network. diff --git a/deprecated/stories/common_phishing_frameworks.yml b/deprecated/stories/common_phishing_frameworks.yml index 055ff6b43a..6c8f0279d1 100644 --- a/deprecated/stories/common_phishing_frameworks.yml +++ b/deprecated/stories/common_phishing_frameworks.yml @@ -3,7 +3,7 @@ id: 9a64ab44-9214-4639-8163-7eaa2621bd61 version: 2 date: '2024-09-24' author: Splunk Research Team, Splunk -status: deprecated +status: removed description: 'Detect DNS and web requests to fake websites generated by the EvilGinx2 toolkit. These websites are designed to fool unwitting users who have clicked on a malicious link in a phishing email.' diff --git a/deprecated/stories/container_implantation_monitoring_and_investigation.yml b/deprecated/stories/container_implantation_monitoring_and_investigation.yml index 53ee1b98a8..8fc04b5754 100644 --- a/deprecated/stories/container_implantation_monitoring_and_investigation.yml +++ b/deprecated/stories/container_implantation_monitoring_and_investigation.yml @@ -3,7 +3,7 @@ id: aa0e28b1-0521-4b6f-9d2a-7b87e34af246 version: 1 date: '2020-02-20' author: Rod Soto, Rico Valdez, Splunk -status: deprecated +status: removed description: Use the searches in this story to monitor your Kubernetes registry repositories for upload, and deployment of potentially vulnerable, backdoor, or implanted containers. These searches provide information on source users, destination path, container diff --git a/deprecated/stories/host_redirection.yml b/deprecated/stories/host_redirection.yml index 90953fb738..8a3c52c671 100644 --- a/deprecated/stories/host_redirection.yml +++ b/deprecated/stories/host_redirection.yml @@ -3,7 +3,7 @@ id: 2e8948a5-5239-406b-b56b-6c50fe268af4 version: 1 date: '2017-09-14' author: Rico Valdez, Splunk -status: deprecated +status: removed description: Detect evidence of tactics used to redirect traffic from a host to a destination other than the one intended--potentially one that is part of an adversary's attack infrastructure. An example is redirecting communications regarding patches diff --git a/deprecated/stories/kubernetes_sensitive_role_activity.yml b/deprecated/stories/kubernetes_sensitive_role_activity.yml index 735eb620fa..3e4aea5653 100644 --- a/deprecated/stories/kubernetes_sensitive_role_activity.yml +++ b/deprecated/stories/kubernetes_sensitive_role_activity.yml @@ -3,7 +3,7 @@ id: 8b3984d2-17b6-47e9-ba43-a3376e70fdcc version: 1 date: '2020-05-20' author: Rod Soto, Splunk -status: deprecated +status: removed description: This story addresses detection and response around Sensitive Role usage within a Kubernetes clusters against cluster resources and namespaces. narrative: Kubernetes is the most used container orchestration platform, this orchestration diff --git a/deprecated/stories/lateral_movement.yml b/deprecated/stories/lateral_movement.yml index 20c7ee6a69..6fbf027832 100644 --- a/deprecated/stories/lateral_movement.yml +++ b/deprecated/stories/lateral_movement.yml @@ -3,7 +3,7 @@ id: 399d65dc-1f08-499b-a259-abd9051f38ad version: 3 date: '2024-09-24' author: David Dorsey, Splunk -status: deprecated +status: removed description: "DEPRECATED IN FAVOR OF ACTIVE DIRECTORY LATERAL MOVEMENT. Detect and investigate tactics, techniques, and procedures around how attackers move laterally within the enterprise. Because lateral movement can expose the adversary to detection, it should be an important focus for security analysts." narrative: "Once attackers gain a foothold within an enterprise, they will seek to expand their accesses and leverage techniques that facilitate lateral movement. Attackers will often spend quite a bit of time and effort moving laterally. Because lateral movement renders an attacker the most vulnerable to detection, it's an excellent focus for detection and investigation. Indications of lateral movement can include the abuse of system utilities (such as `psexec.exe`), unauthorized use of remote desktop services, `file/admin$` shares, WMI, PowerShell, pass-the-hash, or the abuse of scheduled tasks. Organizations must be extra vigilant in detecting lateral movement techniques and look for suspicious activity in and around high-value strategic network assets, such as Active Directory, which are often considered the primary target or \"crown jewels\" to a persistent threat actor. An adversary can use lateral movement for multiple purposes, including remote execution of tools, pivoting to additional systems, obtaining access to specific information or files, access to additional credentials, exfiltrating data, or delivering a secondary effect. Adversaries may use legitimate credentials alongside inherent network and operating-system functionality to remotely connect to other systems and remain under the radar of network defenders. If there is evidence of lateral movement, it is imperative for analysts to collect evidence of the associated offending hosts. For example, an attacker might leverage host A to gain access to host B. From there, the attacker may try to move laterally to host C. In this example, the analyst should gather as much information as possible from all three hosts. It is also important to collect authentication logs for each host, to ensure that the offending accounts are well-documented. Analysts should account for all processes to ensure that the attackers did not install unauthorized software." references: diff --git a/deprecated/stories/monitor_backup_solution.yml b/deprecated/stories/monitor_backup_solution.yml index c3f2dc7a32..3b0074346d 100644 --- a/deprecated/stories/monitor_backup_solution.yml +++ b/deprecated/stories/monitor_backup_solution.yml @@ -3,7 +3,7 @@ id: abe807c7-1eb6-4304-ac32-6e7aacdb891d version: 1 date: '2017-09-12' author: David Dorsey, Splunk -status: deprecated +status: removed description: Address common concerns when monitoring your backup processes. These searches can help you reduce risks from ransomware, device theft, or denial of physical access to a host by backing up data on endpoints. diff --git a/deprecated/stories/monitor_for_unauthorized_software.yml b/deprecated/stories/monitor_for_unauthorized_software.yml index a9e7d9688d..62b812f61c 100644 --- a/deprecated/stories/monitor_for_unauthorized_software.yml +++ b/deprecated/stories/monitor_for_unauthorized_software.yml @@ -3,7 +3,7 @@ id: 8892a655-6205-43f7-abba-06460e38c8ae version: 2 date: '2024-09-24' author: David Dorsey, Splunk -status: deprecated +status: removed description: 'Identify and investigate prohibited/unauthorized software or processes that may be concealing malicious behavior within your environment.' narrative: 'It is critical to identify unauthorized software and processes running diff --git a/deprecated/stories/office_365_detections.yml b/deprecated/stories/office_365_detections.yml index d2fb3d09b7..00b0764a96 100644 --- a/deprecated/stories/office_365_detections.yml +++ b/deprecated/stories/office_365_detections.yml @@ -3,7 +3,7 @@ id: 1a51dd71-effc-48b2-abc4-3e9cdb61e5b9 version: 2 date: '2020-12-16' author: Patrick Bareiss, Mauricio Velazco, Splunk -status: deprecated +status: removed description: Monitor for activities and anomalies indicative of potential threats within Office 365 environments. narrative: Office 365 (O365) is Microsoft's cloud-based suite of productivity tools, encompassing email, collaboration platforms, and office applications, all integrated with Azure Active Directory for identity and access management. Given the centralized storage of sensitive organizational data within O365 and its widespread adoption, it has become a focal point for cybersecurity efforts. The platform's complexity, combined with its ubiquity, makes it both a valuable asset and a prime target for potential threats. As O365's importance grows, it increasingly becomes a target for attackers seeking to exploit organizational data and systems. Security teams should prioritize monitoring O365 not just because of the sensitive data it often holds, but also due to the myriad ways the platform can be exploited. Understanding and monitoring O365's security landscape is crucial for organizations to detect, respond to, and mitigate potential threats in a timely manner. references: diff --git a/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml b/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml index 3b0bbf9c8d..baa7d5b14c 100644 --- a/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml +++ b/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml @@ -3,7 +3,7 @@ id: 6d3306f6-bb2b-4219-8609-8efad64032f2 version: 1 date: '2018-01-08' author: David Dorsey, Splunk -status: deprecated +status: removed description: Assess and mitigate your systems' vulnerability to Spectre and Meltdown exploitation with the searches in this Analytic Story. narrative: Meltdown and Spectre exploit critical vulnerabilities in modern CPUs that diff --git a/deprecated/stories/suspicious_aws_ec2_activities.yml b/deprecated/stories/suspicious_aws_ec2_activities.yml index 89b5348253..06649b6670 100644 --- a/deprecated/stories/suspicious_aws_ec2_activities.yml +++ b/deprecated/stories/suspicious_aws_ec2_activities.yml @@ -3,7 +3,7 @@ id: 2e8948a5-5239-406b-b56b-6c50f1268af3 version: 1 date: '2018-02-09' author: Bhavin Patel, Splunk -status: deprecated +status: removed description: Use the searches in this Analytic Story to monitor your AWS EC2 instances for evidence of anomalous activity and suspicious behaviors, such as EC2 instances that originate from unusual locations or those launched by previously unseen users diff --git a/deprecated/stories/unusual_aws_ec2_modifications.yml b/deprecated/stories/unusual_aws_ec2_modifications.yml index f0f1fc4b54..98eb84e135 100644 --- a/deprecated/stories/unusual_aws_ec2_modifications.yml +++ b/deprecated/stories/unusual_aws_ec2_modifications.yml @@ -3,7 +3,7 @@ id: 73de57ef-0dfc-411f-b1e7-fa24428aeae0 version: 1 date: '2018-04-09' author: David Dorsey, Splunk -status: deprecated +status: removed description: Identify unusual changes to your AWS EC2 instances that may indicate malicious activity. Modifications to your EC2 instances by previously unseen users is an example of an activity that may warrant further investigation. diff --git a/deprecated/stories/web_fraud_detection.yml b/deprecated/stories/web_fraud_detection.yml index 81d8ee3448..7e066b1e4c 100644 --- a/deprecated/stories/web_fraud_detection.yml +++ b/deprecated/stories/web_fraud_detection.yml @@ -3,7 +3,7 @@ id: 18bb45b9-7684-45c6-9e97-1fdd0d98c0a7 version: 1 date: '2018-10-08' author: Jim Apger, Splunk -status: deprecated +status: removed description: Monitor your environment for activity consistent with common attack techniques bad actors use when attempting to compromise web servers or other web-related assets. narrative: 'The Federal Bureau of Investigations (FBI) defines Internet fraud as the From 0d2d727083b3b7377744a9ddac21b213ed2aa556 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Tue, 18 Mar 2025 13:39:39 -0700 Subject: [PATCH 62/67] updating replace --- deprecated/deprecation_mapping.YML | 9 +-------- 1 file changed, 1 insertion(+), 8 deletions(-) diff --git a/deprecated/deprecation_mapping.YML b/deprecated/deprecation_mapping.YML index e681484193..e070b62001 100644 --- a/deprecated/deprecation_mapping.YML +++ b/deprecated/deprecation_mapping.YML @@ -158,14 +158,7 @@ detections: - deprecated_content: Remote System Discovery with Net deprecated_in_version: 5.2.0 reason: "This analytic was focusing on 2 separate and unrelated type of threats - or actions. It was split into other analytics, namely:\r\n\r\nWindows Network - Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277\r\nWindows Sensitive - Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a" - replacement_content: - - Windows Network Share Interaction With Net - - deprecated_content: Remote System Discovery with Net - deprecated_in_version: 5.2.0 - reason: Detection deprecated as it no longer effectively identifies the intended malicious activity + or actions. PLease use the replacement content" replacement_content: - Windows Sensitive Group Discovery With Net - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers From b1d1ae90d9b5620481dade9ce1b2e74cb124327a Mon Sep 17 00:00:00 2001 From: Eric Date: Tue, 18 Mar 2025 14:14:37 -0700 Subject: [PATCH 63/67] rename deprecated directory to removed --- .../baselines/add_prohibited_processes_to_enterprise_security.yml | 0 .../baselines/baseline_of_api_calls_per_user_arn.yml | 0 ...aseline_of_excessive_aws_instances_launched_by_user___mltk.yml | 0 ...eline_of_excessive_aws_instances_terminated_by_user___mltk.yml | 0 {deprecated => removed}/baselines/monitor_successful_backups.yml | 0 .../baselines/monitor_unsuccessful_backups.yml | 0 .../previously_seen_api_call_per_user_roles_in_cloudtrail.yml | 0 .../previously_seen_aws_provisioning_activity_sources.yml | 0 {deprecated => removed}/baselines/previously_seen_aws_regions.yml | 0 {deprecated => removed}/baselines/previously_seen_ec2_amis.yml | 0 .../baselines/previously_seen_ec2_instance_types.yml | 0 .../baselines/previously_seen_ec2_launches_by_user.yml | 0 .../baselines/previously_seen_ec2_modifications_by_user.yml | 0 .../baselines/previously_seen_users_in_cloudtrail.yml | 0 .../systems_ready_for_spectre_meltdown_windows_patch.yml | 0 .../baselines/update_previously_seen_users_in_cloudtrail.yml | 0 {deprecated => removed}/deprecation_mapping.YML | 0 .../detections/abnormally_high_aws_instances_launched_by_user.yml | 0 .../abnormally_high_aws_instances_launched_by_user___mltk.yml | 0 .../abnormally_high_aws_instances_terminated_by_user.yml | 0 .../abnormally_high_aws_instances_terminated_by_user___mltk.yml | 0 .../detections/account_discovery_with_net_app.yml | 0 {deprecated => removed}/detections/asl_aws_createaccesskey.yml | 0 .../detections/asl_aws_excessive_security_scanning.yml | 0 .../detections/asl_aws_password_policy_changes.yml | 0 .../detections/attempt_to_stop_security_service.yml | 0 .../attempted_credential_dump_from_registry_via_reg_exe.yml | 0 .../aws_cloud_provisioning_from_previously_unseen_city.yml | 0 .../aws_cloud_provisioning_from_previously_unseen_country.yml | 0 .../aws_cloud_provisioning_from_previously_unseen_ip_address.yml | 0 .../aws_cloud_provisioning_from_previously_unseen_region.yml | 0 .../aws_eks_kubernetes_cluster_sensitive_object_access.yml | 0 .../detections/change_default_file_association.yml | 0 .../detections/clients_connecting_to_multiple_dns_servers.yml | 0 .../detections/cloud_network_access_control_list_deleted.yml | 0 .../detections/cmdline_tool_not_executed_in_cmd_shell.yml | 0 .../detections/correlation_by_repository_and_risk.yml | 0 .../detections/correlation_by_user_and_risk.yml | 0 .../detections/create_local_admin_accounts_using_net_exe.yml | 0 {deprecated => removed}/detections/deleting_of_net_users.yml | 0 .../detect_activity_related_to_pass_the_hash_attacks.yml | 0 .../detections/detect_api_activity_from_users_without_mfa.yml | 0 .../detect_aws_api_activities_from_unapproved_accounts.yml | 0 .../detections/detect_critical_alerts_from_security_tools.yml | 0 ...detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml | 0 .../detections/detect_long_dns_txt_record_response.yml | 0 .../detections/detect_mimikatz_using_loaded_images.yml | 0 .../detect_mimikatz_via_powershell_and_eventcode_4703.yml | 0 .../detections/detect_new_api_calls_from_user_roles.yml | 0 .../detections/detect_new_user_aws_console_login.yml | 0 ..._processes_used_for_system_network_configuration_discovery.yml | 0 .../detections/detect_spike_in_aws_api_activity.yml | 0 .../detections/detect_spike_in_network_acl_activity.yml | 0 .../detections/detect_spike_in_security_group_activity.yml | 0 .../detections/detect_usb_device_insertion.yml | 0 .../detections/detect_web_traffic_to_dynamic_domain_providers.yml | 0 .../detections/detect_webshell_exploit_behavior.yml | 0 {deprecated => removed}/detections/detection_of_dns_tunnels.yml | 0 {deprecated => removed}/detections/disabling_net_user_account.yml | 0 .../dns_query_requests_resolved_by_unauthorized_dns_servers.yml | 0 {deprecated => removed}/detections/dns_record_changed.yml | 0 .../detections/domain_account_discovery_with_net_app.yml | 0 .../detections/domain_group_discovery_with_net.yml | 0 .../detections/dump_lsass_via_procdump_rename.yml | 0 .../ec2_instance_modified_with_previously_unseen_user.yml | 0 .../ec2_instance_started_in_previously_unseen_region.yml | 0 .../ec2_instance_started_with_previously_unseen_ami.yml | 0 .../ec2_instance_started_with_previously_unseen_instance_type.yml | 0 .../ec2_instance_started_with_previously_unseen_user.yml | 0 .../detections/elevated_group_discovery_with_net.yml | 0 {deprecated => removed}/detections/excel_spawning_powershell.yml | 0 .../detections/excel_spawning_windows_script_host.yml | 0 .../detections/excessive_service_stop_attempt.yml | 0 {deprecated => removed}/detections/excessive_usage_of_net_app.yml | 0 .../detections/execution_of_file_with_spaces_before_extension.yml | 0 .../extended_period_without_successful_netbackup_backups.yml | 0 .../detections/extraction_of_registry_hives.yml | 0 .../detections/first_time_seen_command_line_argument.yml | 0 .../gcp_detect_accounts_with_high_risk_roles_by_project.yml | 0 .../gcp_detect_high_risk_permissions_by_resource_and_account.yml | 0 .../detections/gcp_detect_oauth_token_abuse.yml | 0 .../detections/gcp_kubernetes_cluster_scan_detection.yml | 0 {deprecated => removed}/detections/identify_new_user_accounts.yml | 0 .../kubernetes_aws_detect_most_active_service_accounts_by_pod.yml | 0 .../kubernetes_aws_detect_rbac_authorization_by_account.yml | 0 .../detections/kubernetes_aws_detect_sensitive_role_access.yml | 0 ...netes_aws_detect_service_accounts_forbidden_failure_access.yml | 0 .../kubernetes_azure_active_service_accounts_by_pod_namespace.yml | 0 .../kubernetes_azure_detect_rbac_authorization_by_account.yml | 0 .../kubernetes_azure_detect_sensitive_object_access.yml | 0 .../detections/kubernetes_azure_detect_sensitive_role_access.yml | 0 ...tes_azure_detect_service_accounts_forbidden_failure_access.yml | 0 .../kubernetes_azure_detect_suspicious_kubectl_calls.yml | 0 .../detections/kubernetes_azure_pod_scan_fingerprint.yml | 0 .../detections/kubernetes_azure_scan_fingerprint.yml | 0 .../kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml | 0 .../kubernetes_gcp_detect_rbac_authorizations_by_account.yml | 0 .../detections/kubernetes_gcp_detect_sensitive_object_access.yml | 0 .../detections/kubernetes_gcp_detect_sensitive_role_access.yml | 0 ...netes_gcp_detect_service_accounts_forbidden_failure_access.yml | 0 .../detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml | 0 .../detections/linux_auditd_find_private_keys.yml | 0 .../detections/local_account_discovery_with_net.yml | 0 .../detections/monitor_dns_for_brand_abuse.yml | 0 .../detections/mshtml_module_load_in_office_product.yml | 0 ...tiple_okta_users_with_invalid_credentials_from_the_same_ip.yml | 0 {deprecated => removed}/detections/net_localgroup_discovery.yml | 0 .../detections/network_connection_discovery_with_net.yml | 0 .../detections/o365_suspicious_admin_email_forwarding.yml | 0 .../detections/o365_suspicious_rights_delegation.yml | 0 .../detections/o365_suspicious_user_email_forwarding.yml | 0 .../detections/office_application_drop_executable.yml | 0 .../detections/office_application_spawn_regsvr32_process.yml | 0 .../detections/office_application_spawn_rundll32_process.yml | 0 .../detections/office_document_creating_schedule_task.yml | 0 .../detections/office_document_executing_macro_code.yml | 0 .../office_document_spawned_child_process_to_download.yml | 0 .../detections/office_product_spawn_cmd_process.yml | 0 .../detections/office_product_spawning_bitsadmin.yml | 0 .../detections/office_product_spawning_certutil.yml | 0 .../detections/office_product_spawning_mshta.yml | 0 .../detections/office_product_spawning_rundll32_with_no_dll.yml | 0 .../detections/office_product_spawning_windows_script_host.yml | 0 .../detections/office_product_spawning_wmic.yml | 0 .../detections/office_product_writing_cab_or_inf.yml | 0 {deprecated => removed}/detections/office_spawning_control.yml | 0 {deprecated => removed}/detections/okta_account_locked_out.yml | 0 .../detections/okta_account_lockout_events.yml | 0 {deprecated => removed}/detections/okta_failed_sso_attempts.yml | 0 .../okta_threatinsight_login_failure_with_high_unknown_users.yml | 0 .../okta_threatinsight_suspected_passwordspray_attack.yml | 0 .../detections/okta_two_or_more_rejected_okta_pushes.yml | 0 .../detections/osquery_pack___coldroot_detection.yml | 0 .../detections/password_policy_discovery_with_net.yml | 0 {deprecated => removed}/detections/processes_created_by_netsh.yml | 0 .../detections/prohibited_software_on_endpoint.yml | 0 .../reg_exe_used_to_hide_files_directories_via_registry_keys.yml | 0 .../detections/remote_registry_key_modifications.yml | 0 .../detections/remote_system_discovery_with_net.yml | 0 .../detections/scheduled_tasks_used_in_badrabbit_ransomware.yml | 0 .../detections/spectre_and_meltdown_vulnerable_systems.yml | 0 .../detections/suspicious_changes_to_file_associations.yml | 0 .../detections/suspicious_email___uba_anomaly.yml | 0 {deprecated => removed}/detections/suspicious_file_write.yml | 0 .../detections/suspicious_powershell_command_line_arguments.yml | 0 {deprecated => removed}/detections/suspicious_rundll32_rename.yml | 0 .../detections/suspicious_writes_to_system_volume_information.yml | 0 .../detections/uncommon_processes_on_endpoint.yml | 0 .../detections/unsigned_image_loaded_by_lsass.yml | 0 .../detections/unsuccessful_netbackup_backups.yml | 0 .../detections/web_fraud___account_harvesting.yml | 0 .../detections/web_fraud___anomalous_user_clickspeed.yml | 0 .../detections/web_fraud___password_sharing_across_accounts.yml | 0 .../detections/windows_command_shell_fetch_env_variables.yml | 0 .../detections/windows_connhost_exe_started_forcefully.yml | 0 .../detections/windows_dll_search_order_hijacking_hunt.yml | 0 .../detections/windows_hosts_file_modification.yml | 0 .../detections/windows_lateral_tool_transfer_remcom.yml | 0 .../detections/windows_modify_registry_reg_restore.yml | 0 .../detections/windows_msiexec_with_network_connections.yml | 0 .../detections/windows_network_share_interaction_with_net.yml | 0 .../detections/windows_office_product_spawning_msdt.yml | 0 .../detections/windows_query_registry_reg_save.yml | 0 .../windows_service_stop_via_net__and_sc_application.yml | 0 .../windows_valid_account_with_never_expires_password.yml | 0 {deprecated => removed}/detections/winword_spawning_cmd.yml | 0 .../detections/winword_spawning_powershell.yml | 0 .../detections/winword_spawning_windows_script_host.yml | 0 .../investigations/all_backup_logs_for_host.yml | 0 .../investigations/amazon_eks_kubernetes_activity_by_src_ip.yml | 0 .../aws_investigate_security_hub_alerts_by_dest.yml | 0 .../aws_investigate_user_activities_by_accesskeyid.yml | 0 .../investigations/aws_investigate_user_activities_by_arn.yml | 0 .../investigations/aws_network_acl_details_from_id.yml | 0 .../aws_network_interface_details_via_resourceid.yml | 0 .../investigations/aws_s3_bucket_details_via_bucketname.yml | 0 .../investigations/gcp_kubernetes_activity_by_src_ip.yml | 0 .../investigations/get_all_aws_activity_from_city.yml | 0 .../investigations/get_all_aws_activity_from_country.yml | 0 .../investigations/get_all_aws_activity_from_ip_address.yml | 0 .../investigations/get_all_aws_activity_from_region.yml | 0 .../investigations/get_backup_logs_for_endpoint.yml | 0 .../investigations/get_certificate_logs_for_a_domain.yml | 0 .../investigations/get_dns_server_history_for_a_host.yml | 0 {deprecated => removed}/investigations/get_dns_traffic_ratio.yml | 0 .../investigations/get_ec2_instance_details_by_instanceid.yml | 0 {deprecated => removed}/investigations/get_ec2_launch_details.yml | 0 {deprecated => removed}/investigations/get_email_info.yml | 0 .../investigations/get_emails_from_specific_sender.yml | 0 .../get_first_occurrence_and_last_occurrence_of_a_mac_address.yml | 0 .../investigations/get_history_of_email_sources.yml | 0 .../get_logon_rights_modifications_for_endpoint.yml | 0 .../investigations/get_logon_rights_modifications_for_user.yml | 0 {deprecated => removed}/investigations/get_notable_history.yml | 0 .../get_outbound_emails_to_hidden_cobra_threat_actors.yml | 0 .../investigations/get_parent_process_info.yml | 0 .../investigations/get_process_file_activity.yml | 0 {deprecated => removed}/investigations/get_process_info.yml | 0 .../investigations/get_process_information_for_port_activity.yml | 0 .../get_process_responsible_for_the_dns_traffic.yml | 0 .../investigations/get_sysmon_wmi_activity_for_host.yml | 0 .../investigations/get_web_session_information_via_session_id.yml | 0 .../investigations/investigate_aws_activities_via_region_name.yml | 0 .../investigate_aws_user_activities_by_user_field.yml | 0 .../investigate_failed_logins_for_multiple_destinations.yml | 0 .../investigations/investigate_network_traffic_from_src_ip.yml | 0 .../investigations/investigate_okta_activity_by_app.yml | 0 .../investigations/investigate_okta_activity_by_ip_address.yml | 0 .../investigations/investigate_pass_the_hash_attempts.yml | 0 .../investigations/investigate_pass_the_ticket_attempts.yml | 0 .../investigations/investigate_previous_unseen_user.yml | 0 .../investigate_successful_remote_desktop_authentications.yml | 0 .../investigate_suspicious_strings_in_http_header.yml | 0 .../investigations/investigate_user_activities_in_okta.yml | 0 .../investigations/investigate_web_posts_from_src.yml | 0 {deprecated => removed}/stories/aws_cryptomining.yml | 0 .../stories/aws_suspicious_provisioning_activities.yml | 0 {deprecated => removed}/stories/common_phishing_frameworks.yml | 0 .../container_implantation_monitoring_and_investigation.yml | 0 {deprecated => removed}/stories/host_redirection.yml | 0 .../stories/kubernetes_sensitive_role_activity.yml | 0 {deprecated => removed}/stories/lateral_movement.yml | 0 {deprecated => removed}/stories/monitor_backup_solution.yml | 0 .../stories/monitor_for_unauthorized_software.yml | 0 {deprecated => removed}/stories/office_365_detections.yml | 0 .../stories/spectre_and_meltdown_vulnerabilities.yml | 0 {deprecated => removed}/stories/suspicious_aws_ec2_activities.yml | 0 {deprecated => removed}/stories/unusual_aws_ec2_modifications.yml | 0 {deprecated => removed}/stories/web_fraud_detection.yml | 0 229 files changed, 0 insertions(+), 0 deletions(-) rename {deprecated => removed}/baselines/add_prohibited_processes_to_enterprise_security.yml (100%) rename {deprecated => removed}/baselines/baseline_of_api_calls_per_user_arn.yml (100%) rename {deprecated => removed}/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml (100%) rename {deprecated => removed}/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml (100%) rename {deprecated => removed}/baselines/monitor_successful_backups.yml (100%) rename {deprecated => removed}/baselines/monitor_unsuccessful_backups.yml (100%) rename {deprecated => removed}/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml (100%) rename {deprecated => removed}/baselines/previously_seen_aws_provisioning_activity_sources.yml (100%) rename {deprecated => removed}/baselines/previously_seen_aws_regions.yml (100%) rename {deprecated => removed}/baselines/previously_seen_ec2_amis.yml (100%) rename {deprecated => removed}/baselines/previously_seen_ec2_instance_types.yml (100%) rename {deprecated => removed}/baselines/previously_seen_ec2_launches_by_user.yml (100%) rename {deprecated => removed}/baselines/previously_seen_ec2_modifications_by_user.yml (100%) rename {deprecated => removed}/baselines/previously_seen_users_in_cloudtrail.yml (100%) rename {deprecated => removed}/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml (100%) rename {deprecated => removed}/baselines/update_previously_seen_users_in_cloudtrail.yml (100%) rename {deprecated => removed}/deprecation_mapping.YML (100%) rename {deprecated => removed}/detections/abnormally_high_aws_instances_launched_by_user.yml (100%) rename {deprecated => removed}/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml (100%) rename {deprecated => removed}/detections/abnormally_high_aws_instances_terminated_by_user.yml (100%) rename {deprecated => removed}/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml (100%) rename {deprecated => removed}/detections/account_discovery_with_net_app.yml (100%) rename {deprecated => removed}/detections/asl_aws_createaccesskey.yml (100%) rename {deprecated => removed}/detections/asl_aws_excessive_security_scanning.yml (100%) rename {deprecated => removed}/detections/asl_aws_password_policy_changes.yml (100%) rename {deprecated => removed}/detections/attempt_to_stop_security_service.yml (100%) rename {deprecated => removed}/detections/attempted_credential_dump_from_registry_via_reg_exe.yml (100%) rename {deprecated => removed}/detections/aws_cloud_provisioning_from_previously_unseen_city.yml (100%) rename {deprecated => removed}/detections/aws_cloud_provisioning_from_previously_unseen_country.yml (100%) rename {deprecated => removed}/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml (100%) rename {deprecated => removed}/detections/aws_cloud_provisioning_from_previously_unseen_region.yml (100%) rename {deprecated => removed}/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml (100%) rename {deprecated => removed}/detections/change_default_file_association.yml (100%) rename {deprecated => removed}/detections/clients_connecting_to_multiple_dns_servers.yml (100%) rename {deprecated => removed}/detections/cloud_network_access_control_list_deleted.yml (100%) rename {deprecated => removed}/detections/cmdline_tool_not_executed_in_cmd_shell.yml (100%) rename {deprecated => removed}/detections/correlation_by_repository_and_risk.yml (100%) rename {deprecated => removed}/detections/correlation_by_user_and_risk.yml (100%) rename {deprecated => removed}/detections/create_local_admin_accounts_using_net_exe.yml (100%) rename {deprecated => removed}/detections/deleting_of_net_users.yml (100%) rename {deprecated => removed}/detections/detect_activity_related_to_pass_the_hash_attacks.yml (100%) rename {deprecated => removed}/detections/detect_api_activity_from_users_without_mfa.yml (100%) rename {deprecated => removed}/detections/detect_aws_api_activities_from_unapproved_accounts.yml (100%) rename {deprecated => removed}/detections/detect_critical_alerts_from_security_tools.yml (100%) rename {deprecated => removed}/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml (100%) rename {deprecated => removed}/detections/detect_long_dns_txt_record_response.yml (100%) rename {deprecated => removed}/detections/detect_mimikatz_using_loaded_images.yml (100%) rename {deprecated => removed}/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml (100%) rename {deprecated => removed}/detections/detect_new_api_calls_from_user_roles.yml (100%) rename {deprecated => removed}/detections/detect_new_user_aws_console_login.yml (100%) rename {deprecated => removed}/detections/detect_processes_used_for_system_network_configuration_discovery.yml (100%) rename {deprecated => removed}/detections/detect_spike_in_aws_api_activity.yml (100%) rename {deprecated => removed}/detections/detect_spike_in_network_acl_activity.yml (100%) rename {deprecated => removed}/detections/detect_spike_in_security_group_activity.yml (100%) rename {deprecated => removed}/detections/detect_usb_device_insertion.yml (100%) rename {deprecated => removed}/detections/detect_web_traffic_to_dynamic_domain_providers.yml (100%) rename {deprecated => removed}/detections/detect_webshell_exploit_behavior.yml (100%) rename {deprecated => removed}/detections/detection_of_dns_tunnels.yml (100%) rename {deprecated => removed}/detections/disabling_net_user_account.yml (100%) rename {deprecated => removed}/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml (100%) rename {deprecated => removed}/detections/dns_record_changed.yml (100%) rename {deprecated => removed}/detections/domain_account_discovery_with_net_app.yml (100%) rename {deprecated => removed}/detections/domain_group_discovery_with_net.yml (100%) rename {deprecated => removed}/detections/dump_lsass_via_procdump_rename.yml (100%) rename {deprecated => removed}/detections/ec2_instance_modified_with_previously_unseen_user.yml (100%) rename {deprecated => removed}/detections/ec2_instance_started_in_previously_unseen_region.yml (100%) rename {deprecated => removed}/detections/ec2_instance_started_with_previously_unseen_ami.yml (100%) rename {deprecated => removed}/detections/ec2_instance_started_with_previously_unseen_instance_type.yml (100%) rename {deprecated => removed}/detections/ec2_instance_started_with_previously_unseen_user.yml (100%) rename {deprecated => removed}/detections/elevated_group_discovery_with_net.yml (100%) rename {deprecated => removed}/detections/excel_spawning_powershell.yml (100%) rename {deprecated => removed}/detections/excel_spawning_windows_script_host.yml (100%) rename {deprecated => removed}/detections/excessive_service_stop_attempt.yml (100%) rename {deprecated => removed}/detections/excessive_usage_of_net_app.yml (100%) rename {deprecated => removed}/detections/execution_of_file_with_spaces_before_extension.yml (100%) rename {deprecated => removed}/detections/extended_period_without_successful_netbackup_backups.yml (100%) rename {deprecated => removed}/detections/extraction_of_registry_hives.yml (100%) rename {deprecated => removed}/detections/first_time_seen_command_line_argument.yml (100%) rename {deprecated => removed}/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml (100%) rename {deprecated => removed}/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml (100%) rename {deprecated => removed}/detections/gcp_detect_oauth_token_abuse.yml (100%) rename {deprecated => removed}/detections/gcp_kubernetes_cluster_scan_detection.yml (100%) rename {deprecated => removed}/detections/identify_new_user_accounts.yml (100%) rename {deprecated => removed}/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml (100%) rename {deprecated => removed}/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml (100%) rename {deprecated => removed}/detections/kubernetes_aws_detect_sensitive_role_access.yml (100%) rename {deprecated => removed}/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml (100%) rename {deprecated => removed}/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml (100%) rename {deprecated => removed}/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml (100%) rename {deprecated => removed}/detections/kubernetes_azure_detect_sensitive_object_access.yml (100%) rename {deprecated => removed}/detections/kubernetes_azure_detect_sensitive_role_access.yml (100%) rename {deprecated => removed}/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml (100%) rename {deprecated => removed}/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml (100%) rename {deprecated => removed}/detections/kubernetes_azure_pod_scan_fingerprint.yml (100%) rename {deprecated => removed}/detections/kubernetes_azure_scan_fingerprint.yml (100%) rename {deprecated => removed}/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml (100%) rename {deprecated => removed}/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml (100%) rename {deprecated => removed}/detections/kubernetes_gcp_detect_sensitive_object_access.yml (100%) rename {deprecated => removed}/detections/kubernetes_gcp_detect_sensitive_role_access.yml (100%) rename {deprecated => removed}/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml (100%) rename {deprecated => removed}/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml (100%) rename {deprecated => removed}/detections/linux_auditd_find_private_keys.yml (100%) rename {deprecated => removed}/detections/local_account_discovery_with_net.yml (100%) rename {deprecated => removed}/detections/monitor_dns_for_brand_abuse.yml (100%) rename {deprecated => removed}/detections/mshtml_module_load_in_office_product.yml (100%) rename {deprecated => removed}/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml (100%) rename {deprecated => removed}/detections/net_localgroup_discovery.yml (100%) rename {deprecated => removed}/detections/network_connection_discovery_with_net.yml (100%) rename {deprecated => removed}/detections/o365_suspicious_admin_email_forwarding.yml (100%) rename {deprecated => removed}/detections/o365_suspicious_rights_delegation.yml (100%) rename {deprecated => removed}/detections/o365_suspicious_user_email_forwarding.yml (100%) rename {deprecated => removed}/detections/office_application_drop_executable.yml (100%) rename {deprecated => removed}/detections/office_application_spawn_regsvr32_process.yml (100%) rename {deprecated => removed}/detections/office_application_spawn_rundll32_process.yml (100%) rename {deprecated => removed}/detections/office_document_creating_schedule_task.yml (100%) rename {deprecated => removed}/detections/office_document_executing_macro_code.yml (100%) rename {deprecated => removed}/detections/office_document_spawned_child_process_to_download.yml (100%) rename {deprecated => removed}/detections/office_product_spawn_cmd_process.yml (100%) rename {deprecated => removed}/detections/office_product_spawning_bitsadmin.yml (100%) rename {deprecated => removed}/detections/office_product_spawning_certutil.yml (100%) rename {deprecated => removed}/detections/office_product_spawning_mshta.yml (100%) rename {deprecated => removed}/detections/office_product_spawning_rundll32_with_no_dll.yml (100%) rename {deprecated => removed}/detections/office_product_spawning_windows_script_host.yml (100%) rename {deprecated => removed}/detections/office_product_spawning_wmic.yml (100%) rename {deprecated => removed}/detections/office_product_writing_cab_or_inf.yml (100%) rename {deprecated => removed}/detections/office_spawning_control.yml (100%) rename {deprecated => removed}/detections/okta_account_locked_out.yml (100%) rename {deprecated => removed}/detections/okta_account_lockout_events.yml (100%) rename {deprecated => removed}/detections/okta_failed_sso_attempts.yml (100%) rename {deprecated => removed}/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml (100%) rename {deprecated => removed}/detections/okta_threatinsight_suspected_passwordspray_attack.yml (100%) rename {deprecated => removed}/detections/okta_two_or_more_rejected_okta_pushes.yml (100%) rename {deprecated => removed}/detections/osquery_pack___coldroot_detection.yml (100%) rename {deprecated => removed}/detections/password_policy_discovery_with_net.yml (100%) rename {deprecated => removed}/detections/processes_created_by_netsh.yml (100%) rename {deprecated => removed}/detections/prohibited_software_on_endpoint.yml (100%) rename {deprecated => removed}/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml (100%) rename {deprecated => removed}/detections/remote_registry_key_modifications.yml (100%) rename {deprecated => removed}/detections/remote_system_discovery_with_net.yml (100%) rename {deprecated => removed}/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml (100%) rename {deprecated => removed}/detections/spectre_and_meltdown_vulnerable_systems.yml (100%) rename {deprecated => removed}/detections/suspicious_changes_to_file_associations.yml (100%) rename {deprecated => removed}/detections/suspicious_email___uba_anomaly.yml (100%) rename {deprecated => removed}/detections/suspicious_file_write.yml (100%) rename {deprecated => removed}/detections/suspicious_powershell_command_line_arguments.yml (100%) rename {deprecated => removed}/detections/suspicious_rundll32_rename.yml (100%) rename {deprecated => removed}/detections/suspicious_writes_to_system_volume_information.yml (100%) rename {deprecated => removed}/detections/uncommon_processes_on_endpoint.yml (100%) rename {deprecated => removed}/detections/unsigned_image_loaded_by_lsass.yml (100%) rename {deprecated => removed}/detections/unsuccessful_netbackup_backups.yml (100%) rename {deprecated => removed}/detections/web_fraud___account_harvesting.yml (100%) rename {deprecated => removed}/detections/web_fraud___anomalous_user_clickspeed.yml (100%) rename {deprecated => removed}/detections/web_fraud___password_sharing_across_accounts.yml (100%) rename {deprecated => removed}/detections/windows_command_shell_fetch_env_variables.yml (100%) rename {deprecated => removed}/detections/windows_connhost_exe_started_forcefully.yml (100%) rename {deprecated => removed}/detections/windows_dll_search_order_hijacking_hunt.yml (100%) rename {deprecated => removed}/detections/windows_hosts_file_modification.yml (100%) rename {deprecated => removed}/detections/windows_lateral_tool_transfer_remcom.yml (100%) rename {deprecated => removed}/detections/windows_modify_registry_reg_restore.yml (100%) rename {deprecated => removed}/detections/windows_msiexec_with_network_connections.yml (100%) rename {deprecated => removed}/detections/windows_network_share_interaction_with_net.yml (100%) rename {deprecated => removed}/detections/windows_office_product_spawning_msdt.yml (100%) rename {deprecated => removed}/detections/windows_query_registry_reg_save.yml (100%) rename {deprecated => removed}/detections/windows_service_stop_via_net__and_sc_application.yml (100%) rename {deprecated => removed}/detections/windows_valid_account_with_never_expires_password.yml (100%) rename {deprecated => removed}/detections/winword_spawning_cmd.yml (100%) rename {deprecated => removed}/detections/winword_spawning_powershell.yml (100%) rename {deprecated => removed}/detections/winword_spawning_windows_script_host.yml (100%) rename {deprecated => removed}/investigations/all_backup_logs_for_host.yml (100%) rename {deprecated => removed}/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml (100%) rename {deprecated => removed}/investigations/aws_investigate_security_hub_alerts_by_dest.yml (100%) rename {deprecated => removed}/investigations/aws_investigate_user_activities_by_accesskeyid.yml (100%) rename {deprecated => removed}/investigations/aws_investigate_user_activities_by_arn.yml (100%) rename {deprecated => removed}/investigations/aws_network_acl_details_from_id.yml (100%) rename {deprecated => removed}/investigations/aws_network_interface_details_via_resourceid.yml (100%) rename {deprecated => removed}/investigations/aws_s3_bucket_details_via_bucketname.yml (100%) rename {deprecated => removed}/investigations/gcp_kubernetes_activity_by_src_ip.yml (100%) rename {deprecated => removed}/investigations/get_all_aws_activity_from_city.yml (100%) rename {deprecated => removed}/investigations/get_all_aws_activity_from_country.yml (100%) rename {deprecated => removed}/investigations/get_all_aws_activity_from_ip_address.yml (100%) rename {deprecated => removed}/investigations/get_all_aws_activity_from_region.yml (100%) rename {deprecated => removed}/investigations/get_backup_logs_for_endpoint.yml (100%) rename {deprecated => removed}/investigations/get_certificate_logs_for_a_domain.yml (100%) rename {deprecated => removed}/investigations/get_dns_server_history_for_a_host.yml (100%) rename {deprecated => removed}/investigations/get_dns_traffic_ratio.yml (100%) rename {deprecated => removed}/investigations/get_ec2_instance_details_by_instanceid.yml (100%) rename {deprecated => removed}/investigations/get_ec2_launch_details.yml (100%) rename {deprecated => removed}/investigations/get_email_info.yml (100%) rename {deprecated => removed}/investigations/get_emails_from_specific_sender.yml (100%) rename {deprecated => removed}/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml (100%) rename {deprecated => removed}/investigations/get_history_of_email_sources.yml (100%) rename {deprecated => removed}/investigations/get_logon_rights_modifications_for_endpoint.yml (100%) rename {deprecated => removed}/investigations/get_logon_rights_modifications_for_user.yml (100%) rename {deprecated => removed}/investigations/get_notable_history.yml (100%) rename {deprecated => removed}/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml (100%) rename {deprecated => removed}/investigations/get_parent_process_info.yml (100%) rename {deprecated => removed}/investigations/get_process_file_activity.yml (100%) rename {deprecated => removed}/investigations/get_process_info.yml (100%) rename {deprecated => removed}/investigations/get_process_information_for_port_activity.yml (100%) rename {deprecated => removed}/investigations/get_process_responsible_for_the_dns_traffic.yml (100%) rename {deprecated => removed}/investigations/get_sysmon_wmi_activity_for_host.yml (100%) rename {deprecated => removed}/investigations/get_web_session_information_via_session_id.yml (100%) rename {deprecated => removed}/investigations/investigate_aws_activities_via_region_name.yml (100%) rename {deprecated => removed}/investigations/investigate_aws_user_activities_by_user_field.yml (100%) rename {deprecated => removed}/investigations/investigate_failed_logins_for_multiple_destinations.yml (100%) rename {deprecated => removed}/investigations/investigate_network_traffic_from_src_ip.yml (100%) rename {deprecated => removed}/investigations/investigate_okta_activity_by_app.yml (100%) rename {deprecated => removed}/investigations/investigate_okta_activity_by_ip_address.yml (100%) rename {deprecated => removed}/investigations/investigate_pass_the_hash_attempts.yml (100%) rename {deprecated => removed}/investigations/investigate_pass_the_ticket_attempts.yml (100%) rename {deprecated => removed}/investigations/investigate_previous_unseen_user.yml (100%) rename {deprecated => removed}/investigations/investigate_successful_remote_desktop_authentications.yml (100%) rename {deprecated => removed}/investigations/investigate_suspicious_strings_in_http_header.yml (100%) rename {deprecated => removed}/investigations/investigate_user_activities_in_okta.yml (100%) rename {deprecated => removed}/investigations/investigate_web_posts_from_src.yml (100%) rename {deprecated => removed}/stories/aws_cryptomining.yml (100%) rename {deprecated => removed}/stories/aws_suspicious_provisioning_activities.yml (100%) rename {deprecated => removed}/stories/common_phishing_frameworks.yml (100%) rename {deprecated => removed}/stories/container_implantation_monitoring_and_investigation.yml (100%) rename {deprecated => removed}/stories/host_redirection.yml (100%) rename {deprecated => removed}/stories/kubernetes_sensitive_role_activity.yml (100%) rename {deprecated => removed}/stories/lateral_movement.yml (100%) rename {deprecated => removed}/stories/monitor_backup_solution.yml (100%) rename {deprecated => removed}/stories/monitor_for_unauthorized_software.yml (100%) rename {deprecated => removed}/stories/office_365_detections.yml (100%) rename {deprecated => removed}/stories/spectre_and_meltdown_vulnerabilities.yml (100%) rename {deprecated => removed}/stories/suspicious_aws_ec2_activities.yml (100%) rename {deprecated => removed}/stories/unusual_aws_ec2_modifications.yml (100%) rename {deprecated => removed}/stories/web_fraud_detection.yml (100%) diff --git a/deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml b/removed/baselines/add_prohibited_processes_to_enterprise_security.yml similarity index 100% rename from deprecated/baselines/add_prohibited_processes_to_enterprise_security.yml rename to removed/baselines/add_prohibited_processes_to_enterprise_security.yml diff --git a/deprecated/baselines/baseline_of_api_calls_per_user_arn.yml b/removed/baselines/baseline_of_api_calls_per_user_arn.yml similarity index 100% rename from deprecated/baselines/baseline_of_api_calls_per_user_arn.yml rename to removed/baselines/baseline_of_api_calls_per_user_arn.yml diff --git a/deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml b/removed/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml similarity index 100% rename from deprecated/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml rename to removed/baselines/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml diff --git a/deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml b/removed/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml similarity index 100% rename from deprecated/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml rename to removed/baselines/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml diff --git a/deprecated/baselines/monitor_successful_backups.yml b/removed/baselines/monitor_successful_backups.yml similarity index 100% rename from deprecated/baselines/monitor_successful_backups.yml rename to removed/baselines/monitor_successful_backups.yml diff --git a/deprecated/baselines/monitor_unsuccessful_backups.yml b/removed/baselines/monitor_unsuccessful_backups.yml similarity index 100% rename from deprecated/baselines/monitor_unsuccessful_backups.yml rename to removed/baselines/monitor_unsuccessful_backups.yml diff --git a/deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml b/removed/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml similarity index 100% rename from deprecated/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml rename to removed/baselines/previously_seen_api_call_per_user_roles_in_cloudtrail.yml diff --git a/deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml b/removed/baselines/previously_seen_aws_provisioning_activity_sources.yml similarity index 100% rename from deprecated/baselines/previously_seen_aws_provisioning_activity_sources.yml rename to removed/baselines/previously_seen_aws_provisioning_activity_sources.yml diff --git a/deprecated/baselines/previously_seen_aws_regions.yml b/removed/baselines/previously_seen_aws_regions.yml similarity index 100% rename from deprecated/baselines/previously_seen_aws_regions.yml rename to removed/baselines/previously_seen_aws_regions.yml diff --git a/deprecated/baselines/previously_seen_ec2_amis.yml b/removed/baselines/previously_seen_ec2_amis.yml similarity index 100% rename from deprecated/baselines/previously_seen_ec2_amis.yml rename to removed/baselines/previously_seen_ec2_amis.yml diff --git a/deprecated/baselines/previously_seen_ec2_instance_types.yml b/removed/baselines/previously_seen_ec2_instance_types.yml similarity index 100% rename from deprecated/baselines/previously_seen_ec2_instance_types.yml rename to removed/baselines/previously_seen_ec2_instance_types.yml diff --git a/deprecated/baselines/previously_seen_ec2_launches_by_user.yml b/removed/baselines/previously_seen_ec2_launches_by_user.yml similarity index 100% rename from deprecated/baselines/previously_seen_ec2_launches_by_user.yml rename to removed/baselines/previously_seen_ec2_launches_by_user.yml diff --git a/deprecated/baselines/previously_seen_ec2_modifications_by_user.yml b/removed/baselines/previously_seen_ec2_modifications_by_user.yml similarity index 100% rename from deprecated/baselines/previously_seen_ec2_modifications_by_user.yml rename to removed/baselines/previously_seen_ec2_modifications_by_user.yml diff --git a/deprecated/baselines/previously_seen_users_in_cloudtrail.yml b/removed/baselines/previously_seen_users_in_cloudtrail.yml similarity index 100% rename from deprecated/baselines/previously_seen_users_in_cloudtrail.yml rename to removed/baselines/previously_seen_users_in_cloudtrail.yml diff --git a/deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml b/removed/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml similarity index 100% rename from deprecated/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml rename to removed/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml diff --git a/deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml b/removed/baselines/update_previously_seen_users_in_cloudtrail.yml similarity index 100% rename from deprecated/baselines/update_previously_seen_users_in_cloudtrail.yml rename to removed/baselines/update_previously_seen_users_in_cloudtrail.yml diff --git a/deprecated/deprecation_mapping.YML b/removed/deprecation_mapping.YML similarity index 100% rename from deprecated/deprecation_mapping.YML rename to removed/deprecation_mapping.YML diff --git a/deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml b/removed/detections/abnormally_high_aws_instances_launched_by_user.yml similarity index 100% rename from deprecated/detections/abnormally_high_aws_instances_launched_by_user.yml rename to removed/detections/abnormally_high_aws_instances_launched_by_user.yml diff --git a/deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml b/removed/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml similarity index 100% rename from deprecated/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml rename to removed/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml diff --git a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml b/removed/detections/abnormally_high_aws_instances_terminated_by_user.yml similarity index 100% rename from deprecated/detections/abnormally_high_aws_instances_terminated_by_user.yml rename to removed/detections/abnormally_high_aws_instances_terminated_by_user.yml diff --git a/deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/removed/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml similarity index 100% rename from deprecated/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml rename to removed/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml diff --git a/deprecated/detections/account_discovery_with_net_app.yml b/removed/detections/account_discovery_with_net_app.yml similarity index 100% rename from deprecated/detections/account_discovery_with_net_app.yml rename to removed/detections/account_discovery_with_net_app.yml diff --git a/deprecated/detections/asl_aws_createaccesskey.yml b/removed/detections/asl_aws_createaccesskey.yml similarity index 100% rename from deprecated/detections/asl_aws_createaccesskey.yml rename to removed/detections/asl_aws_createaccesskey.yml diff --git a/deprecated/detections/asl_aws_excessive_security_scanning.yml b/removed/detections/asl_aws_excessive_security_scanning.yml similarity index 100% rename from deprecated/detections/asl_aws_excessive_security_scanning.yml rename to removed/detections/asl_aws_excessive_security_scanning.yml diff --git a/deprecated/detections/asl_aws_password_policy_changes.yml b/removed/detections/asl_aws_password_policy_changes.yml similarity index 100% rename from deprecated/detections/asl_aws_password_policy_changes.yml rename to removed/detections/asl_aws_password_policy_changes.yml diff --git a/deprecated/detections/attempt_to_stop_security_service.yml b/removed/detections/attempt_to_stop_security_service.yml similarity index 100% rename from deprecated/detections/attempt_to_stop_security_service.yml rename to removed/detections/attempt_to_stop_security_service.yml diff --git a/deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml b/removed/detections/attempted_credential_dump_from_registry_via_reg_exe.yml similarity index 100% rename from deprecated/detections/attempted_credential_dump_from_registry_via_reg_exe.yml rename to removed/detections/attempted_credential_dump_from_registry_via_reg_exe.yml diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml b/removed/detections/aws_cloud_provisioning_from_previously_unseen_city.yml similarity index 100% rename from deprecated/detections/aws_cloud_provisioning_from_previously_unseen_city.yml