mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
resolved merge conflict
This commit is contained in:
@@ -28,8 +28,6 @@ tags:
|
||||
- AWS Network ACL Activity
|
||||
- Suspicious AWS Traffic
|
||||
- Command and Control
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect Spike in blocked Outbound Traffic from your AWS
|
||||
product:
|
||||
|
||||
@@ -34,8 +34,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud User Activities
|
||||
deployments:
|
||||
- Weekly Model Rebuild 90 Day Lookback
|
||||
detections:
|
||||
- Abnormally High Number Of Cloud Infrastructure API Calls
|
||||
product:
|
||||
@@ -47,3 +45,9 @@ tags:
|
||||
- All_Changes.user
|
||||
- All_Changes.status
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -37,8 +37,6 @@ tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud Instance Activities
|
||||
- Cloud Cryptomining
|
||||
deployments:
|
||||
- Weekly Model Rebuild 90 Day Lookback
|
||||
detections:
|
||||
- Abnormally High Number Of Cloud Instances Destroyed
|
||||
product:
|
||||
@@ -51,3 +49,9 @@ tags:
|
||||
- All_Changes.status
|
||||
- All_Changes.object_category
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -37,8 +37,6 @@ tags:
|
||||
analytic_story:
|
||||
- Cloud Cryptomining
|
||||
- Suspicious Cloud Instance Activities
|
||||
deployments:
|
||||
- Weekly Model Rebuild 90 Day Lookback
|
||||
detections:
|
||||
- Abnormally High Number Of Cloud Instances Launched
|
||||
product:
|
||||
@@ -51,3 +49,9 @@ tags:
|
||||
- All_Changes.status
|
||||
- All_Changes.object_category
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -33,8 +33,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud User Activities
|
||||
deployments:
|
||||
- Weekly Model Rebuild 90 Day Lookback
|
||||
detections:
|
||||
- Abnormally High Number Of Cloud Security Group API Calls
|
||||
product:
|
||||
@@ -47,3 +45,9 @@ tags:
|
||||
- All_Changes.status
|
||||
- All_Changes.object_category
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -34,8 +34,6 @@ tags:
|
||||
- Suspicious Command-Line Executions
|
||||
- Suspicious MSHTA Activity
|
||||
- Unusual Processes
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect Prohibited Applications Spawning cmd.exe
|
||||
- Unusually Long Command Line - MLTK
|
||||
@@ -50,3 +48,4 @@ tags:
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
security_domain: endpoint
|
||||
|
||||
|
||||
@@ -30,8 +30,6 @@ tags:
|
||||
- Hidden Cobra Malware
|
||||
- Suspicious DNS Traffic
|
||||
- Command and Control
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- DNS Query Length Outliers - MLTK
|
||||
product:
|
||||
|
||||
@@ -23,8 +23,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- AWS Network ACL Activity
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect Spike in Network ACL Activity
|
||||
product:
|
||||
|
||||
@@ -22,8 +22,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious AWS S3 Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect Spike in S3 Bucket deletion
|
||||
product:
|
||||
|
||||
@@ -23,8 +23,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- AWS User Monitoring
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect Spike in Security Group Activity
|
||||
product:
|
||||
|
||||
@@ -40,8 +40,6 @@ tags:
|
||||
- Hidden Cobra Malware
|
||||
- Netsh Abuse
|
||||
- Ransomware
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Processes launching netsh
|
||||
- SMB Traffic Spike - MLTK
|
||||
|
||||
@@ -19,8 +19,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Asset Tracking
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect Unauthorized Assets by MAC address
|
||||
product:
|
||||
|
||||
@@ -20,8 +20,6 @@ tags:
|
||||
- Prohibited Traffic Allowed or Protocol Mismatch
|
||||
- Ransomware
|
||||
- Command and Control
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Prohibited Network Traffic Allowed
|
||||
product:
|
||||
|
||||
@@ -21,8 +21,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- AWS User Monitoring
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect AWS API Activities From Unapproved Accounts
|
||||
product:
|
||||
|
||||
@@ -21,8 +21,6 @@ tags:
|
||||
- Monitor for Unauthorized Software
|
||||
- SamSam Ransomware
|
||||
asset_type: Endpoint
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Prohibited Software On Endpoint
|
||||
product:
|
||||
|
||||
@@ -22,8 +22,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- AWS User Monitoring
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect Spike in AWS API Activity
|
||||
product:
|
||||
|
||||
@@ -33,8 +33,6 @@ tags:
|
||||
analytic_story:
|
||||
- AWS Cryptomining
|
||||
- Suspicious AWS EC2 Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Abnormally High AWS Instances Launched by User - MLTK
|
||||
product:
|
||||
|
||||
@@ -33,8 +33,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious AWS EC2 Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Abnormally High AWS Instances Terminated by User - MLTK
|
||||
product:
|
||||
|
||||
@@ -22,8 +22,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- AWS User Monitoring
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect new API calls from user roles
|
||||
product:
|
||||
|
||||
@@ -20,8 +20,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- AWS Suspicious Provisioning Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- AWS Cloud Provisioning From Previously Unseen IP Address
|
||||
- AWS Cloud Provisioning From Previously Unseen City
|
||||
|
||||
@@ -18,8 +18,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- AWS Cryptomining
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- EC2 Instance Started With Previously Unseen AMI
|
||||
product:
|
||||
|
||||
@@ -18,8 +18,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- AWS Cryptomining
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- EC2 Instance Started With Previously Unseen Instance Type
|
||||
product:
|
||||
|
||||
@@ -19,8 +19,6 @@ tags:
|
||||
analytic_story:
|
||||
- AWS Cryptomining
|
||||