rename to removed/detections/aws_cloud_provisioning_from_previously_unseen_city.yml diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml b/removed/detections/aws_cloud_provisioning_from_previously_unseen_country.yml similarity index 100% rename from deprecated/detections/aws_cloud_provisioning_from_previously_unseen_country.yml rename to removed/detections/aws_cloud_provisioning_from_previously_unseen_country.yml diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/removed/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml similarity index 100% rename from deprecated/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml rename to removed/detections/aws_cloud_provisioning_from_previously_unseen_ip_address.yml diff --git a/deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml b/removed/detections/aws_cloud_provisioning_from_previously_unseen_region.yml similarity index 100% rename from deprecated/detections/aws_cloud_provisioning_from_previously_unseen_region.yml rename to removed/detections/aws_cloud_provisioning_from_previously_unseen_region.yml diff --git a/deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/removed/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml similarity index 100% rename from deprecated/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml rename to removed/detections/aws_eks_kubernetes_cluster_sensitive_object_access.yml diff --git a/deprecated/detections/change_default_file_association.yml b/removed/detections/change_default_file_association.yml similarity index 100% rename from deprecated/detections/change_default_file_association.yml rename to removed/detections/change_default_file_association.yml diff --git a/deprecated/detections/clients_connecting_to_multiple_dns_servers.yml b/removed/detections/clients_connecting_to_multiple_dns_servers.yml similarity index 100% rename from deprecated/detections/clients_connecting_to_multiple_dns_servers.yml rename to removed/detections/clients_connecting_to_multiple_dns_servers.yml diff --git a/deprecated/detections/cloud_network_access_control_list_deleted.yml b/removed/detections/cloud_network_access_control_list_deleted.yml similarity index 100% rename from deprecated/detections/cloud_network_access_control_list_deleted.yml rename to removed/detections/cloud_network_access_control_list_deleted.yml diff --git a/deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml b/removed/detections/cmdline_tool_not_executed_in_cmd_shell.yml similarity index 100% rename from deprecated/detections/cmdline_tool_not_executed_in_cmd_shell.yml rename to removed/detections/cmdline_tool_not_executed_in_cmd_shell.yml diff --git a/deprecated/detections/correlation_by_repository_and_risk.yml b/removed/detections/correlation_by_repository_and_risk.yml similarity index 100% rename from deprecated/detections/correlation_by_repository_and_risk.yml rename to removed/detections/correlation_by_repository_and_risk.yml diff --git a/deprecated/detections/correlation_by_user_and_risk.yml b/removed/detections/correlation_by_user_and_risk.yml similarity index 100% rename from deprecated/detections/correlation_by_user_and_risk.yml rename to removed/detections/correlation_by_user_and_risk.yml diff --git a/deprecated/detections/create_local_admin_accounts_using_net_exe.yml b/removed/detections/create_local_admin_accounts_using_net_exe.yml similarity index 100% rename from deprecated/detections/create_local_admin_accounts_using_net_exe.yml rename to removed/detections/create_local_admin_accounts_using_net_exe.yml diff --git a/deprecated/detections/deleting_of_net_users.yml b/removed/detections/deleting_of_net_users.yml similarity index 100% rename from deprecated/detections/deleting_of_net_users.yml rename to removed/detections/deleting_of_net_users.yml diff --git a/deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml b/removed/detections/detect_activity_related_to_pass_the_hash_attacks.yml similarity index 100% rename from deprecated/detections/detect_activity_related_to_pass_the_hash_attacks.yml rename to removed/detections/detect_activity_related_to_pass_the_hash_attacks.yml diff --git a/deprecated/detections/detect_api_activity_from_users_without_mfa.yml b/removed/detections/detect_api_activity_from_users_without_mfa.yml similarity index 100% rename from deprecated/detections/detect_api_activity_from_users_without_mfa.yml rename to removed/detections/detect_api_activity_from_users_without_mfa.yml diff --git a/deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml b/removed/detections/detect_aws_api_activities_from_unapproved_accounts.yml similarity index 100% rename from deprecated/detections/detect_aws_api_activities_from_unapproved_accounts.yml rename to removed/detections/detect_aws_api_activities_from_unapproved_accounts.yml diff --git a/deprecated/detections/detect_critical_alerts_from_security_tools.yml b/removed/detections/detect_critical_alerts_from_security_tools.yml similarity index 100% rename from deprecated/detections/detect_critical_alerts_from_security_tools.yml rename to removed/detections/detect_critical_alerts_from_security_tools.yml diff --git a/deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/removed/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml similarity index 100% rename from deprecated/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml rename to removed/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml diff --git a/deprecated/detections/detect_long_dns_txt_record_response.yml b/removed/detections/detect_long_dns_txt_record_response.yml similarity index 100% rename from deprecated/detections/detect_long_dns_txt_record_response.yml rename to removed/detections/detect_long_dns_txt_record_response.yml diff --git a/deprecated/detections/detect_mimikatz_using_loaded_images.yml b/removed/detections/detect_mimikatz_using_loaded_images.yml similarity index 100% rename from deprecated/detections/detect_mimikatz_using_loaded_images.yml rename to removed/detections/detect_mimikatz_using_loaded_images.yml diff --git a/deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/removed/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml similarity index 100% rename from deprecated/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml rename to removed/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml diff --git a/deprecated/detections/detect_new_api_calls_from_user_roles.yml b/removed/detections/detect_new_api_calls_from_user_roles.yml similarity index 100% rename from deprecated/detections/detect_new_api_calls_from_user_roles.yml rename to removed/detections/detect_new_api_calls_from_user_roles.yml diff --git a/deprecated/detections/detect_new_user_aws_console_login.yml b/removed/detections/detect_new_user_aws_console_login.yml similarity index 100% rename from deprecated/detections/detect_new_user_aws_console_login.yml rename to removed/detections/detect_new_user_aws_console_login.yml diff --git a/deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml b/removed/detections/detect_processes_used_for_system_network_configuration_discovery.yml similarity index 100% rename from deprecated/detections/detect_processes_used_for_system_network_configuration_discovery.yml rename to removed/detections/detect_processes_used_for_system_network_configuration_discovery.yml diff --git a/deprecated/detections/detect_spike_in_aws_api_activity.yml b/removed/detections/detect_spike_in_aws_api_activity.yml similarity index 100% rename from deprecated/detections/detect_spike_in_aws_api_activity.yml rename to removed/detections/detect_spike_in_aws_api_activity.yml diff --git a/deprecated/detections/detect_spike_in_network_acl_activity.yml b/removed/detections/detect_spike_in_network_acl_activity.yml similarity index 100% rename from deprecated/detections/detect_spike_in_network_acl_activity.yml rename to removed/detections/detect_spike_in_network_acl_activity.yml diff --git a/deprecated/detections/detect_spike_in_security_group_activity.yml b/removed/detections/detect_spike_in_security_group_activity.yml similarity index 100% rename from deprecated/detections/detect_spike_in_security_group_activity.yml rename to removed/detections/detect_spike_in_security_group_activity.yml diff --git a/deprecated/detections/detect_usb_device_insertion.yml b/removed/detections/detect_usb_device_insertion.yml similarity index 100% rename from deprecated/detections/detect_usb_device_insertion.yml rename to removed/detections/detect_usb_device_insertion.yml diff --git a/deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml b/removed/detections/detect_web_traffic_to_dynamic_domain_providers.yml similarity index 100% rename from deprecated/detections/detect_web_traffic_to_dynamic_domain_providers.yml rename to removed/detections/detect_web_traffic_to_dynamic_domain_providers.yml diff --git a/deprecated/detections/detect_webshell_exploit_behavior.yml b/removed/detections/detect_webshell_exploit_behavior.yml similarity index 100% rename from deprecated/detections/detect_webshell_exploit_behavior.yml rename to removed/detections/detect_webshell_exploit_behavior.yml diff --git a/deprecated/detections/detection_of_dns_tunnels.yml b/removed/detections/detection_of_dns_tunnels.yml similarity index 100% rename from deprecated/detections/detection_of_dns_tunnels.yml rename to removed/detections/detection_of_dns_tunnels.yml diff --git a/deprecated/detections/disabling_net_user_account.yml b/removed/detections/disabling_net_user_account.yml similarity index 100% rename from deprecated/detections/disabling_net_user_account.yml rename to removed/detections/disabling_net_user_account.yml diff --git a/deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/removed/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml similarity index 100% rename from deprecated/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml rename to removed/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml diff --git a/deprecated/detections/dns_record_changed.yml b/removed/detections/dns_record_changed.yml similarity index 100% rename from deprecated/detections/dns_record_changed.yml rename to removed/detections/dns_record_changed.yml diff --git a/deprecated/detections/domain_account_discovery_with_net_app.yml b/removed/detections/domain_account_discovery_with_net_app.yml similarity index 100% rename from deprecated/detections/domain_account_discovery_with_net_app.yml rename to removed/detections/domain_account_discovery_with_net_app.yml diff --git a/deprecated/detections/domain_group_discovery_with_net.yml b/removed/detections/domain_group_discovery_with_net.yml similarity index 100% rename from deprecated/detections/domain_group_discovery_with_net.yml rename to removed/detections/domain_group_discovery_with_net.yml diff --git a/deprecated/detections/dump_lsass_via_procdump_rename.yml b/removed/detections/dump_lsass_via_procdump_rename.yml similarity index 100% rename from deprecated/detections/dump_lsass_via_procdump_rename.yml rename to removed/detections/dump_lsass_via_procdump_rename.yml diff --git a/deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml b/removed/detections/ec2_instance_modified_with_previously_unseen_user.yml similarity index 100% rename from deprecated/detections/ec2_instance_modified_with_previously_unseen_user.yml rename to removed/detections/ec2_instance_modified_with_previously_unseen_user.yml diff --git a/deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml b/removed/detections/ec2_instance_started_in_previously_unseen_region.yml similarity index 100% rename from deprecated/detections/ec2_instance_started_in_previously_unseen_region.yml rename to removed/detections/ec2_instance_started_in_previously_unseen_region.yml diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml b/removed/detections/ec2_instance_started_with_previously_unseen_ami.yml similarity index 100% rename from deprecated/detections/ec2_instance_started_with_previously_unseen_ami.yml rename to removed/detections/ec2_instance_started_with_previously_unseen_ami.yml diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml b/removed/detections/ec2_instance_started_with_previously_unseen_instance_type.yml similarity index 100% rename from deprecated/detections/ec2_instance_started_with_previously_unseen_instance_type.yml rename to removed/detections/ec2_instance_started_with_previously_unseen_instance_type.yml diff --git a/deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml b/removed/detections/ec2_instance_started_with_previously_unseen_user.yml similarity index 100% rename from deprecated/detections/ec2_instance_started_with_previously_unseen_user.yml rename to removed/detections/ec2_instance_started_with_previously_unseen_user.yml diff --git a/deprecated/detections/elevated_group_discovery_with_net.yml b/removed/detections/elevated_group_discovery_with_net.yml similarity index 100% rename from deprecated/detections/elevated_group_discovery_with_net.yml rename to removed/detections/elevated_group_discovery_with_net.yml diff --git a/deprecated/detections/excel_spawning_powershell.yml b/removed/detections/excel_spawning_powershell.yml similarity index 100% rename from deprecated/detections/excel_spawning_powershell.yml rename to removed/detections/excel_spawning_powershell.yml diff --git a/deprecated/detections/excel_spawning_windows_script_host.yml b/removed/detections/excel_spawning_windows_script_host.yml similarity index 100% rename from deprecated/detections/excel_spawning_windows_script_host.yml rename to removed/detections/excel_spawning_windows_script_host.yml diff --git a/deprecated/detections/excessive_service_stop_attempt.yml b/removed/detections/excessive_service_stop_attempt.yml similarity index 100% rename from deprecated/detections/excessive_service_stop_attempt.yml rename to removed/detections/excessive_service_stop_attempt.yml diff --git a/deprecated/detections/excessive_usage_of_net_app.yml b/removed/detections/excessive_usage_of_net_app.yml similarity index 100% rename from deprecated/detections/excessive_usage_of_net_app.yml rename to removed/detections/excessive_usage_of_net_app.yml diff --git a/deprecated/detections/execution_of_file_with_spaces_before_extension.yml b/removed/detections/execution_of_file_with_spaces_before_extension.yml similarity index 100% rename from deprecated/detections/execution_of_file_with_spaces_before_extension.yml rename to removed/detections/execution_of_file_with_spaces_before_extension.yml diff --git a/deprecated/detections/extended_period_without_successful_netbackup_backups.yml b/removed/detections/extended_period_without_successful_netbackup_backups.yml similarity index 100% rename from deprecated/detections/extended_period_without_successful_netbackup_backups.yml rename to removed/detections/extended_period_without_successful_netbackup_backups.yml diff --git a/deprecated/detections/extraction_of_registry_hives.yml b/removed/detections/extraction_of_registry_hives.yml similarity index 100% rename from deprecated/detections/extraction_of_registry_hives.yml rename to removed/detections/extraction_of_registry_hives.yml diff --git a/deprecated/detections/first_time_seen_command_line_argument.yml b/removed/detections/first_time_seen_command_line_argument.yml similarity index 100% rename from deprecated/detections/first_time_seen_command_line_argument.yml rename to removed/detections/first_time_seen_command_line_argument.yml diff --git a/deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/removed/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml similarity index 100% rename from deprecated/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml rename to removed/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml diff --git a/deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/removed/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml similarity index 100% rename from deprecated/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml rename to removed/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml diff --git a/deprecated/detections/gcp_detect_oauth_token_abuse.yml b/removed/detections/gcp_detect_oauth_token_abuse.yml similarity index 100% rename from deprecated/detections/gcp_detect_oauth_token_abuse.yml rename to removed/detections/gcp_detect_oauth_token_abuse.yml diff --git a/deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml b/removed/detections/gcp_kubernetes_cluster_scan_detection.yml similarity index 100% rename from deprecated/detections/gcp_kubernetes_cluster_scan_detection.yml rename to removed/detections/gcp_kubernetes_cluster_scan_detection.yml diff --git a/deprecated/detections/identify_new_user_accounts.yml b/removed/detections/identify_new_user_accounts.yml similarity index 100% rename from deprecated/detections/identify_new_user_accounts.yml rename to removed/detections/identify_new_user_accounts.yml diff --git a/deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/removed/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml similarity index 100% rename from deprecated/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml rename to removed/detections/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml diff --git a/deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml b/removed/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml similarity index 100% rename from deprecated/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml rename to removed/detections/kubernetes_aws_detect_rbac_authorization_by_account.yml diff --git a/deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml b/removed/detections/kubernetes_aws_detect_sensitive_role_access.yml similarity index 100% rename from deprecated/detections/kubernetes_aws_detect_sensitive_role_access.yml rename to removed/detections/kubernetes_aws_detect_sensitive_role_access.yml diff --git a/deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/removed/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml similarity index 100% rename from deprecated/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml rename to removed/detections/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml diff --git a/deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/removed/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml similarity index 100% rename from deprecated/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml rename to removed/detections/kubernetes_azure_active_service_accounts_by_pod_namespace.yml diff --git a/deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml b/removed/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml similarity index 100% rename from deprecated/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml rename to removed/detections/kubernetes_azure_detect_rbac_authorization_by_account.yml diff --git a/deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml b/removed/detections/kubernetes_azure_detect_sensitive_object_access.yml similarity index 100% rename from deprecated/detections/kubernetes_azure_detect_sensitive_object_access.yml rename to removed/detections/kubernetes_azure_detect_sensitive_object_access.yml diff --git a/deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml b/removed/detections/kubernetes_azure_detect_sensitive_role_access.yml similarity index 100% rename from deprecated/detections/kubernetes_azure_detect_sensitive_role_access.yml rename to removed/detections/kubernetes_azure_detect_sensitive_role_access.yml diff --git a/deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/removed/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml similarity index 100% rename from deprecated/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml rename to removed/detections/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml diff --git a/deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/removed/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml similarity index 100% rename from deprecated/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml rename to removed/detections/kubernetes_azure_detect_suspicious_kubectl_calls.yml diff --git a/deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml b/removed/detections/kubernetes_azure_pod_scan_fingerprint.yml similarity index 100% rename from deprecated/detections/kubernetes_azure_pod_scan_fingerprint.yml rename to removed/detections/kubernetes_azure_pod_scan_fingerprint.yml diff --git a/deprecated/detections/kubernetes_azure_scan_fingerprint.yml b/removed/detections/kubernetes_azure_scan_fingerprint.yml similarity index 100% rename from deprecated/detections/kubernetes_azure_scan_fingerprint.yml rename to removed/detections/kubernetes_azure_scan_fingerprint.yml diff --git a/deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/removed/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml similarity index 100% rename from deprecated/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml rename to removed/detections/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml diff --git a/deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/removed/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml similarity index 100% rename from deprecated/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml rename to removed/detections/kubernetes_gcp_detect_rbac_authorizations_by_account.yml diff --git a/deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml b/removed/detections/kubernetes_gcp_detect_sensitive_object_access.yml similarity index 100% rename from deprecated/detections/kubernetes_gcp_detect_sensitive_object_access.yml rename to removed/detections/kubernetes_gcp_detect_sensitive_object_access.yml diff --git a/deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml b/removed/detections/kubernetes_gcp_detect_sensitive_role_access.yml similarity index 100% rename from deprecated/detections/kubernetes_gcp_detect_sensitive_role_access.yml rename to removed/detections/kubernetes_gcp_detect_sensitive_role_access.yml diff --git a/deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/removed/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml similarity index 100% rename from deprecated/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml rename to removed/detections/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml diff --git a/deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/removed/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml similarity index 100% rename from deprecated/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml rename to removed/detections/kubernetes_gcp_detect_suspicious_kubectl_calls.yml diff --git a/deprecated/detections/linux_auditd_find_private_keys.yml b/removed/detections/linux_auditd_find_private_keys.yml similarity index 100% rename from deprecated/detections/linux_auditd_find_private_keys.yml rename to removed/detections/linux_auditd_find_private_keys.yml diff --git a/deprecated/detections/local_account_discovery_with_net.yml b/removed/detections/local_account_discovery_with_net.yml similarity index 100% rename from deprecated/detections/local_account_discovery_with_net.yml rename to removed/detections/local_account_discovery_with_net.yml diff --git a/deprecated/detections/monitor_dns_for_brand_abuse.yml b/removed/detections/monitor_dns_for_brand_abuse.yml similarity index 100% rename from deprecated/detections/monitor_dns_for_brand_abuse.yml rename to removed/detections/monitor_dns_for_brand_abuse.yml diff --git a/deprecated/detections/mshtml_module_load_in_office_product.yml b/removed/detections/mshtml_module_load_in_office_product.yml similarity index 100% rename from deprecated/detections/mshtml_module_load_in_office_product.yml rename to removed/detections/mshtml_module_load_in_office_product.yml diff --git a/deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml b/removed/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml similarity index 100% rename from deprecated/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml rename to removed/detections/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml diff --git a/deprecated/detections/net_localgroup_discovery.yml b/removed/detections/net_localgroup_discovery.yml similarity index 100% rename from deprecated/detections/net_localgroup_discovery.yml rename to removed/detections/net_localgroup_discovery.yml diff --git a/deprecated/detections/network_connection_discovery_with_net.yml b/removed/detections/network_connection_discovery_with_net.yml similarity index 100% rename from deprecated/detections/network_connection_discovery_with_net.yml rename to removed/detections/network_connection_discovery_with_net.yml diff --git a/deprecated/detections/o365_suspicious_admin_email_forwarding.yml b/removed/detections/o365_suspicious_admin_email_forwarding.yml similarity index 100% rename from deprecated/detections/o365_suspicious_admin_email_forwarding.yml rename to removed/detections/o365_suspicious_admin_email_forwarding.yml diff --git a/deprecated/detections/o365_suspicious_rights_delegation.yml b/removed/detections/o365_suspicious_rights_delegation.yml similarity index 100% rename from deprecated/detections/o365_suspicious_rights_delegation.yml rename to removed/detections/o365_suspicious_rights_delegation.yml diff --git a/deprecated/detections/o365_suspicious_user_email_forwarding.yml b/removed/detections/o365_suspicious_user_email_forwarding.yml similarity index 100% rename from deprecated/detections/o365_suspicious_user_email_forwarding.yml rename to removed/detections/o365_suspicious_user_email_forwarding.yml diff --git a/deprecated/detections/office_application_drop_executable.yml b/removed/detections/office_application_drop_executable.yml similarity index 100% rename from deprecated/detections/office_application_drop_executable.yml rename to removed/detections/office_application_drop_executable.yml diff --git a/deprecated/detections/office_application_spawn_regsvr32_process.yml b/removed/detections/office_application_spawn_regsvr32_process.yml similarity index 100% rename from deprecated/detections/office_application_spawn_regsvr32_process.yml rename to removed/detections/office_application_spawn_regsvr32_process.yml diff --git a/deprecated/detections/office_application_spawn_rundll32_process.yml b/removed/detections/office_application_spawn_rundll32_process.yml similarity index 100% rename from deprecated/detections/office_application_spawn_rundll32_process.yml rename to removed/detections/office_application_spawn_rundll32_process.yml diff --git a/deprecated/detections/office_document_creating_schedule_task.yml b/removed/detections/office_document_creating_schedule_task.yml similarity index 100% rename from deprecated/detections/office_document_creating_schedule_task.yml rename to removed/detections/office_document_creating_schedule_task.yml diff --git a/deprecated/detections/office_document_executing_macro_code.yml b/removed/detections/office_document_executing_macro_code.yml similarity index 100% rename from deprecated/detections/office_document_executing_macro_code.yml rename to removed/detections/office_document_executing_macro_code.yml diff --git a/deprecated/detections/office_document_spawned_child_process_to_download.yml b/removed/detections/office_document_spawned_child_process_to_download.yml similarity index 100% rename from deprecated/detections/office_document_spawned_child_process_to_download.yml rename to removed/detections/office_document_spawned_child_process_to_download.yml diff --git a/deprecated/detections/office_product_spawn_cmd_process.yml b/removed/detections/office_product_spawn_cmd_process.yml similarity index 100% rename from deprecated/detections/office_product_spawn_cmd_process.yml rename to removed/detections/office_product_spawn_cmd_process.yml diff --git a/deprecated/detections/office_product_spawning_bitsadmin.yml b/removed/detections/office_product_spawning_bitsadmin.yml similarity index 100% rename from deprecated/detections/office_product_spawning_bitsadmin.yml rename to removed/detections/office_product_spawning_bitsadmin.yml diff --git a/deprecated/detections/office_product_spawning_certutil.yml b/removed/detections/office_product_spawning_certutil.yml similarity index 100% rename from deprecated/detections/office_product_spawning_certutil.yml rename to removed/detections/office_product_spawning_certutil.yml diff --git a/deprecated/detections/office_product_spawning_mshta.yml b/removed/detections/office_product_spawning_mshta.yml similarity index 100% rename from deprecated/detections/office_product_spawning_mshta.yml rename to removed/detections/office_product_spawning_mshta.yml diff --git a/deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml b/removed/detections/office_product_spawning_rundll32_with_no_dll.yml similarity index 100% rename from deprecated/detections/office_product_spawning_rundll32_with_no_dll.yml rename to removed/detections/office_product_spawning_rundll32_with_no_dll.yml diff --git a/deprecated/detections/office_product_spawning_windows_script_host.yml b/removed/detections/office_product_spawning_windows_script_host.yml similarity index 100% rename from deprecated/detections/office_product_spawning_windows_script_host.yml rename to removed/detections/office_product_spawning_windows_script_host.yml diff --git a/deprecated/detections/office_product_spawning_wmic.yml b/removed/detections/office_product_spawning_wmic.yml similarity index 100% rename from deprecated/detections/office_product_spawning_wmic.yml rename to removed/detections/office_product_spawning_wmic.yml diff --git a/deprecated/detections/office_product_writing_cab_or_inf.yml b/removed/detections/office_product_writing_cab_or_inf.yml similarity index 100% rename from deprecated/detections/office_product_writing_cab_or_inf.yml rename to removed/detections/office_product_writing_cab_or_inf.yml diff --git a/deprecated/detections/office_spawning_control.yml b/removed/detections/office_spawning_control.yml similarity index 100% rename from deprecated/detections/office_spawning_control.yml rename to removed/detections/office_spawning_control.yml diff --git a/deprecated/detections/okta_account_locked_out.yml b/removed/detections/okta_account_locked_out.yml similarity index 100% rename from deprecated/detections/okta_account_locked_out.yml rename to removed/detections/okta_account_locked_out.yml diff --git a/deprecated/detections/okta_account_lockout_events.yml b/removed/detections/okta_account_lockout_events.yml similarity index 100% rename from deprecated/detections/okta_account_lockout_events.yml rename to removed/detections/okta_account_lockout_events.yml diff --git a/deprecated/detections/okta_failed_sso_attempts.yml b/removed/detections/okta_failed_sso_attempts.yml similarity index 100% rename from deprecated/detections/okta_failed_sso_attempts.yml rename to removed/detections/okta_failed_sso_attempts.yml diff --git a/deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml b/removed/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml similarity index 100% rename from deprecated/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml rename to removed/detections/okta_threatinsight_login_failure_with_high_unknown_users.yml diff --git a/deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml b/removed/detections/okta_threatinsight_suspected_passwordspray_attack.yml similarity index 100% rename from deprecated/detections/okta_threatinsight_suspected_passwordspray_attack.yml rename to removed/detections/okta_threatinsight_suspected_passwordspray_attack.yml diff --git a/deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml b/removed/detections/okta_two_or_more_rejected_okta_pushes.yml similarity index 100% rename from deprecated/detections/okta_two_or_more_rejected_okta_pushes.yml rename to removed/detections/okta_two_or_more_rejected_okta_pushes.yml diff --git a/deprecated/detections/osquery_pack___coldroot_detection.yml b/removed/detections/osquery_pack___coldroot_detection.yml similarity index 100% rename from deprecated/detections/osquery_pack___coldroot_detection.yml rename to removed/detections/osquery_pack___coldroot_detection.yml diff --git a/deprecated/detections/password_policy_discovery_with_net.yml b/removed/detections/password_policy_discovery_with_net.yml similarity index 100% rename from deprecated/detections/password_policy_discovery_with_net.yml rename to removed/detections/password_policy_discovery_with_net.yml diff --git a/deprecated/detections/processes_created_by_netsh.yml b/removed/detections/processes_created_by_netsh.yml similarity index 100% rename from deprecated/detections/processes_created_by_netsh.yml rename to removed/detections/processes_created_by_netsh.yml diff --git a/deprecated/detections/prohibited_software_on_endpoint.yml b/removed/detections/prohibited_software_on_endpoint.yml similarity index 100% rename from deprecated/detections/prohibited_software_on_endpoint.yml rename to removed/detections/prohibited_software_on_endpoint.yml diff --git a/deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/removed/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml similarity index 100% rename from deprecated/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml rename to removed/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml diff --git a/deprecated/detections/remote_registry_key_modifications.yml b/removed/detections/remote_registry_key_modifications.yml similarity index 100% rename from deprecated/detections/remote_registry_key_modifications.yml rename to removed/detections/remote_registry_key_modifications.yml diff --git a/deprecated/detections/remote_system_discovery_with_net.yml b/removed/detections/remote_system_discovery_with_net.yml similarity index 100% rename from deprecated/detections/remote_system_discovery_with_net.yml rename to removed/detections/remote_system_discovery_with_net.yml diff --git a/deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml b/removed/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml similarity index 100% rename from deprecated/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml rename to removed/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml diff --git a/deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml b/removed/detections/spectre_and_meltdown_vulnerable_systems.yml similarity index 100% rename from deprecated/detections/spectre_and_meltdown_vulnerable_systems.yml rename to removed/detections/spectre_and_meltdown_vulnerable_systems.yml diff --git a/deprecated/detections/suspicious_changes_to_file_associations.yml b/removed/detections/suspicious_changes_to_file_associations.yml similarity index 100% rename from deprecated/detections/suspicious_changes_to_file_associations.yml rename to removed/detections/suspicious_changes_to_file_associations.yml diff --git a/deprecated/detections/suspicious_email___uba_anomaly.yml b/removed/detections/suspicious_email___uba_anomaly.yml similarity index 100% rename from deprecated/detections/suspicious_email___uba_anomaly.yml rename to removed/detections/suspicious_email___uba_anomaly.yml diff --git a/deprecated/detections/suspicious_file_write.yml b/removed/detections/suspicious_file_write.yml similarity index 100% rename from deprecated/detections/suspicious_file_write.yml rename to removed/detections/suspicious_file_write.yml diff --git a/deprecated/detections/suspicious_powershell_command_line_arguments.yml b/removed/detections/suspicious_powershell_command_line_arguments.yml similarity index 100% rename from deprecated/detections/suspicious_powershell_command_line_arguments.yml rename to removed/detections/suspicious_powershell_command_line_arguments.yml diff --git a/deprecated/detections/suspicious_rundll32_rename.yml b/removed/detections/suspicious_rundll32_rename.yml similarity index 100% rename from deprecated/detections/suspicious_rundll32_rename.yml rename to removed/detections/suspicious_rundll32_rename.yml diff --git a/deprecated/detections/suspicious_writes_to_system_volume_information.yml b/removed/detections/suspicious_writes_to_system_volume_information.yml similarity index 100% rename from deprecated/detections/suspicious_writes_to_system_volume_information.yml rename to removed/detections/suspicious_writes_to_system_volume_information.yml diff --git a/deprecated/detections/uncommon_processes_on_endpoint.yml b/removed/detections/uncommon_processes_on_endpoint.yml similarity index 100% rename from deprecated/detections/uncommon_processes_on_endpoint.yml rename to removed/detections/uncommon_processes_on_endpoint.yml diff --git a/deprecated/detections/unsigned_image_loaded_by_lsass.yml b/removed/detections/unsigned_image_loaded_by_lsass.yml similarity index 100% rename from deprecated/detections/unsigned_image_loaded_by_lsass.yml rename to removed/detections/unsigned_image_loaded_by_lsass.yml diff --git a/deprecated/detections/unsuccessful_netbackup_backups.yml b/removed/detections/unsuccessful_netbackup_backups.yml similarity index 100% rename from deprecated/detections/unsuccessful_netbackup_backups.yml rename to removed/detections/unsuccessful_netbackup_backups.yml diff --git a/deprecated/detections/web_fraud___account_harvesting.yml b/removed/detections/web_fraud___account_harvesting.yml similarity index 100% rename from deprecated/detections/web_fraud___account_harvesting.yml rename to removed/detections/web_fraud___account_harvesting.yml diff --git a/deprecated/detections/web_fraud___anomalous_user_clickspeed.yml b/removed/detections/web_fraud___anomalous_user_clickspeed.yml similarity index 100% rename from deprecated/detections/web_fraud___anomalous_user_clickspeed.yml rename to removed/detections/web_fraud___anomalous_user_clickspeed.yml diff --git a/deprecated/detections/web_fraud___password_sharing_across_accounts.yml b/removed/detections/web_fraud___password_sharing_across_accounts.yml similarity index 100% rename from deprecated/detections/web_fraud___password_sharing_across_accounts.yml rename to removed/detections/web_fraud___password_sharing_across_accounts.yml diff --git a/deprecated/detections/windows_command_shell_fetch_env_variables.yml b/removed/detections/windows_command_shell_fetch_env_variables.yml similarity index 100% rename from deprecated/detections/windows_command_shell_fetch_env_variables.yml rename to removed/detections/windows_command_shell_fetch_env_variables.yml diff --git a/deprecated/detections/windows_connhost_exe_started_forcefully.yml b/removed/detections/windows_connhost_exe_started_forcefully.yml similarity index 100% rename from deprecated/detections/windows_connhost_exe_started_forcefully.yml rename to removed/detections/windows_connhost_exe_started_forcefully.yml diff --git a/deprecated/detections/windows_dll_search_order_hijacking_hunt.yml b/removed/detections/windows_dll_search_order_hijacking_hunt.yml similarity index 100% rename from deprecated/detections/windows_dll_search_order_hijacking_hunt.yml rename to removed/detections/windows_dll_search_order_hijacking_hunt.yml diff --git a/deprecated/detections/windows_hosts_file_modification.yml b/removed/detections/windows_hosts_file_modification.yml similarity index 100% rename from deprecated/detections/windows_hosts_file_modification.yml rename to removed/detections/windows_hosts_file_modification.yml diff --git a/deprecated/detections/windows_lateral_tool_transfer_remcom.yml b/removed/detections/windows_lateral_tool_transfer_remcom.yml similarity index 100% rename from deprecated/detections/windows_lateral_tool_transfer_remcom.yml rename to removed/detections/windows_lateral_tool_transfer_remcom.yml diff --git a/deprecated/detections/windows_modify_registry_reg_restore.yml b/removed/detections/windows_modify_registry_reg_restore.yml similarity index 100% rename from deprecated/detections/windows_modify_registry_reg_restore.yml rename to removed/detections/windows_modify_registry_reg_restore.yml diff --git a/deprecated/detections/windows_msiexec_with_network_connections.yml b/removed/detections/windows_msiexec_with_network_connections.yml similarity index 100% rename from deprecated/detections/windows_msiexec_with_network_connections.yml rename to removed/detections/windows_msiexec_with_network_connections.yml diff --git a/deprecated/detections/windows_network_share_interaction_with_net.yml b/removed/detections/windows_network_share_interaction_with_net.yml similarity index 100% rename from deprecated/detections/windows_network_share_interaction_with_net.yml rename to removed/detections/windows_network_share_interaction_with_net.yml diff --git a/deprecated/detections/windows_office_product_spawning_msdt.yml b/removed/detections/windows_office_product_spawning_msdt.yml similarity index 100% rename from deprecated/detections/windows_office_product_spawning_msdt.yml rename to removed/detections/windows_office_product_spawning_msdt.yml diff --git a/deprecated/detections/windows_query_registry_reg_save.yml b/removed/detections/windows_query_registry_reg_save.yml similarity index 100% rename from deprecated/detections/windows_query_registry_reg_save.yml rename to removed/detections/windows_query_registry_reg_save.yml diff --git a/deprecated/detections/windows_service_stop_via_net__and_sc_application.yml b/removed/detections/windows_service_stop_via_net__and_sc_application.yml similarity index 100% rename from deprecated/detections/windows_service_stop_via_net__and_sc_application.yml rename to removed/detections/windows_service_stop_via_net__and_sc_application.yml diff --git a/deprecated/detections/windows_valid_account_with_never_expires_password.yml b/removed/detections/windows_valid_account_with_never_expires_password.yml similarity index 100% rename from deprecated/detections/windows_valid_account_with_never_expires_password.yml rename to removed/detections/windows_valid_account_with_never_expires_password.yml diff --git a/deprecated/detections/winword_spawning_cmd.yml b/removed/detections/winword_spawning_cmd.yml similarity index 100% rename from deprecated/detections/winword_spawning_cmd.yml rename to removed/detections/winword_spawning_cmd.yml diff --git a/deprecated/detections/winword_spawning_powershell.yml b/removed/detections/winword_spawning_powershell.yml similarity index 100% rename from deprecated/detections/winword_spawning_powershell.yml rename to removed/detections/winword_spawning_powershell.yml diff --git a/deprecated/detections/winword_spawning_windows_script_host.yml b/removed/detections/winword_spawning_windows_script_host.yml similarity index 100% rename from deprecated/detections/winword_spawning_windows_script_host.yml rename to removed/detections/winword_spawning_windows_script_host.yml diff --git a/deprecated/investigations/all_backup_logs_for_host.yml b/removed/investigations/all_backup_logs_for_host.yml similarity index 100% rename from deprecated/investigations/all_backup_logs_for_host.yml rename to removed/investigations/all_backup_logs_for_host.yml diff --git a/deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml b/removed/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml similarity index 100% rename from deprecated/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml rename to removed/investigations/amazon_eks_kubernetes_activity_by_src_ip.yml diff --git a/deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml b/removed/investigations/aws_investigate_security_hub_alerts_by_dest.yml similarity index 100% rename from deprecated/investigations/aws_investigate_security_hub_alerts_by_dest.yml rename to removed/investigations/aws_investigate_security_hub_alerts_by_dest.yml diff --git a/deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml b/removed/investigations/aws_investigate_user_activities_by_accesskeyid.yml similarity index 100% rename from deprecated/investigations/aws_investigate_user_activities_by_accesskeyid.yml rename to removed/investigations/aws_investigate_user_activities_by_accesskeyid.yml diff --git a/deprecated/investigations/aws_investigate_user_activities_by_arn.yml b/removed/investigations/aws_investigate_user_activities_by_arn.yml similarity index 100% rename from deprecated/investigations/aws_investigate_user_activities_by_arn.yml rename to removed/investigations/aws_investigate_user_activities_by_arn.yml diff --git a/deprecated/investigations/aws_network_acl_details_from_id.yml b/removed/investigations/aws_network_acl_details_from_id.yml similarity index 100% rename from deprecated/investigations/aws_network_acl_details_from_id.yml rename to removed/investigations/aws_network_acl_details_from_id.yml diff --git a/deprecated/investigations/aws_network_interface_details_via_resourceid.yml b/removed/investigations/aws_network_interface_details_via_resourceid.yml similarity index 100% rename from deprecated/investigations/aws_network_interface_details_via_resourceid.yml rename to removed/investigations/aws_network_interface_details_via_resourceid.yml diff --git a/deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml b/removed/investigations/aws_s3_bucket_details_via_bucketname.yml similarity index 100% rename from deprecated/investigations/aws_s3_bucket_details_via_bucketname.yml rename to removed/investigations/aws_s3_bucket_details_via_bucketname.yml diff --git a/deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml b/removed/investigations/gcp_kubernetes_activity_by_src_ip.yml similarity index 100% rename from deprecated/investigations/gcp_kubernetes_activity_by_src_ip.yml rename to removed/investigations/gcp_kubernetes_activity_by_src_ip.yml diff --git a/deprecated/investigations/get_all_aws_activity_from_city.yml b/removed/investigations/get_all_aws_activity_from_city.yml similarity index 100% rename from deprecated/investigations/get_all_aws_activity_from_city.yml rename to removed/investigations/get_all_aws_activity_from_city.yml diff --git a/deprecated/investigations/get_all_aws_activity_from_country.yml b/removed/investigations/get_all_aws_activity_from_country.yml similarity index 100% rename from deprecated/investigations/get_all_aws_activity_from_country.yml rename to removed/investigations/get_all_aws_activity_from_country.yml diff --git a/deprecated/investigations/get_all_aws_activity_from_ip_address.yml b/removed/investigations/get_all_aws_activity_from_ip_address.yml similarity index 100% rename from deprecated/investigations/get_all_aws_activity_from_ip_address.yml rename to removed/investigations/get_all_aws_activity_from_ip_address.yml diff --git a/deprecated/investigations/get_all_aws_activity_from_region.yml b/removed/investigations/get_all_aws_activity_from_region.yml similarity index 100% rename from deprecated/investigations/get_all_aws_activity_from_region.yml rename to removed/investigations/get_all_aws_activity_from_region.yml diff --git a/deprecated/investigations/get_backup_logs_for_endpoint.yml b/removed/investigations/get_backup_logs_for_endpoint.yml similarity index 100% rename from deprecated/investigations/get_backup_logs_for_endpoint.yml rename to removed/investigations/get_backup_logs_for_endpoint.yml diff --git a/deprecated/investigations/get_certificate_logs_for_a_domain.yml b/removed/investigations/get_certificate_logs_for_a_domain.yml similarity index 100% rename from deprecated/investigations/get_certificate_logs_for_a_domain.yml rename to removed/investigations/get_certificate_logs_for_a_domain.yml diff --git a/deprecated/investigations/get_dns_server_history_for_a_host.yml b/removed/investigations/get_dns_server_history_for_a_host.yml similarity index 100% rename from deprecated/investigations/get_dns_server_history_for_a_host.yml rename to removed/investigations/get_dns_server_history_for_a_host.yml diff --git a/deprecated/investigations/get_dns_traffic_ratio.yml b/removed/investigations/get_dns_traffic_ratio.yml similarity index 100% rename from deprecated/investigations/get_dns_traffic_ratio.yml rename to removed/investigations/get_dns_traffic_ratio.yml diff --git a/deprecated/investigations/get_ec2_instance_details_by_instanceid.yml b/removed/investigations/get_ec2_instance_details_by_instanceid.yml similarity index 100% rename from deprecated/investigations/get_ec2_instance_details_by_instanceid.yml rename to removed/investigations/get_ec2_instance_details_by_instanceid.yml diff --git a/deprecated/investigations/get_ec2_launch_details.yml b/removed/investigations/get_ec2_launch_details.yml similarity index 100% rename from deprecated/investigations/get_ec2_launch_details.yml rename to removed/investigations/get_ec2_launch_details.yml diff --git a/deprecated/investigations/get_email_info.yml b/removed/investigations/get_email_info.yml similarity index 100% rename from deprecated/investigations/get_email_info.yml rename to removed/investigations/get_email_info.yml diff --git a/deprecated/investigations/get_emails_from_specific_sender.yml b/removed/investigations/get_emails_from_specific_sender.yml similarity index 100% rename from deprecated/investigations/get_emails_from_specific_sender.yml rename to removed/investigations/get_emails_from_specific_sender.yml diff --git a/deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml b/removed/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml similarity index 100% rename from deprecated/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml rename to removed/investigations/get_first_occurrence_and_last_occurrence_of_a_mac_address.yml diff --git a/deprecated/investigations/get_history_of_email_sources.yml b/removed/investigations/get_history_of_email_sources.yml similarity index 100% rename from deprecated/investigations/get_history_of_email_sources.yml rename to removed/investigations/get_history_of_email_sources.yml diff --git a/deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml b/removed/investigations/get_logon_rights_modifications_for_endpoint.yml similarity index 100% rename from deprecated/investigations/get_logon_rights_modifications_for_endpoint.yml rename to removed/investigations/get_logon_rights_modifications_for_endpoint.yml diff --git a/deprecated/investigations/get_logon_rights_modifications_for_user.yml b/removed/investigations/get_logon_rights_modifications_for_user.yml similarity index 100% rename from deprecated/investigations/get_logon_rights_modifications_for_user.yml rename to removed/investigations/get_logon_rights_modifications_for_user.yml diff --git a/deprecated/investigations/get_notable_history.yml b/removed/investigations/get_notable_history.yml similarity index 100% rename from deprecated/investigations/get_notable_history.yml rename to removed/investigations/get_notable_history.yml diff --git a/deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml b/removed/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml similarity index 100% rename from deprecated/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml rename to removed/investigations/get_outbound_emails_to_hidden_cobra_threat_actors.yml diff --git a/deprecated/investigations/get_parent_process_info.yml b/removed/investigations/get_parent_process_info.yml similarity index 100% rename from deprecated/investigations/get_parent_process_info.yml rename to removed/investigations/get_parent_process_info.yml diff --git a/deprecated/investigations/get_process_file_activity.yml b/removed/investigations/get_process_file_activity.yml similarity index 100% rename from deprecated/investigations/get_process_file_activity.yml rename to removed/investigations/get_process_file_activity.yml diff --git a/deprecated/investigations/get_process_info.yml b/removed/investigations/get_process_info.yml similarity index 100% rename from deprecated/investigations/get_process_info.yml rename to removed/investigations/get_process_info.yml diff --git a/deprecated/investigations/get_process_information_for_port_activity.yml b/removed/investigations/get_process_information_for_port_activity.yml similarity index 100% rename from deprecated/investigations/get_process_information_for_port_activity.yml rename to removed/investigations/get_process_information_for_port_activity.yml diff --git a/deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml b/removed/investigations/get_process_responsible_for_the_dns_traffic.yml similarity index 100% rename from deprecated/investigations/get_process_responsible_for_the_dns_traffic.yml rename to removed/investigations/get_process_responsible_for_the_dns_traffic.yml diff --git a/deprecated/investigations/get_sysmon_wmi_activity_for_host.yml b/removed/investigations/get_sysmon_wmi_activity_for_host.yml similarity index 100% rename from deprecated/investigations/get_sysmon_wmi_activity_for_host.yml rename to removed/investigations/get_sysmon_wmi_activity_for_host.yml diff --git a/deprecated/investigations/get_web_session_information_via_session_id.yml b/removed/investigations/get_web_session_information_via_session_id.yml similarity index 100% rename from deprecated/investigations/get_web_session_information_via_session_id.yml rename to removed/investigations/get_web_session_information_via_session_id.yml diff --git a/deprecated/investigations/investigate_aws_activities_via_region_name.yml b/removed/investigations/investigate_aws_activities_via_region_name.yml similarity index 100% rename from deprecated/investigations/investigate_aws_activities_via_region_name.yml rename to removed/investigations/investigate_aws_activities_via_region_name.yml diff --git a/deprecated/investigations/investigate_aws_user_activities_by_user_field.yml b/removed/investigations/investigate_aws_user_activities_by_user_field.yml similarity index 100% rename from deprecated/investigations/investigate_aws_user_activities_by_user_field.yml rename to removed/investigations/investigate_aws_user_activities_by_user_field.yml diff --git a/deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml b/removed/investigations/investigate_failed_logins_for_multiple_destinations.yml similarity index 100% rename from deprecated/investigations/investigate_failed_logins_for_multiple_destinations.yml rename to removed/investigations/investigate_failed_logins_for_multiple_destinations.yml diff --git a/deprecated/investigations/investigate_network_traffic_from_src_ip.yml b/removed/investigations/investigate_network_traffic_from_src_ip.yml similarity index 100% rename from deprecated/investigations/investigate_network_traffic_from_src_ip.yml rename to removed/investigations/investigate_network_traffic_from_src_ip.yml diff --git a/deprecated/investigations/investigate_okta_activity_by_app.yml b/removed/investigations/investigate_okta_activity_by_app.yml similarity index 100% rename from deprecated/investigations/investigate_okta_activity_by_app.yml rename to removed/investigations/investigate_okta_activity_by_app.yml diff --git a/deprecated/investigations/investigate_okta_activity_by_ip_address.yml b/removed/investigations/investigate_okta_activity_by_ip_address.yml similarity index 100% rename from deprecated/investigations/investigate_okta_activity_by_ip_address.yml rename to removed/investigations/investigate_okta_activity_by_ip_address.yml diff --git a/deprecated/investigations/investigate_pass_the_hash_attempts.yml b/removed/investigations/investigate_pass_the_hash_attempts.yml similarity index 100% rename from deprecated/investigations/investigate_pass_the_hash_attempts.yml rename to removed/investigations/investigate_pass_the_hash_attempts.yml diff --git a/deprecated/investigations/investigate_pass_the_ticket_attempts.yml b/removed/investigations/investigate_pass_the_ticket_attempts.yml similarity index 100% rename from deprecated/investigations/investigate_pass_the_ticket_attempts.yml rename to removed/investigations/investigate_pass_the_ticket_attempts.yml diff --git a/deprecated/investigations/investigate_previous_unseen_user.yml b/removed/investigations/investigate_previous_unseen_user.yml similarity index 100% rename from deprecated/investigations/investigate_previous_unseen_user.yml rename to removed/investigations/investigate_previous_unseen_user.yml diff --git a/deprecated/investigations/investigate_successful_remote_desktop_authentications.yml b/removed/investigations/investigate_successful_remote_desktop_authentications.yml similarity index 100% rename from deprecated/investigations/investigate_successful_remote_desktop_authentications.yml rename to removed/investigations/investigate_successful_remote_desktop_authentications.yml diff --git a/deprecated/investigations/investigate_suspicious_strings_in_http_header.yml b/removed/investigations/investigate_suspicious_strings_in_http_header.yml similarity index 100% rename from deprecated/investigations/investigate_suspicious_strings_in_http_header.yml rename to removed/investigations/investigate_suspicious_strings_in_http_header.yml diff --git a/deprecated/investigations/investigate_user_activities_in_okta.yml b/removed/investigations/investigate_user_activities_in_okta.yml similarity index 100% rename from deprecated/investigations/investigate_user_activities_in_okta.yml rename to removed/investigations/investigate_user_activities_in_okta.yml diff --git a/deprecated/investigations/investigate_web_posts_from_src.yml b/removed/investigations/investigate_web_posts_from_src.yml similarity index 100% rename from deprecated/investigations/investigate_web_posts_from_src.yml rename to removed/investigations/investigate_web_posts_from_src.yml diff --git a/deprecated/stories/aws_cryptomining.yml b/removed/stories/aws_cryptomining.yml similarity index 100% rename from deprecated/stories/aws_cryptomining.yml rename to removed/stories/aws_cryptomining.yml diff --git a/deprecated/stories/aws_suspicious_provisioning_activities.yml b/removed/stories/aws_suspicious_provisioning_activities.yml similarity index 100% rename from deprecated/stories/aws_suspicious_provisioning_activities.yml rename to removed/stories/aws_suspicious_provisioning_activities.yml diff --git a/deprecated/stories/common_phishing_frameworks.yml b/removed/stories/common_phishing_frameworks.yml similarity index 100% rename from deprecated/stories/common_phishing_frameworks.yml rename to removed/stories/common_phishing_frameworks.yml diff --git a/deprecated/stories/container_implantation_monitoring_and_investigation.yml b/removed/stories/container_implantation_monitoring_and_investigation.yml similarity index 100% rename from deprecated/stories/container_implantation_monitoring_and_investigation.yml rename to removed/stories/container_implantation_monitoring_and_investigation.yml diff --git a/deprecated/stories/host_redirection.yml b/removed/stories/host_redirection.yml similarity index 100% rename from deprecated/stories/host_redirection.yml rename to removed/stories/host_redirection.yml diff --git a/deprecated/stories/kubernetes_sensitive_role_activity.yml b/removed/stories/kubernetes_sensitive_role_activity.yml similarity index 100% rename from deprecated/stories/kubernetes_sensitive_role_activity.yml rename to removed/stories/kubernetes_sensitive_role_activity.yml diff --git a/deprecated/stories/lateral_movement.yml b/removed/stories/lateral_movement.yml similarity index 100% rename from deprecated/stories/lateral_movement.yml rename to removed/stories/lateral_movement.yml diff --git a/deprecated/stories/monitor_backup_solution.yml b/removed/stories/monitor_backup_solution.yml similarity index 100% rename from deprecated/stories/monitor_backup_solution.yml rename to removed/stories/monitor_backup_solution.yml diff --git a/deprecated/stories/monitor_for_unauthorized_software.yml b/removed/stories/monitor_for_unauthorized_software.yml similarity index 100% rename from deprecated/stories/monitor_for_unauthorized_software.yml rename to removed/stories/monitor_for_unauthorized_software.yml diff --git a/deprecated/stories/office_365_detections.yml b/removed/stories/office_365_detections.yml similarity index 100% rename from deprecated/stories/office_365_detections.yml rename to removed/stories/office_365_detections.yml diff --git a/deprecated/stories/spectre_and_meltdown_vulnerabilities.yml b/removed/stories/spectre_and_meltdown_vulnerabilities.yml similarity index 100% rename from deprecated/stories/spectre_and_meltdown_vulnerabilities.yml rename to removed/stories/spectre_and_meltdown_vulnerabilities.yml diff --git a/deprecated/stories/suspicious_aws_ec2_activities.yml b/removed/stories/suspicious_aws_ec2_activities.yml similarity index 100% rename from deprecated/stories/suspicious_aws_ec2_activities.yml rename to removed/stories/suspicious_aws_ec2_activities.yml diff --git a/deprecated/stories/unusual_aws_ec2_modifications.yml b/removed/stories/unusual_aws_ec2_modifications.yml similarity index 100% rename from deprecated/stories/unusual_aws_ec2_modifications.yml rename to removed/stories/unusual_aws_ec2_modifications.yml diff --git a/deprecated/stories/web_fraud_detection.yml b/removed/stories/web_fraud_detection.yml similarity index 100% rename from deprecated/stories/web_fraud_detection.yml rename to removed/stories/web_fraud_detection.yml From f096d77d6f7485cc6b235ffc2e72298c99b21386 Mon Sep 17 00:00:00 2001 From: Eric Date: Tue, 18 Mar 2025 14:25:56 -0700 Subject: [PATCH 64/67] Changed the names of some fields due to the use of both deprecated and removed to refer to content in different stages of removal --- removed/deprecation_mapping.YML | 1004 +++++++++++++++---------------- 1 file changed, 502 insertions(+), 502 deletions(-) diff --git a/removed/deprecation_mapping.YML b/removed/deprecation_mapping.YML index e070b62001..73220d59fb 100644 --- a/removed/deprecation_mapping.YML +++ b/removed/deprecation_mapping.YML @@ -1,248 +1,248 @@ detections: - - deprecated_content: Open Redirect in Splunk Web - deprecated_in_version: 5.2.0 + - content: Open Redirect in Splunk Web + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Splunk Enterprise Information Disclosure - deprecated_in_version: 5.2.0 + - content: Splunk Enterprise Information Disclosure + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: ASL AWS Excessive Security Scanning - deprecated_in_version: 5.2.0 + - content: ASL AWS Excessive Security Scanning + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: AWS Cloud Provisioning From Previously Unseen Region - deprecated_in_version: 5.2.0 + - content: AWS Cloud Provisioning From Previously Unseen Region + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen Region - - deprecated_content: First time seen command line argument - deprecated_in_version: 5.2.0 + - content: First time seen command line argument + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Windows connhost exe started forcefully - deprecated_in_version: 5.2.0 + - content: Windows connhost exe started forcefully + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Detect Mimikatz Using Loaded Images - deprecated_in_version: 5.2.0 + - content: Detect Mimikatz Using Loaded Images + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Kubernetes Azure detect sensitive role access - deprecated_in_version: 5.2.0 + - content: Kubernetes Azure detect sensitive role access + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Web Fraud - Anomalous User Clickspeed - deprecated_in_version: 5.2.0 + - content: Web Fraud - Anomalous User Clickspeed + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: EC2 Instance Started With Previously Unseen Instance Type - deprecated_in_version: 5.2.0 + - content: EC2 Instance Started With Previously Unseen Instance Type + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created With Previously Unseen Instance Type - - deprecated_content: EC2 Instance Started With Previously Unseen AMI - deprecated_in_version: 5.2.0 + - content: EC2 Instance Started With Previously Unseen AMI + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created With Previously Unseen Image - - deprecated_content: Domain Group Discovery With Net - deprecated_in_version: 5.2.0 + - content: Domain Group Discovery With Net + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Group Discovery Via Net - - deprecated_content: Kubernetes AWS detect sensitive role access - deprecated_in_version: 5.2.0 + - content: Kubernetes AWS detect sensitive role access + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Winword Spawning Windows Script Host - deprecated_in_version: 5.2.0 + - content: Winword Spawning Windows Script Host + removed_in_version: 5.2.0 reason: "The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level.\nThis would ease management and false positives tuning." replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: Winword Spawning PowerShell - deprecated_in_version: 5.2.0 + - content: Winword Spawning PowerShell + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: Attempted Credential Dump From Registry via Reg exe - deprecated_in_version: 5.2.0 + - content: Attempted Credential Dump From Registry via Reg exe + removed_in_version: 5.2.0 reason: This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine replacement_content: - Windows Sensitive Registry Hive Dump Via CommandLine - - deprecated_content: Detect processes used for System Network Configuration Discovery - deprecated_in_version: 5.2.0 + - content: Detect processes used for System Network Configuration Discovery + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Potential System Network Configuration Discovery Activity - - deprecated_content: Execution of File With Spaces Before Extension - deprecated_in_version: 5.2.0 + - content: Execution of File With Spaces Before Extension + removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Execution of File with Multiple Extensions - - deprecated_content: EC2 Instance Started In Previously Unseen Region - deprecated_in_version: 5.2.0 + - content: EC2 Instance Started In Previously Unseen Region + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created In Previously Unused Region - - deprecated_content: Office Document Spawned Child Process To Download - deprecated_in_version: 5.2.0 + - content: Office Document Spawned Child Process To Download + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Child Process For Download - - deprecated_content: Detect new API calls from user roles - deprecated_in_version: 5.2.0 + - content: Detect new API calls from user roles + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud API Calls From Previously Unseen User Roles - - deprecated_content: Cmdline Tool Not Executed In CMD Shell - deprecated_in_version: 5.2.0 + - content: Cmdline Tool Not Executed In CMD Shell + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Cmdline Tool Execution From Non-Shell Process - - deprecated_content: Linux Auditd Find Private Keys - deprecated_in_version: 5.2.0 + - content: Linux Auditd Find Private Keys + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Linux Auditd Private Keys and Certificate Enumeration - - deprecated_content: Detect AWS API Activities From Unapproved Accounts - deprecated_in_version: 5.2.0 + - content: Detect AWS API Activities From Unapproved Accounts + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Monitor DNS For Brand Abuse - deprecated_in_version: 5.2.0 + - content: Monitor DNS For Brand Abuse + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Kubernetes GCP detect sensitive object access - deprecated_in_version: 5.2.0 + - content: Kubernetes GCP detect sensitive object access + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Kubernetes Azure scan fingerprint - deprecated_in_version: 5.2.0 + - content: Kubernetes Azure scan fingerprint + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: ASL AWS Password Policy Changes - deprecated_in_version: 5.2.0 + - content: ASL AWS Password Policy Changes + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: O365 Suspicious Admin Email Forwarding - deprecated_in_version: 5.2.0 + - content: O365 Suspicious Admin Email Forwarding + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Mailbox Email Forwarding Enabled - - deprecated_content: AWS Cloud Provisioning From Previously Unseen City - deprecated_in_version: 5.2.0 + - content: AWS Cloud Provisioning From Previously Unseen City + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen City - - deprecated_content: Kubernetes AWS detect service accounts forbidden failure access - deprecated_in_version: 5.2.0 + - content: Kubernetes AWS detect service accounts forbidden failure access + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Osquery pack - ColdRoot detection - deprecated_in_version: 5.2.0 + - content: Osquery pack - ColdRoot detection + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Windows Modify Registry Reg Restore - deprecated_in_version: 5.2.0 + - content: Windows Modify Registry Reg Restore + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Registry Entries Restored Via Reg - - deprecated_content: Kubernetes GCP detect most active service accounts by pod - deprecated_in_version: 5.2.0 + - content: Kubernetes GCP detect most active service accounts by pod + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Scheduled tasks used in BadRabbit ransomware - deprecated_in_version: 5.2.0 + - content: Scheduled tasks used in BadRabbit ransomware + removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Scheduled Task Deleted Or Created via CMD - - deprecated_content: Suspicious Rundll32 Rename - deprecated_in_version: 5.2.0 + - content: Suspicious Rundll32 Rename + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Remote System Discovery with Net - deprecated_in_version: 5.2.0 + - content: Remote System Discovery with Net + removed_in_version: 5.2.0 reason: "This analytic was focusing on 2 separate and unrelated type of threats or actions. PLease use the replacement content" replacement_content: - Windows Sensitive Group Discovery With Net - - deprecated_content: DNS Query Requests Resolved by Unauthorized DNS Servers - deprecated_in_version: 5.2.0 + - content: DNS Query Requests Resolved by Unauthorized DNS Servers + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Suspicious Changes to File Associations - deprecated_in_version: 5.2.0 + - content: Suspicious Changes to File Associations + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: GCP Detect high risk permissions by resource and account - deprecated_in_version: 5.2.0 + - content: GCP Detect high risk permissions by resource and account + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Office Product Writing cab or inf - deprecated_in_version: 5.2.0 + - content: Office Product Writing cab or inf + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Dropped Cab or Inf File - - deprecated_content: Identify New User Accounts - deprecated_in_version: 5.2.0 + - content: Identify New User Accounts + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Office Product Spawn CMD Process - deprecated_in_version: 5.2.0 + - content: Office Product Spawn CMD Process + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: Windows DLL Search Order Hijacking Hunt - deprecated_in_version: 5.2.0 + - content: Windows DLL Search Order Hijacking Hunt + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Windows DLL Search Order Hijacking Hunt with Sysmon - - deprecated_content: ASL AWS CreateAccessKey - deprecated_in_version: 5.2.0 + - content: ASL AWS CreateAccessKey + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - ASL AWS Create Access Key - - deprecated_content: Okta ThreatInsight Login Failure with High Unknown users - deprecated_in_version: 5.2.0 + - content: Okta ThreatInsight Login Failure with High Unknown users + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Detect Spike in Security Group Activity - deprecated_in_version: 5.2.0 + - content: Detect Spike in Security Group Activity + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Security Group API Calls - - deprecated_content: Office Product Spawning BITSAdmin - deprecated_in_version: 5.2.0 + - content: Office Product Spawning BITSAdmin + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: Create local admin accounts using net exe - deprecated_in_version: 5.2.0 + - content: Create local admin accounts using net exe + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Create Local Administrator Account Via Net - - deprecated_content: Abnormally High AWS Instances Terminated by User - MLTK - deprecated_in_version: 5.2.0 + - content: Abnormally High AWS Instances Terminated by User - MLTK + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Windows Office Product Spawning MSDT - deprecated_in_version: 5.2.0 + - content: Windows Office Product Spawning MSDT + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned MSDT - - deprecated_content: Detect Spike in AWS API Activity - deprecated_in_version: 5.2.0 + - content: Detect Spike in AWS API Activity + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Office Product Spawning Windows Script Host - deprecated_in_version: 5.2.0 + - content: Office Product Spawning Windows Script Host + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: Prohibited Software On Endpoint - deprecated_in_version: 5.2.0 + - content: Prohibited Software On Endpoint + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Attacker Tools On Endpoint - - deprecated_content: AWS Cloud Provisioning From Previously Unseen Country - deprecated_in_version: 5.2.0 + - content: AWS Cloud Provisioning From Previously Unseen Country + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen Country - - deprecated_content: Detect Critical Alerts from Security Tools - deprecated_in_version: 5.2.0 + - content: Detect Critical Alerts from Security Tools + removed_in_version: 5.2.0 reason: As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender @@ -250,759 +250,759 @@ detections: have their specific analytics. replacement_content: - Microsoft Defender ATP Alerts - - deprecated_content: Detect Critical Alerts from Security Tools - deprecated_in_version: 5.2.0 + - content: Detect Critical Alerts from Security Tools + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Microsoft Defender Incident Alerts - - deprecated_content: Excel Spawning PowerShell - deprecated_in_version: 5.2.0 + - content: Excel Spawning PowerShell + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: Office Application Spawn rundll32 process - deprecated_in_version: 5.2.0 + - content: Office Application Spawn rundll32 process + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: Excessive Usage Of Net App - deprecated_in_version: 5.2.0 + - content: Excessive Usage Of Net App + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Excessive Usage Of Net App - - deprecated_content: Elevated Group Discovery With Net - deprecated_in_version: 5.2.0 + - content: Elevated Group Discovery With Net + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Sensitive Group Discovery With Net - - deprecated_content: Local Account Discovery with Net - deprecated_in_version: 5.2.0 + - content: Local Account Discovery with Net + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows User Discovery Via Net - - deprecated_content: Windows Command Shell Fetch Env Variables - deprecated_in_version: 5.2.0 + - content: Windows Command Shell Fetch Env Variables + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows List ENV Variables Via SET Command From Uncommon Parent - - deprecated_content: Suspicious Email - UBA Anomaly - deprecated_in_version: 5.2.0 + - content: Suspicious Email - UBA Anomaly + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Detect web traffic to dynamic domain providers - deprecated_in_version: 5.2.0 + - content: Detect web traffic to dynamic domain providers + removed_in_version: 5.2.0 reason: Updated to use a different log source replacement_content: - Detect hosts connecting to dynamic domain providers - - deprecated_content: Okta Failed SSO Attempts - deprecated_in_version: 5.2.0 + - content: Okta Failed SSO Attempts + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Unauthorized Access to Application - - deprecated_content: Kubernetes AWS detect RBAC authorization by account - deprecated_in_version: 5.2.0 + - content: Kubernetes AWS detect RBAC authorization by account + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Kubernetes Azure detect service accounts forbidden failure access - deprecated_in_version: 5.2.0 + - content: Kubernetes Azure detect service accounts forbidden failure access + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Remote Registry Key modifications - deprecated_in_version: 5.2.0 + - content: Remote Registry Key modifications + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: O365 Suspicious User Email Forwarding - deprecated_in_version: 5.2.0 + - content: O365 Suspicious User Email Forwarding + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Mailbox Email Forwarding Enabled - - deprecated_content: Office Product Spawning MSHTA - deprecated_in_version: 5.2.0 + - content: Office Product Spawning MSHTA + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: Kubernetes AWS detect most active service accounts by pod - deprecated_in_version: 5.2.0 + - content: Kubernetes AWS detect most active service accounts by pod + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Correlation by Repository and Risk - deprecated_in_version: 5.2.0 + - content: Correlation by Repository and Risk + removed_in_version: 5.2.0 reason: Detections updated to use the datamodel replacement_content: - Risk Rule for Dev Sec Ops by Repository - - deprecated_content: Kubernetes Azure detect RBAC authorization by account - deprecated_in_version: 5.2.0 + - content: Kubernetes Azure detect RBAC authorization by account + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Clients Connecting to Multiple DNS Servers - deprecated_in_version: 5.2.0 + - content: Clients Connecting to Multiple DNS Servers + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Excessive Service Stop Attempt - deprecated_in_version: 5.2.0 + - content: Excessive Service Stop Attempt + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Excessive Service Stop Attempt - - deprecated_content: Multiple Okta Users With Invalid Credentials From The Same IP - deprecated_in_version: 5.2.0 + - content: Multiple Okta Users With Invalid Credentials From The Same IP + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Users Failing To Authenticate From Ip - - deprecated_content: Suspicious writes to System Volume Information - deprecated_in_version: 5.2.0 + - content: Suspicious writes to System Volume Information + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Detect new user AWS Console Login - deprecated_in_version: 5.2.0 + - content: Detect new user AWS Console Login + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Detect AWS Console Login by New User - - deprecated_content: Domain Account Discovery With Net App - deprecated_in_version: 5.2.0 + - content: Domain Account Discovery With Net App + removed_in_version: 5.2.0 reason: "This analytic was a TTP that looked only for commands that tries to query info about the users via net user /do. This had a couple of issues, such as triggering on creation of users via the /add flag etc..\nIt was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122" replacement_content: - Windows User Discovery Via Net - - deprecated_content: Detection of DNS Tunnels - deprecated_in_version: 5.2.0 + - content: Detection of DNS Tunnels + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Detect DNS requests to Phishing Sites leveraging EvilGinx2 - deprecated_in_version: 5.2.0 + - content: Detect DNS requests to Phishing Sites leveraging EvilGinx2 + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Office Document Creating Schedule Task - deprecated_in_version: 5.2.0 + - content: Office Document Creating Schedule Task + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Loading Taskschd DLL - - deprecated_content: Okta Account Locked Out - deprecated_in_version: 5.2.0 + - content: Okta Account Locked Out + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Accounts Locked Out - - deprecated_content: Unsuccessful Netbackup backups - deprecated_in_version: 5.2.0 + - content: Unsuccessful Netbackup backups + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Detect Mimikatz Via PowerShell And EventCode 4703 - deprecated_in_version: 5.2.0 + - content: Detect Mimikatz Via PowerShell And EventCode 4703 + removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Detect Mimikatz With PowerShell Script Block Logging - - deprecated_content: Winword Spawning Cmd - deprecated_in_version: 5.2.0 + - content: Winword Spawning Cmd + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: GCP Kubernetes cluster scan detection - deprecated_in_version: 5.2.0 + - content: GCP Kubernetes cluster scan detection + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Kubernetes Scanning by Unauthenticated IP Address - - deprecated_content: Kubernetes GCP detect suspicious kubectl calls - deprecated_in_version: 5.2.0 + - content: Kubernetes GCP detect suspicious kubectl calls + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: gcp detect oauth token abuse - deprecated_in_version: 5.2.0 + - content: gcp detect oauth token abuse + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Correlation by User and Risk - deprecated_in_version: 5.2.0 + - content: Correlation by User and Risk + removed_in_version: 5.2.0 reason: Detections updated to use the datamodel replacement_content: - Risk Rule for Dev Sec Ops by Repository - - deprecated_content: Processes created by netsh - deprecated_in_version: 5.2.0 + - content: Processes created by netsh + removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Processes launching netsh - - deprecated_content: Office Product Spawning Wmic - deprecated_in_version: 5.2.0 + - content: Office Product Spawning Wmic + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: Extraction of Registry Hives - deprecated_in_version: 5.2.0 + - content: Extraction of Registry Hives + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Sensitive Registry Hive Dump Via CommandLine - - deprecated_content: Attempt To Stop Security Service - deprecated_in_version: 5.2.0 + - content: Attempt To Stop Security Service + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Attempt To Stop Security Service - - deprecated_content: Windows MSIExec With Network Connections - deprecated_in_version: 5.2.0 + - content: Windows MSIExec With Network Connections + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows HTTP Network Communication From MSIExec - - deprecated_content: Windows Query Registry Reg Save - deprecated_in_version: 5.2.0 + - content: Windows Query Registry Reg Save + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Registry Entries Exported Via Reg - - deprecated_content: Cloud Network Access Control List Deleted - deprecated_in_version: 5.2.0 + - content: Cloud Network Access Control List Deleted + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - AWS Network Access Control List Deleted - - deprecated_content: O365 Suspicious Rights Delegation - deprecated_in_version: 5.2.0 + - content: O365 Suspicious Rights Delegation + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Elevated Mailbox Permission Assigned - - deprecated_content: Abnormally High AWS Instances Launched by User - MLTK - deprecated_in_version: 5.2.0 + - content: Abnormally High AWS Instances Launched by User - MLTK + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Reg exe used to hide files directories via registry keys - deprecated_in_version: 5.2.0 + - content: Reg exe used to hide files directories via registry keys + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Detect Long DNS TXT Record Response - deprecated_in_version: 5.2.0 + - content: Detect Long DNS TXT Record Response + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Password Policy Discovery with Net - deprecated_in_version: 5.2.0 + - content: Password Policy Discovery with Net + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Password Policy Discovery with Net - - deprecated_content: AWS Cloud Provisioning From Previously Unseen IP Address - deprecated_in_version: 5.2.0 + - content: AWS Cloud Provisioning From Previously Unseen IP Address + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen IP Address - - deprecated_content: Network Connection Discovery With Net - deprecated_in_version: 5.2.0 + - content: Network Connection Discovery With Net + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Network Connection Discovery Via Net - - deprecated_content: Kubernetes Azure detect suspicious kubectl calls - deprecated_in_version: 5.2.0 + - content: Kubernetes Azure detect suspicious kubectl calls + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Kubernetes GCP detect sensitive role access - deprecated_in_version: 5.2.0 + - content: Kubernetes GCP detect sensitive role access + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Detect Webshell Exploit Behavior - deprecated_in_version: 5.2.0 + - content: Detect Webshell Exploit Behavior + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Suspicious Child Process Spawned From WebServer - - deprecated_content: DNS record changed - deprecated_in_version: 5.2.0 + - content: DNS record changed + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Unsigned Image Loaded by LSASS - deprecated_in_version: 5.2.0 + - content: Unsigned Image Loaded by LSASS + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Detect USB device insertion - deprecated_in_version: 5.2.0 + - content: Detect USB device insertion + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Windows Network Share Interaction With Net - deprecated_in_version: 5.2.0 + - content: Windows Network Share Interaction With Net + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Network Share Interaction Via Net - - deprecated_content: Account Discovery With Net App - deprecated_in_version: 5.2.0 + - content: Account Discovery With Net App + removed_in_version: 5.2.0 reason: This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 / Windows Excessive Usage Of Net App. replacement_content: - Windows Excessive Usage Of Net App - - deprecated_content: Change Default File Association - deprecated_in_version: 5.2.0 + - content: Change Default File Association + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows New Default File Association Value Set - - deprecated_content: Windows Lateral Tool Transfer RemCom - deprecated_in_version: 5.2.0 + - content: Windows Lateral Tool Transfer RemCom + removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Windows Service Execution RemCom - - deprecated_content: Office Document Executing Macro Code - deprecated_in_version: 5.2.0 + - content: Office Document Executing Macro Code + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Loading VBE7 DLL - - deprecated_content: Okta Account Lockout Events - deprecated_in_version: 5.2.0 + - content: Okta Account Lockout Events + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Accounts Locked Out - - deprecated_content: Abnormally High AWS Instances Launched by User - deprecated_in_version: 5.2.0 + - content: Abnormally High AWS Instances Launched by User + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Instances Launched - - deprecated_content: EC2 Instance Modified With Previously Unseen User - deprecated_in_version: 5.2.0 + - content: EC2 Instance Modified With Previously Unseen User + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud API Calls From Previously Unseen User Roles - - deprecated_content: Windows Valid Account With Never Expires Password - deprecated_in_version: 5.2.0 + - content: Windows Valid Account With Never Expires Password + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Set Account Password Policy To Unlimited Via Net - - deprecated_content: Windows hosts file modification - deprecated_in_version: 5.2.0 + - content: Windows hosts file modification + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: MSHTML Module Load in Office Product - deprecated_in_version: 5.2.0 + - content: MSHTML Module Load in Office Product + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Loaded MSHTML Module - - deprecated_content: Abnormally High AWS Instances Terminated by User - deprecated_in_version: 5.2.0 + - content: Abnormally High AWS Instances Terminated by User + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Instances Destroyed - - deprecated_content: Web Fraud - Account Harvesting - deprecated_in_version: 5.2.0 + - content: Web Fraud - Account Harvesting + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Office Spawning Control - deprecated_in_version: 5.2.0 + - content: Office Spawning Control + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Control - - deprecated_content: Detect Activity Related to Pass the Hash Attacks - deprecated_in_version: 5.2.0 + - content: Detect Activity Related to Pass the Hash Attacks + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Deleting Of Net Users - deprecated_in_version: 5.2.0 + - content: Deleting Of Net Users + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows User Deletion Via Net - - deprecated_content: Suspicious File Write - deprecated_in_version: 5.2.0 + - content: Suspicious File Write + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: AWS EKS Kubernetes cluster sensitive object access - deprecated_in_version: 5.2.0 + - content: AWS EKS Kubernetes cluster sensitive object access + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Kubernetes Abuse of Secret by Unusual Location - - deprecated_content: Spectre and Meltdown Vulnerable Systems - deprecated_in_version: 5.2.0 + - content: Spectre and Meltdown Vulnerable Systems + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: EC2 Instance Started With Previously Unseen User - deprecated_in_version: 5.2.0 + - content: EC2 Instance Started With Previously Unseen User + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created By Previously Unseen User - - deprecated_content: Office Product Spawning CertUtil - deprecated_in_version: 5.2.0 + - content: Office Product Spawning CertUtil + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: Kubernetes GCP detect RBAC authorizations by account - deprecated_in_version: 5.2.0 + - content: Kubernetes GCP detect RBAC authorizations by account + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Office Application Drop Executable - deprecated_in_version: 5.2.0 + - content: Office Application Drop Executable + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Dropped Uncommon File - - deprecated_content: Kubernetes Azure active service accounts by pod namespace - deprecated_in_version: 5.2.0 + - content: Kubernetes Azure active service accounts by pod namespace + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Kubernetes Azure pod scan fingerprint - deprecated_in_version: 5.2.0 + - content: Kubernetes Azure pod scan fingerprint + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Detect Spike in Network ACL Activity - deprecated_in_version: 5.2.0 + - content: Detect Spike in Network ACL Activity + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Infrastructure API Calls - - deprecated_content: Suspicious Powershell Command-Line Arguments - deprecated_in_version: 5.2.0 + - content: Suspicious Powershell Command-Line Arguments + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Malicious PowerShell Process - Encoded Command - - deprecated_content: Office Application Spawn Regsvr32 process - deprecated_in_version: 5.2.0 + - content: Office Application Spawn Regsvr32 process + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - - deprecated_content: Detect API activity from users without MFA - deprecated_in_version: 5.2.0 + - content: Detect API activity from users without MFA + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - AWS Successful Single-Factor Authentication - - deprecated_content: Kubernetes Azure detect sensitive object access - deprecated_in_version: 5.2.0 + - content: Kubernetes Azure detect sensitive object access + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Web Fraud - Password Sharing Across Accounts - deprecated_in_version: 5.2.0 + - content: Web Fraud - Password Sharing Across Accounts + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Disabling Net User Account - deprecated_in_version: 5.2.0 + - content: Disabling Net User Account + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows User Disabled Via Net - - deprecated_content: GCP Detect accounts with high risk roles by project - deprecated_in_version: 5.2.0 + - content: GCP Detect accounts with high risk roles by project + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Kubernetes GCP detect service accounts forbidden failure access - deprecated_in_version: 5.2.0 + - content: Kubernetes GCP detect service accounts forbidden failure access + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Extended Period Without Successful Netbackup Backups - deprecated_in_version: 5.2.0 + - content: Extended Period Without Successful Netbackup Backups + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Office Product Spawning Rundll32 with no DLL - deprecated_in_version: 5.2.0 + - content: Office Product Spawning Rundll32 with no DLL + removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Rundll32 With No DLL - - deprecated_content: Okta ThreatInsight Suspected PasswordSpray Attack - deprecated_in_version: 5.2.0 + - content: Okta ThreatInsight Suspected PasswordSpray Attack + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta ThreatInsight Threat Detected - - deprecated_content: Net Localgroup Discovery - deprecated_in_version: 5.2.0 + - content: Net Localgroup Discovery + removed_in_version: 5.2.0 reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net replacement_content: - Windows Group Discovery Via Net - - deprecated_content: Uncommon Processes On Endpoint - deprecated_in_version: 5.2.0 + - content: Uncommon Processes On Endpoint + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Attacker Tools On Endpoint - - deprecated_content: Dump LSASS via procdump Rename - deprecated_in_version: 5.2.0 + - content: Dump LSASS via procdump Rename + removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Dump LSASS via procdump - - deprecated_content: Okta Two or More Rejected Okta Pushes - deprecated_in_version: 5.2.0 + - content: Okta Two or More Rejected Okta Pushes + removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Failed MFA Requests For User - - deprecated_content: Windows Service Stop Via Net and SC Application - deprecated_in_version: 5.2.0 + - content: Windows Service Stop Via Net and SC Application + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Excel Spawning Windows Script Host - deprecated_in_version: 5.2.0 + - content: Excel Spawning Windows Script Host + removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: GitHub Actions Disable Security Workflow - deprecated_in_version: 5.4.0 + - content: GitHub Actions Disable Security Workflow + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Github Commit Changes In Master - deprecated_in_version: 5.4.0 + - content: Github Commit Changes In Master + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Github Commit In Develop - deprecated_in_version: 5.4.0 + - content: Github Commit In Develop + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: GitHub Dependabot Alert - deprecated_in_version: 5.4.0 + - content: GitHub Dependabot Alert + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: GitHub Pull Request from Unknown User - deprecated_in_version: 5.4.0 + - content: GitHub Pull Request from Unknown User + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Known Services Killed by Ransomware - deprecated_in_version: 5.4.0 + - content: Known Services Killed by Ransomware + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Remote Desktop Network Bruteforce - deprecated_in_version: 5.4.0 + - content: Remote Desktop Network Bruteforce + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Suspicious Driver Loaded Path - deprecated_in_version: 5.4.0 + - content: Suspicious Driver Loaded Path + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Suspicious Event Log Service Behavior - deprecated_in_version: 5.4.0 + - content: Suspicious Event Log Service Behavior + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Suspicious Process File Path - deprecated_in_version: 5.4.0 + - content: Suspicious Process File Path + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: AWS Cross Account Activity From Previously Unseen Account - deprecated_in_version: 5.4.0 + - content: AWS Cross Account Activity From Previously Unseen Account + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: aws detect attach to role policy - deprecated_in_version: 5.4.0 + - content: aws detect attach to role policy + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: aws detect permanent key creation - deprecated_in_version: 5.4.0 + - content: aws detect permanent key creation + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: aws detect role creation - deprecated_in_version: 5.4.0 + - content: aws detect role creation + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: aws detect sts assume role abuse - deprecated_in_version: 5.4.0 + - content: aws detect sts assume role abuse + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: aws detect sts get session token abuse - deprecated_in_version: 5.4.0 + - content: aws detect sts get session token abuse + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: AWS SAML Access by Provider User and Principal - deprecated_in_version: 5.4.0 + - content: AWS SAML Access by Provider User and Principal + removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity baselines: - - deprecated_content: Add Prohibited Processes to Enterprise Security - deprecated_in_version: 5.2.0 + - content: Add Prohibited Processes to Enterprise Security + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Baseline of API Calls per User ARN - deprecated_in_version: 5.2.0 + - content: Baseline of API Calls per User ARN + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Baseline of Excessive AWS Instances Launched by User - MLTK - deprecated_in_version: 5.2.0 + - content: Baseline of Excessive AWS Instances Launched by User - MLTK + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Baseline of Excessive AWS Instances Terminated by User - MLTK - deprecated_in_version: 5.2.0 + - content: Baseline of Excessive AWS Instances Terminated by User - MLTK + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Previously seen API call per user roles in CloudTrail - deprecated_in_version: 5.2.0 + - content: Previously seen API call per user roles in CloudTrail + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Previously Seen AWS Provisioning Activity Sources - deprecated_in_version: 5.2.0 + - content: Previously Seen AWS Provisioning Activity Sources + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Previously Seen EC2 AMIs - deprecated_in_version: 5.2.0 + - content: Previously Seen EC2 AMIs + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Previously Seen EC2 Instance Types - deprecated_in_version: 5.2.0 + - content: Previously Seen EC2 Instance Types + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Previously Seen EC2 Launches By User - deprecated_in_version: 5.2.0 + - content: Previously Seen EC2 Launches By User + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Previously seen users in CloudTrail - deprecated_in_version: 5.2.0 + - content: Previously seen users in CloudTrail + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Update previously seen users in CloudTrail - deprecated_in_version: 5.2.0 + - content: Update previously seen users in CloudTrail + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Monitor Successful Backups - deprecated_in_version: 5.2.0 + - content: Monitor Successful Backups + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Monitor Unsuccessful Backups - deprecated_in_version: 5.2.0 + - content: Monitor Unsuccessful Backups + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Previously Seen AWS Regions - deprecated_in_version: 5.2.0 + - content: Previously Seen AWS Regions + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Previously Seen EC2 Modifications By User - deprecated_in_version: 5.2.0 + - content: Previously Seen EC2 Modifications By User + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Systems Ready for Spectre-Meltdown Windows Patch - deprecated_in_version: 5.2.0 + - content: Systems Ready for Spectre-Meltdown Windows Patch + removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Previously Seen AWS Cross Account Activity - Initial - deprecated_in_version: 5.4.0 + - content: Previously Seen AWS Cross Account Activity - Initial + removed_in_version: 5.4.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - - deprecated_content: Previously Seen AWS Cross Account Activity - Update - deprecated_in_version: 5.4.0 + - content: Previously Seen AWS Cross Account Activity - Update + removed_in_version: 5.4.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' investigations: - - deprecated_content: All backup logs for host - deprecated_in_version: 5.2.0 + - content: All backup logs for host + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Amazon EKS Kubernetes activity by src ip - deprecated_in_version: 5.2.0 + - content: Amazon EKS Kubernetes activity by src ip + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: AWS Investigate Security Hub alerts by dest - deprecated_in_version: 5.2.0 + - content: AWS Investigate Security Hub alerts by dest + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: AWS Investigate User Activities By AccessKeyId - deprecated_in_version: 5.2.0 + - content: AWS Investigate User Activities By AccessKeyId + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: AWS Investigate User Activities By ARN - deprecated_in_version: 5.2.0 + - content: AWS Investigate User Activities By ARN + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: AWS Network ACL Details from ID - deprecated_in_version: 5.2.0 + - content: AWS Network ACL Details from ID + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: AWS Network Interface details via resourceId - deprecated_in_version: 5.2.0 + - content: AWS Network Interface details via resourceId + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: AWS S3 Bucket details via bucketName - deprecated_in_version: 5.2.0 + - content: AWS S3 Bucket details via bucketName + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: GCP Kubernetes activity by src ip - deprecated_in_version: 5.2.0 + - content: GCP Kubernetes activity by src ip + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get All AWS Activity From City - deprecated_in_version: 5.2.0 + - content: Get All AWS Activity From City + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get All AWS Activity From Country - deprecated_in_version: 5.2.0 + - content: Get All AWS Activity From Country + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get All AWS Activity From IP Address - deprecated_in_version: 5.2.0 + - content: Get All AWS Activity From IP Address + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get All AWS Activity From Region - deprecated_in_version: 5.2.0 + - content: Get All AWS Activity From Region + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Backup Logs For Endpoint - deprecated_in_version: 5.2.0 + - content: Get Backup Logs For Endpoint + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Certificate logs for a domain - deprecated_in_version: 5.2.0 + - content: Get Certificate logs for a domain + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get DNS Server History for a host - deprecated_in_version: 5.2.0 + - content: Get DNS Server History for a host + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get DNS traffic ratio - deprecated_in_version: 5.2.0 + - content: Get DNS traffic ratio + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get EC2 Instance Details by instanceId - deprecated_in_version: 5.2.0 + - content: Get EC2 Instance Details by instanceId + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get EC2 Launch Details - deprecated_in_version: 5.2.0 + - content: Get EC2 Launch Details + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Email Info - deprecated_in_version: 5.2.0 + - content: Get Email Info + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Emails From Specific Sender - deprecated_in_version: 5.2.0 + - content: Get Emails From Specific Sender + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get First Occurrence and Last Occurrence of a MAC Address - deprecated_in_version: 5.2.0 + - content: Get First Occurrence and Last Occurrence of a MAC Address + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get History Of Email Sources - deprecated_in_version: 5.2.0 + - content: Get History Of Email Sources + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Logon Rights Modifications For Endpoint - deprecated_in_version: 5.2.0 + - content: Get Logon Rights Modifications For Endpoint + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Logon Rights Modifications For User - deprecated_in_version: 5.2.0 + - content: Get Logon Rights Modifications For User + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Notable History - deprecated_in_version: 5.2.0 + - content: Get Notable History + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Outbound Emails to Hidden Cobra Threat Actors - deprecated_in_version: 5.2.0 + - content: Get Outbound Emails to Hidden Cobra Threat Actors + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Parent Process Info - deprecated_in_version: 5.2.0 + - content: Get Parent Process Info + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Process File Activity - deprecated_in_version: 5.2.0 + - content: Get Process File Activity + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Process Info - deprecated_in_version: 5.2.0 + - content: Get Process Info + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Process Information For Port Activity - deprecated_in_version: 5.2.0 + - content: Get Process Information For Port Activity + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Process Responsible For The DNS Traffic - deprecated_in_version: 5.2.0 + - content: Get Process Responsible For The DNS Traffic + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Sysmon WMI Activity for Host - deprecated_in_version: 5.2.0 + - content: Get Sysmon WMI Activity for Host + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Get Web Session Information via session id - deprecated_in_version: 5.2.0 + - content: Get Web Session Information via session id + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate AWS activities via region name - deprecated_in_version: 5.2.0 + - content: Investigate AWS activities via region name + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate AWS User Activities by user field - deprecated_in_version: 5.2.0 + - content: Investigate AWS User Activities by user field + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate Failed Logins for Multiple Destinations - deprecated_in_version: 5.2.0 + - content: Investigate Failed Logins for Multiple Destinations + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate Network Traffic From src ip - deprecated_in_version: 5.2.0 + - content: Investigate Network Traffic From src ip + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate Okta Activity by app - deprecated_in_version: 5.2.0 + - content: Investigate Okta Activity by app + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate Okta Activity by IP Address - deprecated_in_version: 5.2.0 + - content: Investigate Okta Activity by IP Address + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate Pass the Hash Attempts - deprecated_in_version: 5.2.0 + - content: Investigate Pass the Hash Attempts + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate Pass the Ticket Attempts - deprecated_in_version: 5.2.0 + - content: Investigate Pass the Ticket Attempts + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate Previous Unseen User - deprecated_in_version: 5.2.0 + - content: Investigate Previous Unseen User + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate Successful Remote Desktop Authentications - deprecated_in_version: 5.2.0 + - content: Investigate Successful Remote Desktop Authentications + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate Suspicious Strings in HTTP Header - deprecated_in_version: 5.2.0 + - content: Investigate Suspicious Strings in HTTP Header + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate User Activities In Okta - deprecated_in_version: 5.2.0 + - content: Investigate User Activities In Okta + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - - deprecated_content: Investigate Web POSTs From src - deprecated_in_version: 5.2.0 + - content: Investigate Web POSTs From src + removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' stories: - - deprecated_content: AWS Cryptomining - deprecated_in_version: 5.2.0 + - content: AWS Cryptomining + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Cloud Cryptomining - - deprecated_content: AWS Suspicious Provisioning Activities - deprecated_in_version: 5.2.0 + - content: AWS Suspicious Provisioning Activities + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Suspicious Cloud Provisioning Activities - - deprecated_content: Common Phishing Frameworks - deprecated_in_version: 5.2.0 + - content: Common Phishing Frameworks + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Container Implantation Monitoring and Investigation - deprecated_in_version: 5.2.0 + - content: Container Implantation Monitoring and Investigation + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Kubernetes Security - - deprecated_content: Host Redirection - deprecated_in_version: 5.2.0 + - content: Host Redirection + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Kubernetes Sensitive Role Activity - deprecated_in_version: 5.2.0 + - content: Kubernetes Sensitive Role Activity + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Kubernetes Security - - deprecated_content: Lateral Movement - deprecated_in_version: 5.2.0 + - content: Lateral Movement + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Compromised User Account - - deprecated_content: Monitor Backup Solution - deprecated_in_version: 5.2.0 + - content: Monitor Backup Solution + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Monitor for Unauthorized Software - deprecated_in_version: 5.2.0 + - content: Monitor for Unauthorized Software + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Office 365 Detections - deprecated_in_version: 5.2.0 + - content: Office 365 Detections + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Office 365 Account Takeover - - deprecated_content: Spectre And Meltdown Vulnerabilities - deprecated_in_version: 5.2.0 + - content: Spectre And Meltdown Vulnerabilities + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Suspicious AWS EC2 Activities - deprecated_in_version: 5.2.0 + - content: Suspicious AWS EC2 Activities + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Suspicious Cloud Instance Activities - - deprecated_content: Unusual AWS EC2 Modifications - deprecated_in_version: 5.2.0 + - content: Unusual AWS EC2 Modifications + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Suspicious Cloud Instance Activities - - deprecated_content: Web Fraud Detection - deprecated_in_version: 5.2.0 + - content: Web Fraud Detection + removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - - deprecated_content: Nexus APT Threat Activity - deprecated_in_version: 5.4.0 + - content: Nexus APT Threat Activity + removed_in_version: 5.4.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - China-Nexus Threat Activity \ No newline at end of file From 6488af7c57740c0e39da9bcb968b6c822c087f61 Mon Sep 17 00:00:00 2001 From: delgado-jacob <29643013+delgado-jacob@users.noreply.github.com> Date: Tue, 18 Mar 2025 14:29:30 -0700 Subject: [PATCH 65/67] Add Zeek TA, fix detection source list --- data_sources/bro_conn.yml | 5 ++++- data_sources/bro_dns.yml | 6 +++++- data_sources/bro_files.yml | 5 ++++- data_sources/bro_http.yml | 5 ++++- data_sources/bro_loaded_scripts.yml | 5 ++++- data_sources/bro_ntp.yml | 5 ++++- data_sources/bro_ocsp.yml | 5 ++++- data_sources/bro_ssl.yml | 5 ++++- data_sources/bro_weird.yml | 5 ++++- data_sources/bro_x509.yml | 5 ++++- detections/network/detect_outbound_ldap_traffic.yml | 3 --- 11 files changed, 41 insertions(+), 13 deletions(-) diff --git a/data_sources/bro_conn.yml b/data_sources/bro_conn.yml index 1d8e4110c3..2344d857d7 100644 --- a/data_sources/bro_conn.yml +++ b/data_sources/bro_conn.yml @@ -12,4 +12,7 @@ mitre_components: - Application Log Content source: bro:conn:json sourcetype: bro:conn:json -supported_TA: [] +supported_TA: +- name: TA for Zeek + url: https://splunkbase.splunk.com/app/5466 + version: 1.0.8 diff --git a/data_sources/bro_dns.yml b/data_sources/bro_dns.yml index b4deae7a6c..a87a59819a 100644 --- a/data_sources/bro_dns.yml +++ b/data_sources/bro_dns.yml @@ -13,4 +13,8 @@ mitre_components: - Response Metadata source: bro:dns:json sourcetype: bro:dns:json -supported_TA: [] +supported_TA: +- name: TA for Zeek + url: https://splunkbase.splunk.com/app/5466 + version: 1.0.8 + diff --git a/data_sources/bro_files.yml b/data_sources/bro_files.yml index 20121d2067..6185e27c8f 100644 --- a/data_sources/bro_files.yml +++ b/data_sources/bro_files.yml @@ -14,4 +14,7 @@ mitre_components: - Application Log Content source: bro:files:json sourcetype: bro:files:json -supported_TA: [] +supported_TA: +- name: TA for Zeek + url: https://splunkbase.splunk.com/app/5466 + version: 1.0.8 diff --git a/data_sources/bro_http.yml b/data_sources/bro_http.yml index e8e25150dc..02c2647022 100644 --- a/data_sources/bro_http.yml +++ b/data_sources/bro_http.yml @@ -13,4 +13,7 @@ mitre_components: - Application Log Content source: bro:http:json sourcetype: bro:http:json -supported_TA: [] +supported_TA: +- name: TA for Zeek + url: https://splunkbase.splunk.com/app/5466 + version: 1.0.8 diff --git a/data_sources/bro_loaded_scripts.yml b/data_sources/bro_loaded_scripts.yml index 2b9669bac3..016c7beb38 100644 --- a/data_sources/bro_loaded_scripts.yml +++ b/data_sources/bro_loaded_scripts.yml @@ -12,4 +12,7 @@ mitre_components: - OS API Execution source: bro:loaded_scripts:json sourcetype: bro:loaded_scripts:json -supported_TA: [] +supported_TA: +- name: TA for Zeek + url: https://splunkbase.splunk.com/app/5466 + version: 1.0.8 diff --git a/data_sources/bro_ntp.yml b/data_sources/bro_ntp.yml index 727dfc5bfa..f76e65c2ae 100644 --- a/data_sources/bro_ntp.yml +++ b/data_sources/bro_ntp.yml @@ -12,4 +12,7 @@ mitre_components: - Application Log Content source: bro:ntp:json sourcetype: bro:ntp:json -supported_TA: [] +supported_TA: +- name: TA for Zeek + url: https://splunkbase.splunk.com/app/5466 + version: 1.0.8 diff --git a/data_sources/bro_ocsp.yml b/data_sources/bro_ocsp.yml index 316e75d352..fc3bd136a9 100644 --- a/data_sources/bro_ocsp.yml +++ b/data_sources/bro_ocsp.yml @@ -13,4 +13,7 @@ mitre_components: - Application Log Content source: bro:ocsp:json sourcetype: bro:ocsp:json -supported_TA: [] +supported_TA: +- name: TA for Zeek + url: https://splunkbase.splunk.com/app/5466 + version: 1.0.8 diff --git a/data_sources/bro_ssl.yml b/data_sources/bro_ssl.yml index b138786a0f..42a8a59910 100644 --- a/data_sources/bro_ssl.yml +++ b/data_sources/bro_ssl.yml @@ -13,4 +13,7 @@ mitre_components: - Application Log Content source: bro:ssl:json sourcetype: bro:ssl:json -supported_TA: [] +supported_TA: +- name: TA for Zeek + url: https://splunkbase.splunk.com/app/5466 + version: 1.0.8 diff --git a/data_sources/bro_weird.yml b/data_sources/bro_weird.yml index 4d46c68d74..fe5a01ce05 100644 --- a/data_sources/bro_weird.yml +++ b/data_sources/bro_weird.yml @@ -13,4 +13,7 @@ mitre_components: - Host Status source: bro:weird:json sourcetype: bro:weird:json -supported_TA: [] +supported_TA: +- name: TA for Zeek + url: https://splunkbase.splunk.com/app/5466 + version: 1.0.8 diff --git a/data_sources/bro_x509.yml b/data_sources/bro_x509.yml index 3f23109ebd..a5d7370c9e 100644 --- a/data_sources/bro_x509.yml +++ b/data_sources/bro_x509.yml @@ -13,4 +13,7 @@ mitre_components: - Host Status source: bro:x509:json sourcetype: bro:x509:json -supported_TA: [] +supported_TA: +- name: TA for Zeek + url: https://splunkbase.splunk.com/app/5466 + version: 1.0.8 diff --git a/detections/network/detect_outbound_ldap_traffic.yml b/detections/network/detect_outbound_ldap_traffic.yml index 43c8417a22..03e2420676 100644 --- a/detections/network/detect_outbound_ldap_traffic.yml +++ b/detections/network/detect_outbound_ldap_traffic.yml @@ -13,10 +13,7 @@ description: The following analytic identifies outbound LDAP traffic to external this to access sensitive directory information, leading to data breaches or further network compromise. data_source: -- Bro conn - Palo Alto Network Traffic -- Splunk Stream TCP -- Splunk Stream IP search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(All_Traffic.dest_ip) as dest_ip from datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port = 389 OR All_Traffic.dest_port = 636 AND NOT (All_Traffic.dest_ip From ea3fa4daf6eabcbdd9f3625b37b6f3837083794a Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Tue, 18 Mar 2025 14:52:30 -0700 Subject: [PATCH 66/67] updating search --- detections/cloud/aws_saml_update_identity_provider.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/cloud/aws_saml_update_identity_provider.yml b/detections/cloud/aws_saml_update_identity_provider.yml index 1cbc4848f6..b75e51fa8b 100644 --- a/detections/cloud/aws_saml_update_identity_provider.yml +++ b/detections/cloud/aws_saml_update_identity_provider.yml @@ -17,7 +17,7 @@ data_source: - AWS CloudTrail UpdateSAMLProvider search: '`cloudtrail` eventName=UpdateSAMLProvider | rename user_name as user - | stats count min(_time) as firstTime max(_time) as lastTime values(request_parameters) as request_parameters by signature dest user user_agent src vendor_account vendor_region vendor_product + | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.sAMLProviderArn) as request_parameters by signature dest user user_agent src vendor_account vendor_region vendor_product | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_saml_update_identity_provider_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This From 58aca7db99704d6a877714031870c9e37e2bc2e1 Mon Sep 17 00:00:00 2001 From: Eric Date: Tue, 18 Mar 2025 15:41:21 -0700 Subject: [PATCH 67/67] Update the deprecation_info.csv file, manually generated with a version of contentctl that has not yet been merged or released in main branch. --- lookups/deprecation_info.csv | 400 ++++++++++++++++++----------------- 1 file changed, 206 insertions(+), 194 deletions(-) diff --git a/lookups/deprecation_info.csv b/lookups/deprecation_info.csv index ca41e89981..743562a38e 100644 --- a/lookups/deprecation_info.csv +++ b/lookups/deprecation_info.csv @@ -1,195 +1,207 @@ -Name,Content Type,Deprecated in Version,Reason,Migration Guide,Replacement Content -ESCU - ASL AWS Excessive Security Scanning - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aba1860-9617-4af9-b19d-aecac16fe4f2 -ESCU - First time seen command line argument - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Windows connhost exe started forcefully - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Detect Mimikatz Using Loaded Images - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Kubernetes Azure detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Web Fraud - Anomalous User Clickspeed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c6ddbf53-9715-49f3-bb4c-fb2e8a309cda -ESCU - EC2 Instance Started With Previously Unseen AMI - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc24922d-987c-4645-b288-f8c73ec194c4 -ESCU - Domain Group Discovery With Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44 -ESCU - Kubernetes AWS detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Winword Spawning Windows Script Host - Rule,Detection,5.2.0,"The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level. -This would ease management and false positives tuning.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - Winword Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - Attempted Credential Dump From Registry via Reg exe - Rule,Detection,5.2.0,"This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e -ESCU - Detect processes used for System Network Configuration Discovery - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3f0b95e3-3195-46ac-bea3-84fb59e7fac5 -ESCU - Execution of File With Spaces Before Extension - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b06a555e-dce0-417d-a2eb-28a5d8d66ef7 -ESCU - EC2 Instance Started In Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/fa4089e2-50e3-40f7-8469-d2cc1564ca59 -ESCU - Office Document Spawned Child Process To Download - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f02b64b8-cbea-4f75-bf77-7a05111566b1 -ESCU - Detect new API calls from user roles - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f -ESCU - Cmdline Tool Not Executed In CMD Shell - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2afa393f-b88d-41b7-9793-623c93a2dfde -ESCU - Linux Auditd Find Private Keys - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/892eb674-3344-4143-8e52-4775b1daf3f1 -ESCU - Detect AWS API Activities From Unapproved Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Monitor DNS For Brand Abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Kubernetes GCP detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Kubernetes Azure scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - ASL AWS Password Policy Changes - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - O365 Suspicious Admin Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24 -ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e7ecc5e0-88df-48b9-91af-51104c68f02f -ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Osquery pack - ColdRoot detection - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Windows Modify Registry Reg Restore - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a17af481-e2ad-494c-9da6-afb4d243a019 -ESCU - Kubernetes GCP detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Scheduled tasks used in BadRabbit ransomware - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d5af132c-7c17-439c-9d31-13d55340f36c -ESCU - Suspicious Rundll32 Rename - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,"This analytic was focusing on 2 separate and unrelated type of threats or actions. It was split into other analytics, namely: - -Windows Network Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277 -Windows Sensitive Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4dc3951f-b3f8-4f46-b412-76a483f72277 -ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af -ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Suspicious Changes to File Associations - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - GCP Detect high risk permissions by resource and account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Office Product Writing cab or inf - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/dbdd251e-dd45-4ec9-a555-f5e151391746 -ESCU - Identify New User Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Office Product Spawn CMD Process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - Windows DLL Search Order Hijacking Hunt - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/79c7d1fc-64c7-91be-a616-ccda752efe81 -ESCU - ASL AWS CreateAccessKey - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/81a9f2fe-1697-473c-af1d-086b0d8b63c8 -ESCU - Okta ThreatInsight Login Failure with High Unknown users - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Detect Spike in Security Group Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d4dfb7f3-7a37-498a-b5df-f19334e871af -ESCU - Office Product Spawning BITSAdmin - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - Create local admin accounts using net exe - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2c568c34-bb57-4b43-9d75-19c605b98e70 -ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Windows Office Product Spawning MSDT - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a3148fad-3734-4b7f-9a71-62f08d39fab1 -ESCU - Detect Spike in AWS API Activity - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Office Product Spawning Windows Script Host - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - Prohibited Software On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893 -ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/94994255-3acf-4213-9b3f-0494df03bb31 -ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,"As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender Incident Alerts. Going forward analytics from leveraging alerts from vendors will have their specific analytics.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/38f034ed-1598-46c8-95e8-14edf05fdf5d -ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/13435b55-afd8-46d4-9045-7d5457f430a5 -ESCU - Excel Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - Office Application Spawn rundll32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - Excessive Usage Of Net App - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38 -ESCU - Elevated Group Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af -ESCU - Local Account Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72 -ESCU - Windows Command Shell Fetch Env Variables - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/aec157f4-8783-4584-aca6-754c4dc7fba9 -ESCU - Suspicious Email - UBA Anomaly - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Detect web traffic to dynamic domain providers - Rule,Detection,5.2.0,Updated to use a different log source,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a1e761ac-1344-4dbd-88b2-3f34c912d359 -ESCU - Okta Failed SSO Attempts - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5f661629-9750-4cb9-897c-1f05d6db8727 -ESCU - Kubernetes AWS detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Remote Registry Key modifications - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - O365 Suspicious User Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24 -ESCU - Office Product Spawning MSHTA - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - Kubernetes AWS detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Correlation by Repository and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67 -ESCU - Kubernetes Azure detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Clients Connecting to Multiple DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Excessive Service Stop Attempt - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8f3a614f-6b98-4f7d-82dd-d0df38452a8b -ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/de365ffa-42f5-46b5-b43f-fa72290b8218 -ESCU - Suspicious writes to System Volume Information - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Detect new user AWS Console Login - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc91a8cd-35e7-4bb2-6140-e756cc46fd71 +Name,Content Type,Removed in Version,Reason,Replacement Content,Replacement Content Link +ESCU - Previously Seen AWS Cross Account Activity - Initial,Baseline,5.4.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Previously Seen AWS Cross Account Activity - Update,Baseline,5.4.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - AWS SAML Access by Provider User and Principal - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - GitHub Actions Disable Security Workflow - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - GitHub Dependabot Alert - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - GitHub Pull Request from Unknown User - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Github Commit Changes In Master - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Github Commit In Develop - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Known Services Killed by Ransomware - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Remote Desktop Network Bruteforce - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Suspicious Driver Loaded Path - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Suspicious Event Log Service Behavior - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Suspicious Process File Path - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - aws detect attach to role policy - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - aws detect permanent key creation - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - aws detect role creation - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - aws detect sts assume role abuse - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - aws detect sts get session token abuse - Rule,Detection,5.4.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +Nexus APT Threat Activity,Story,5.4.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,China-Nexus Threat Activity,https://research.splunk.com/stories/china_nexus_threat_activity +ESCU - Add Prohibited Processes to Enterprise Security,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Baseline of API Calls per User ARN,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Monitor Successful Backups,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Monitor Unsuccessful Backups,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Previously Seen AWS Provisioning Activity Sources,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Previously Seen AWS Regions,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Previously Seen EC2 AMIs,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Previously Seen EC2 Instance Types,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Previously Seen EC2 Launches By User,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Previously Seen EC2 Modifications By User,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Previously seen API call per user roles in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Systems Ready for Spectre-Meltdown Windows Patch,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - Update previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",No Replacement Content Available,No Content Link Available +ESCU - ASL AWS CreateAccessKey - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - ASL AWS Create Access Key - Rule,https://research.splunk.com/cloud/81a9f2fe-1697-473c-af1d-086b0d8b63c8 +ESCU - ASL AWS Excessive Security Scanning - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - ASL AWS Password Policy Changes - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Provisioning Activity From Previously Unseen City - Rule,https://research.splunk.com/cloud/e7ecc5e0-88df-48b9-91af-51104c68f02f +ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Provisioning Activity From Previously Unseen Country - Rule,https://research.splunk.com/cloud/94994255-3acf-4213-9b3f-0494df03bb31 +ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Provisioning Activity From Previously Unseen IP Address - Rule,https://research.splunk.com/cloud/f86a8ec9-b042-45eb-92f4-e9ed1d781078 +ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Provisioning Activity From Previously Unseen Region - Rule,https://research.splunk.com/cloud/5aba1860-9617-4af9-b19d-aecac16fe4f2 +ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Kubernetes Abuse of Secret by Unusual Location - Rule,https://research.splunk.com/cloud/40a064c1-4ec1-4381-9e35-61192ba8ef82 +ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Abnormally High AWS Instances Launched by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Abnormally High Number Of Cloud Instances Launched - Rule,https://research.splunk.com/cloud/f2361e9f-3928-496c-a556-120cd4223a65 +ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Abnormally High AWS Instances Terminated by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Abnormally High Number Of Cloud Instances Destroyed - Rule,https://research.splunk.com/cloud/ef629fc9-1583-4590-b62a-f2247fbf7bbf +ESCU - Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 / Windows Excessive Usage Of Net App.",ESCU - Windows Excessive Usage Of Net App - Rule,https://research.splunk.com/endpoint/355ba810-0a20-4215-8485-9ce3f87f2e38 +ESCU - Attempt To Stop Security Service - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Attempt To Stop Security Service - Rule,https://research.splunk.com/endpoint/9ed27cea-4e27-4eff-b2c6-aac9e78a7517 +ESCU - Attempted Credential Dump From Registry via Reg exe - Rule,Detection,5.2.0,"This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine",ESCU - Windows Sensitive Registry Hive Dump Via CommandLine - Rule,https://research.splunk.com/endpoint/5aaff29d-0cce-405b-9ee8-5d06b49d045e +ESCU - Change Default File Association - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows New Default File Association Value Set - Rule,https://research.splunk.com/endpoint/7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a +ESCU - Clients Connecting to Multiple DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Cloud Network Access Control List Deleted - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - AWS Network Access Control List Deleted - Rule,https://research.splunk.com/cloud/ada0f478-84a8-4641-a3f1-d82362d6fd75 +ESCU - Cmdline Tool Not Executed In CMD Shell - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Cmdline Tool Execution From Non-Shell Process - Rule,https://research.splunk.com/endpoint/2afa393f-b88d-41b7-9793-623c93a2dfde +ESCU - Correlation by Repository and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,ESCU - Risk Rule for Dev Sec Ops by Repository - Rule,https://research.splunk.com/cloud/161bc0ca-4651-4c13-9c27-27770660cf67 +ESCU - Correlation by User and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,ESCU - Risk Rule for Dev Sec Ops by Repository - Rule,https://research.splunk.com/cloud/161bc0ca-4651-4c13-9c27-27770660cf67 +ESCU - Create local admin accounts using net exe - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Create Local Administrator Account Via Net - Rule,https://research.splunk.com/endpoint/2c568c34-bb57-4b43-9d75-19c605b98e70 +ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - DNS record changed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Deleting Of Net Users - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows User Deletion Via Net - Rule,https://research.splunk.com/endpoint/b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e +ESCU - Detect API activity from users without MFA - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - AWS Successful Single-Factor Authentication - Rule,https://research.splunk.com/cloud/a520b1fe-cc9e-4f56-b762-18354594c52f +ESCU - Detect AWS API Activities From Unapproved Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Detect Activity Related to Pass the Hash Attacks - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,"As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender Incident Alerts. Going forward analytics from leveraging alerts from vendors will have their specific analytics.",ESCU - Microsoft Defender ATP Alerts - Rule,https://research.splunk.com/endpoint/38f034ed-1598-46c8-95e8-14edf05fdf5d +ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Microsoft Defender Incident Alerts - Rule,https://research.splunk.com/endpoint/13435b55-afd8-46d4-9045-7d5457f430a5 +ESCU - Detect DNS requests to Phishing Sites leveraging EvilGinx2 - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Detect Long DNS TXT Record Response - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Detect Mimikatz Using Loaded Images - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Detect Mimikatz With PowerShell Script Block Logging - Rule,https://research.splunk.com/endpoint/8148c29c-c952-11eb-9255-acde48001122 +ESCU - Detect Spike in AWS API Activity - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Detect Spike in Network ACL Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Abnormally High Number Of Cloud Infrastructure API Calls - Rule,https://research.splunk.com/cloud/0840ddf1-8c89-46ff-b730-c8d6722478c0 +ESCU - Detect Spike in Security Group Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Abnormally High Number Of Cloud Security Group API Calls - Rule,https://research.splunk.com/cloud/d4dfb7f3-7a37-498a-b5df-f19334e871af +ESCU - Detect USB device insertion - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Detect Webshell Exploit Behavior - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Suspicious Child Process Spawned From WebServer - Rule,https://research.splunk.com/endpoint/2d4470ef-7158-4b47-b68b-1f7f16382156 +ESCU - Detect new API calls from user roles - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud API Calls From Previously Unseen User Roles - Rule,https://research.splunk.com/cloud/2181ad1f-1e73-4d0c-9780-e8880482a08f +ESCU - Detect new user AWS Console Login - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Detect AWS Console Login by New User - Rule,https://research.splunk.com/cloud/bc91a8cd-35e7-4bb2-6140-e756cc46fd71 +ESCU - Detect processes used for System Network Configuration Discovery - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Potential System Network Configuration Discovery Activity - Rule,https://research.splunk.com/endpoint/3f0b95e3-3195-46ac-bea3-84fb59e7fac5 +ESCU - Detect web traffic to dynamic domain providers - Rule,Detection,5.2.0,Updated to use a different log source,ESCU - Detect hosts connecting to dynamic domain providers - Rule,https://research.splunk.com/network/a1e761ac-1344-4dbd-88b2-3f34c912d359 +ESCU - Detection of DNS Tunnels - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Disabling Net User Account - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows User Disabled Via Net - Rule,https://research.splunk.com/endpoint/b0359e05-c87b-4354-83d8-aee0d890243f ESCU - Domain Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that looked only for commands that tries to query info about the users via net user /do. This had a couple of issues, such as triggering on creation of users via the /add flag etc.. -It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72 -ESCU - Detection of DNS Tunnels - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Detect DNS requests to Phishing Sites leveraging EvilGinx2 - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Office Document Creating Schedule Task - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d7297cfa-1f04-4714-bfbe-3679e0666959 -ESCU - Okta Account Locked Out - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1 -ESCU - Unsuccessful Netbackup backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8148c29c-c952-11eb-9255-acde48001122 -ESCU - Winword Spawning Cmd - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - GCP Kubernetes cluster scan detection - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f9cadf4e-df22-4f4e-a08f-9d3344c2165d -ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - gcp detect oauth token abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Correlation by User and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67 -ESCU - Processes created by netsh - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b89919ed-fe5f-492c-b139-95dbb162040e -ESCU - Office Product Spawning Wmic - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - Extraction of Registry Hives - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e -ESCU - Attempt To Stop Security Service - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/9ed27cea-4e27-4eff-b2c6-aac9e78a7517 -ESCU - Windows MSIExec With Network Connections - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0fd38c7-f71a-43a2-870e-f3ca06bcdd99 -ESCU - Windows Query Registry Reg Save - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/466379bc-0f47-476c-8202-16ef38112e0d -ESCU - Cloud Network Access Control List Deleted - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ada0f478-84a8-4641-a3f1-d82362d6fd75 -ESCU - O365 Suspicious Rights Delegation - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2246c142-a678-45f8-8546-aaed7e0efd30 -ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Reg exe used to hide files directories via registry keys - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Detect Long DNS TXT Record Response - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Password Policy Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e52f7865-be78-46bf-b7ed-150fbe447613 -ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f86a8ec9-b042-45eb-92f4-e9ed1d781078 -ESCU - Network Connection Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/86a5b949-679b-4197-8d4c-9c180a818c45 -ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Kubernetes GCP detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Detect Webshell Exploit Behavior - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2d4470ef-7158-4b47-b68b-1f7f16382156 -ESCU - DNS record changed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Unsigned Image Loaded by LSASS - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Detect USB device insertion - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Windows Network Share Interaction With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e51fbdb0-0be0-474f-92ea-d289f71a695e -ESCU - Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 / Windows Excessive Usage Of Net App.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38 -ESCU - Change Default File Association - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a -ESCU - Windows Lateral Tool Transfer RemCom - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7e3d68db-ea4d-419b-adbd-e14a525ecf09 -ESCU - Office Document Executing Macro Code - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7cfec906-2697-43f7-898b-83634a051d9a -ESCU - Okta Account Lockout Events - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1 -ESCU - Abnormally High AWS Instances Launched by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f2361e9f-3928-496c-a556-120cd4223a65 -ESCU - EC2 Instance Modified With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f -ESCU - Windows Valid Account With Never Expires Password - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/11f93009-8083-43fd-82a7-821fcbdc8342 -ESCU - Windows hosts file modification - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - MSHTML Module Load in Office Product - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4cc015c9-687c-40d2-adcc-46350f66e10c -ESCU - Abnormally High AWS Instances Terminated by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ef629fc9-1583-4590-b62a-f2247fbf7bbf -ESCU - Web Fraud - Account Harvesting - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Office Spawning Control - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/081c485d-ac8d-4bee-ad4c-525772fead4d -ESCU - Detect Activity Related to Pass the Hash Attacks - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Deleting Of Net Users - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e -ESCU - Suspicious File Write - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/40a064c1-4ec1-4381-9e35-61192ba8ef82 -ESCU - Spectre and Meltdown Vulnerable Systems - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - EC2 Instance Started With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/37a0ec8d-827e-4d6d-8025-cedf31f3a149 -ESCU - Office Product Spawning CertUtil - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Office Application Drop Executable - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7ac0fced-9eae-4381-a748-90dcd1aa9393 -ESCU - Kubernetes Azure active service accounts by pod namespace - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Kubernetes Azure pod scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Detect Spike in Network ACL Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0840ddf1-8c89-46ff-b730-c8d6722478c0 -ESCU - Suspicious Powershell Command-Line Arguments - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c4db14d9-7909-48b4-a054-aa14d89dbb19 -ESCU - Office Application Spawn Regsvr32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8 -ESCU - Detect API activity from users without MFA - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a520b1fe-cc9e-4f56-b762-18354594c52f -ESCU - Kubernetes Azure detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Web Fraud - Password Sharing Across Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Disabling Net User Account - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0359e05-c87b-4354-83d8-aee0d890243f -ESCU - GCP Detect accounts with high risk roles by project - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Extended Period Without Successful Netbackup Backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Office Product Spawning Rundll32 with no DLL - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f28e787e-69ca-480e-9f98-ab970e6d4bcc -ESCU - Okta ThreatInsight Suspected PasswordSpray Attack - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/140504ae-5fe2-4d65-b2bc-a211813fbca6 -ESCU - Net Localgroup Discovery - Rule,Detection,5.2.0,Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44 -ESCU - Uncommon Processes On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893 -ESCU - Dump LSASS via procdump Rename - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3742ebfe-64c2-11eb-ae93-0242ac130002 -ESCU - Okta Two or More Rejected Okta Pushes - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/826dbaae-a1e6-4c8c-b384-d16898956e73 -ESCU - Excel Spawning Windows Script Host - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - GitHub Actions Disable Security Workflow - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Github Commit Changes In Master - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Github Commit In Develop - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - GitHub Dependabot Alert - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - GitHub Pull Request from Unknown User - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Known Services Killed by Ransomware - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Remote Desktop Network Bruteforce - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Suspicious Driver Loaded Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Suspicious Event Log Service Behavior - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Suspicious Process File Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Windows Service Stop Via Net and SC Application - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -ESCU - Add Prohibited Processes to Enterprise Security,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, -ESCU - Baseline of API Calls per User ARN,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, -ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, -ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, -ESCU - Previously seen API call per user roles in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, -ESCU - Previously Seen AWS Provisioning Activity Sources,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, -ESCU - Previously Seen EC2 AMIs,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, -ESCU - Previously Seen EC2 Instance Types,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, -ESCU - Previously Seen EC2 Launches By User,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, -ESCU - Previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, -ESCU - Update previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/, -AWS Cryptomining,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -AWS Suspicious Provisioning Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Common Phishing Frameworks,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Container Implantation Monitoring and Investigation,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Host Redirection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Kubernetes Sensitive Role Activity,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Lateral Movement,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Monitor Backup Solution,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Monitor for Unauthorized Software,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Office 365 Detections,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Spectre And Meltdown Vulnerabilities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Suspicious AWS EC2 Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Unusual AWS EC2 Modifications,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Web Fraud Detection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, -Nexus APT Threat Activity,Story,5.4.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/, +It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122",ESCU - Windows User Discovery Via Net - Rule,https://research.splunk.com/endpoint/7742987e-88c1-476b-a626-a869e088ab72 +ESCU - Domain Group Discovery With Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Group Discovery Via Net - Rule,https://research.splunk.com/endpoint/c5c8e0f3-147a-43da-bf04-4cfaec27dc44 +ESCU - Dump LSASS via procdump Rename - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Dump LSASS via procdump - Rule,https://research.splunk.com/endpoint/3742ebfe-64c2-11eb-ae93-0242ac130002 +ESCU - EC2 Instance Modified With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud API Calls From Previously Unseen User Roles - Rule,https://research.splunk.com/cloud/2181ad1f-1e73-4d0c-9780-e8880482a08f +ESCU - EC2 Instance Started In Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Compute Instance Created In Previously Unused Region - Rule,https://research.splunk.com/cloud/fa4089e2-50e3-40f7-8469-d2cc1564ca59 +ESCU - EC2 Instance Started With Previously Unseen AMI - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Compute Instance Created With Previously Unseen Image - Rule,https://research.splunk.com/cloud/bc24922d-987c-4645-b288-f8c73ec194c4 +ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule,https://research.splunk.com/cloud/c6ddbf53-9715-49f3-bb4c-fb2e8a309cda +ESCU - EC2 Instance Started With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Cloud Compute Instance Created By Previously Unseen User - Rule,https://research.splunk.com/cloud/37a0ec8d-827e-4d6d-8025-cedf31f3a149 +ESCU - Elevated Group Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Sensitive Group Discovery With Net - Rule,https://research.splunk.com/endpoint/d9eb7cda-5622-4722-bc88-7f2442f4b5af +ESCU - Excel Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Excel Spawning Windows Script Host - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Excessive Service Stop Attempt - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Excessive Service Stop Attempt - Rule,https://research.splunk.com/endpoint/8f3a614f-6b98-4f7d-82dd-d0df38452a8b +ESCU - Excessive Usage Of Net App - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Excessive Usage Of Net App - Rule,https://research.splunk.com/endpoint/355ba810-0a20-4215-8485-9ce3f87f2e38 +ESCU - Execution of File With Spaces Before Extension - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Execution of File with Multiple Extensions - Rule,https://research.splunk.com/endpoint/b06a555e-dce0-417d-a2eb-28a5d8d66ef7 +ESCU - Extended Period Without Successful Netbackup Backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Extraction of Registry Hives - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Sensitive Registry Hive Dump Via CommandLine - Rule,https://research.splunk.com/endpoint/5aaff29d-0cce-405b-9ee8-5d06b49d045e +ESCU - First time seen command line argument - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - GCP Detect accounts with high risk roles by project - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - GCP Detect high risk permissions by resource and account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - GCP Kubernetes cluster scan detection - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Kubernetes Scanning by Unauthenticated IP Address - Rule,https://research.splunk.com/cloud/f9cadf4e-df22-4f4e-a08f-9d3344c2165d +ESCU - Identify New User Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes AWS detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes AWS detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes AWS detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes Azure active service accounts by pod namespace - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes Azure detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes Azure detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes Azure detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes Azure pod scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes Azure scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes GCP detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes GCP detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes GCP detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Linux Auditd Find Private Keys - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Linux Auditd Private Keys and Certificate Enumeration - Rule,https://research.splunk.com/endpoint/892eb674-3344-4143-8e52-4775b1daf3f1 +ESCU - Local Account Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows User Discovery Via Net - Rule,https://research.splunk.com/endpoint/7742987e-88c1-476b-a626-a869e088ab72 +ESCU - MSHTML Module Load in Office Product - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Loaded MSHTML Module - Rule,https://research.splunk.com/endpoint/4cc015c9-687c-40d2-adcc-46350f66e10c +ESCU - Monitor DNS For Brand Abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta Multiple Users Failing To Authenticate From Ip - Rule,https://research.splunk.com/application/de365ffa-42f5-46b5-b43f-fa72290b8218 +ESCU - Net Localgroup Discovery - Rule,Detection,5.2.0,Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net,ESCU - Windows Group Discovery Via Net - Rule,https://research.splunk.com/endpoint/c5c8e0f3-147a-43da-bf04-4cfaec27dc44 +ESCU - Network Connection Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Network Connection Discovery Via Net - Rule,https://research.splunk.com/endpoint/86a5b949-679b-4197-8d4c-9c180a818c45 +ESCU - O365 Suspicious Admin Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - O365 Mailbox Email Forwarding Enabled - Rule,https://research.splunk.com/cloud/0b6bc75c-05d1-4101-9fc3-97e706168f24 +ESCU - O365 Suspicious Rights Delegation - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - O365 Elevated Mailbox Permission Assigned - Rule,https://research.splunk.com/cloud/2246c142-a678-45f8-8546-aaed7e0efd30 +ESCU - O365 Suspicious User Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - O365 Mailbox Email Forwarding Enabled - Rule,https://research.splunk.com/cloud/0b6bc75c-05d1-4101-9fc3-97e706168f24 +ESCU - Office Application Drop Executable - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Dropped Uncommon File - Rule,https://research.splunk.com/endpoint/7ac0fced-9eae-4381-a748-90dcd1aa9393 +ESCU - Office Application Spawn Regsvr32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Office Application Spawn rundll32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Office Document Creating Schedule Task - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Loading Taskschd DLL - Rule,https://research.splunk.com/endpoint/d7297cfa-1f04-4714-bfbe-3679e0666959 +ESCU - Office Document Executing Macro Code - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Loading VBE7 DLL - Rule,https://research.splunk.com/endpoint/7cfec906-2697-43f7-898b-83634a051d9a +ESCU - Office Document Spawned Child Process To Download - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Spawned Child Process For Download - Rule,https://research.splunk.com/endpoint/f02b64b8-cbea-4f75-bf77-7a05111566b1 +ESCU - Office Product Spawn CMD Process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Office Product Spawning BITSAdmin - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Office Product Spawning CertUtil - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Office Product Spawning MSHTA - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Office Product Spawning Rundll32 with no DLL - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Spawned Rundll32 With No DLL - Rule,https://research.splunk.com/endpoint/f28e787e-69ca-480e-9f98-ab970e6d4bcc +ESCU - Office Product Spawning Windows Script Host - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Office Product Spawning Wmic - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Office Product Writing cab or inf - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Dropped Cab or Inf File - Rule,https://research.splunk.com/endpoint/dbdd251e-dd45-4ec9-a555-f5e151391746 +ESCU - Office Spawning Control - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Spawned Control - Rule,https://research.splunk.com/endpoint/081c485d-ac8d-4bee-ad4c-525772fead4d +ESCU - Okta Account Locked Out - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta Multiple Accounts Locked Out - Rule,https://research.splunk.com/application/a511426e-184f-4de6-8711-cfd2af29d1e1 +ESCU - Okta Account Lockout Events - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta Multiple Accounts Locked Out - Rule,https://research.splunk.com/application/a511426e-184f-4de6-8711-cfd2af29d1e1 +ESCU - Okta Failed SSO Attempts - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta Unauthorized Access to Application - Rule,https://research.splunk.com/application/5f661629-9750-4cb9-897c-1f05d6db8727 +ESCU - Okta ThreatInsight Login Failure with High Unknown users - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Okta ThreatInsight Suspected PasswordSpray Attack - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta ThreatInsight Threat Detected - Rule,https://research.splunk.com/application/140504ae-5fe2-4d65-b2bc-a211813fbca6 +ESCU - Okta Two or More Rejected Okta Pushes - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Okta Multiple Failed MFA Requests For User - Rule,https://research.splunk.com/application/826dbaae-a1e6-4c8c-b384-d16898956e73 +ESCU - Open Redirect in Splunk Web - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Osquery pack - ColdRoot detection - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Password Policy Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Password Policy Discovery with Net - Rule,https://research.splunk.com/endpoint/e52f7865-be78-46bf-b7ed-150fbe447613 +ESCU - Processes created by netsh - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Processes launching netsh - Rule,https://research.splunk.com/endpoint/b89919ed-fe5f-492c-b139-95dbb162040e +ESCU - Prohibited Software On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Attacker Tools On Endpoint - Rule,https://research.splunk.com/endpoint/a51bfe1a-94f0-48cc-b4e4-16a110145893 +ESCU - Reg exe used to hide files directories via registry keys - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Remote Registry Key modifications - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,This analytic was focusing on 2 separate and unrelated type of threats or actions. PLease use the replacement content,ESCU - Windows Sensitive Group Discovery With Net - Rule,https://research.splunk.com/endpoint/d9eb7cda-5622-4722-bc88-7f2442f4b5af +ESCU - Scheduled tasks used in BadRabbit ransomware - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Scheduled Task Deleted Or Created via CMD - Rule,https://research.splunk.com/endpoint/d5af132c-7c17-439c-9d31-13d55340f36c +ESCU - Spectre and Meltdown Vulnerable Systems - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Splunk Enterprise Information Disclosure - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Suspicious Changes to File Associations - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Suspicious Email - UBA Anomaly - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Suspicious File Write - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Suspicious Powershell Command-Line Arguments - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Malicious PowerShell Process - Encoded Command - Rule,https://research.splunk.com/endpoint/c4db14d9-7909-48b4-a054-aa14d89dbb19 +ESCU - Suspicious Rundll32 Rename - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Suspicious writes to System Volume Information - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Uncommon Processes On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Attacker Tools On Endpoint - Rule,https://research.splunk.com/endpoint/a51bfe1a-94f0-48cc-b4e4-16a110145893 +ESCU - Unsigned Image Loaded by LSASS - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Unsuccessful Netbackup backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Web Fraud - Account Harvesting - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Web Fraud - Anomalous User Clickspeed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Web Fraud - Password Sharing Across Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Windows Command Shell Fetch Env Variables - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows List ENV Variables Via SET Command From Uncommon Parent - Rule,https://research.splunk.com/endpoint/aec157f4-8783-4584-aca6-754c4dc7fba9 +ESCU - Windows DLL Search Order Hijacking Hunt - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,ESCU - Windows DLL Search Order Hijacking Hunt with Sysmon - Rule,https://research.splunk.com/endpoint/79c7d1fc-64c7-91be-a616-ccda752efe81 +ESCU - Windows Lateral Tool Transfer RemCom - Rule,Detection,5.2.0,Updated to a new detection name,ESCU - Windows Service Execution RemCom - Rule,https://research.splunk.com/endpoint/7e3d68db-ea4d-419b-adbd-e14a525ecf09 +ESCU - Windows MSIExec With Network Connections - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows HTTP Network Communication From MSIExec - Rule,https://research.splunk.com/endpoint/b0fd38c7-f71a-43a2-870e-f3ca06bcdd99 +ESCU - Windows Modify Registry Reg Restore - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Registry Entries Restored Via Reg - Rule,https://research.splunk.com/endpoint/a17af481-e2ad-494c-9da6-afb4d243a019 +ESCU - Windows Network Share Interaction With Net - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Network Share Interaction Via Net - Rule,https://research.splunk.com/endpoint/e51fbdb0-0be0-474f-92ea-d289f71a695e +ESCU - Windows Office Product Spawning MSDT - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Office Product Spawned MSDT - Rule,https://research.splunk.com/endpoint/a3148fad-3734-4b7f-9a71-62f08d39fab1 +ESCU - Windows Query Registry Reg Save - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Registry Entries Exported Via Reg - Rule,https://research.splunk.com/endpoint/466379bc-0f47-476c-8202-16ef38112e0d +ESCU - Windows Service Stop Via Net and SC Application - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Windows Valid Account With Never Expires Password - Rule,Detection,5.2.0,Renamed and updated logic,ESCU - Windows Set Account Password Policy To Unlimited Via Net - Rule,https://research.splunk.com/endpoint/11f93009-8083-43fd-82a7-821fcbdc8342 +ESCU - Windows connhost exe started forcefully - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Windows hosts file modification - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +ESCU - Winword Spawning Cmd - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Winword Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - Winword Spawning Windows Script Host - Rule,Detection,5.2.0,"The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level. +This would ease management and false positives tuning.",ESCU - Windows Office Product Spawned Uncommon Process - Rule,https://research.splunk.com/endpoint/55d8741c-fa32-4692-8109-410304961eb8 +ESCU - gcp detect oauth token abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +AWS Cryptomining,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Cloud Cryptomining,https://research.splunk.com/stories/cloud_cryptomining +AWS Suspicious Provisioning Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Suspicious Cloud Provisioning Activities,https://research.splunk.com/stories/suspicious_cloud_provisioning_activities +Common Phishing Frameworks,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +Container Implantation Monitoring and Investigation,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Kubernetes Security,https://research.splunk.com/stories/kubernetes_security +Host Redirection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +Kubernetes Sensitive Role Activity,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Kubernetes Security,https://research.splunk.com/stories/kubernetes_security +Lateral Movement,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Compromised User Account,https://research.splunk.com/stories/compromised_user_account +Monitor Backup Solution,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +Monitor for Unauthorized Software,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +Office 365 Detections,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Office 365 Account Takeover,https://research.splunk.com/stories/office_365_account_takeover +Spectre And Meltdown Vulnerabilities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available +Suspicious AWS EC2 Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Suspicious Cloud Instance Activities,https://research.splunk.com/stories/suspicious_cloud_instance_activities +Unusual AWS EC2 Modifications,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,Suspicious Cloud Instance Activities,https://research.splunk.com/stories/suspicious_cloud_instance_activities +Web Fraud Detection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,No Replacement Content Available,No Content Link Available