- Suspicious AWS EC2 Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- EC2 Instance Started With Previously Unseen User
|
||||
product:
|
||||
|
||||
@@ -23,8 +23,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious AWS Login Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect AWS Console Login by User from New Country
|
||||
- Detect AWS Console Login by User from New Region
|
||||
|
||||
@@ -25,8 +25,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious AWS Login Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect AWS Console Login by User from New Country
|
||||
- Detect AWS Console Login by User from New Region
|
||||
|
||||
@@ -27,8 +27,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- DNS Hijacking
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- DNS record changed
|
||||
product:
|
||||
|
||||
@@ -20,8 +20,6 @@ tags:
|
||||
- Brand Monitoring
|
||||
- Suspicious Emails
|
||||
asset_type: Endpoint
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Monitor Email For Brand Abuse
|
||||
- Monitor DNS For Brand Abuse
|
||||
|
||||
@@ -21,8 +21,6 @@ tags:
|
||||
- Ryuk Ransomware
|
||||
- Hidden Cobra Malware
|
||||
- Active Directory Lateral Movement
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Remote Desktop Network Traffic
|
||||
product:
|
||||
|
||||
@@ -22,8 +22,6 @@ tags:
|
||||
- Ryuk Ransomware
|
||||
- Hidden Cobra Malware
|
||||
- Active Directory Lateral Movement
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Remote Desktop Network Traffic
|
||||
product:
|
||||
|
||||
@@ -21,8 +21,6 @@ tags:
|
||||
- Ryuk Ransomware
|
||||
- Hidden Cobra Malware
|
||||
- Active Directory Lateral Movement
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Remote Desktop Network Traffic
|
||||
product:
|
||||
|
||||
@@ -18,8 +18,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Monitor Backup Solution
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Unsuccessful Netbackup backups
|
||||
product:
|
||||
|
||||
@@ -17,8 +17,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Monitor Backup Solution
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Unsuccessful Netbackup backups
|
||||
product:
|
||||
|
||||
@@ -22,8 +22,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- AWS Cross Account Activity
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- AWS Cross Account Activity From Previously Unseen Account
|
||||
product:
|
||||
|
||||
@@ -26,8 +26,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud Authentication Activities
|
||||
deployments:
|
||||
- 90 Day Baseline
|
||||
detections:
|
||||
- AWS Cross Account Activity From Previously Unseen Account
|
||||
product:
|
||||
@@ -42,3 +40,9 @@ tags:
|
||||
- Authentication.src
|
||||
- Authentication.user_role
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -27,8 +27,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud Authentication Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- AWS Cross Account Activity From Previously Unseen Account
|
||||
product:
|
||||
|
||||
@@ -20,8 +20,6 @@ tags:
|
||||
analytic_story:
|
||||
- AWS Cryptomining
|
||||
- Suspicious AWS EC2 Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- EC2 Instance Started In Previously Unseen Region
|
||||
product:
|
||||
|
||||
@@ -22,8 +22,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud User Activities
|
||||
deployments:
|
||||
- 90 Day Baseline
|
||||
detections:
|
||||
- Cloud API Calls From Previously Unseen User Roles
|
||||
product:
|
||||
@@ -37,3 +35,9 @@ tags:
|
||||
- All_Changes.user
|
||||
- All_Changes.command
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -24,8 +24,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud User Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Cloud API Calls From Previously Unseen User Roles
|
||||
product:
|
||||
|
||||
@@ -19,8 +19,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cloud Cryptomining
|
||||
deployments:
|
||||
- Hourly Cache Updates
|
||||
detections:
|
||||
- Cloud Compute Instance Created By Previously Unseen User
|
||||
product:
|
||||
@@ -33,3 +31,9 @@ tags:
|
||||
- All_Changes.object_category
|
||||
- All_Changes.user
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 55 * * * *
|
||||
earliest_time: -70m@m
|
||||
latest_time: -10m@m
|
||||
schedule_window: auto
|
||||
@@ -22,8 +22,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cloud Cryptomining
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Cloud Compute Instance Created By Previously Unseen User
|
||||
product:
|
||||
|
||||
@@ -21,8 +21,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cloud Cryptomining
|
||||
deployments:
|
||||
- 90 Day Baseline
|
||||
detections:
|
||||
- Cloud Compute Instance Created With Previously Unseen Image
|
||||
product:
|
||||
@@ -34,3 +32,9 @@ tags:
|
||||
- All_Changes.action
|
||||
- All_Changes.Instance_Changes.image_id
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -22,8 +22,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cloud Cryptomining
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Cloud Compute Instance Created With Previously Unseen Image
|
||||
product:
|
||||
|
||||
@@ -20,8 +20,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cloud Cryptomining
|
||||
deployments:
|
||||
- 90 Day Baseline
|
||||
detections:
|
||||
- Cloud Compute Instance Created With Previously Unseen Instance Type
|
||||
product:
|
||||
@@ -33,3 +31,9 @@ tags:
|
||||
- All_Changes.action
|
||||
- All_Changes.Instance_Changes.instance_type
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -22,8 +22,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cloud Cryptomining
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Cloud Compute Instance Created With Previously Unseen Instance Type
|
||||
product:
|
||||
|
||||
@@ -20,8 +20,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud Instance Activities
|
||||
deployments:
|
||||
- 90 Day Baseline
|
||||
detections:
|
||||
- Cloud Instance Modified By Previously Unseen User
|
||||
product:
|
||||
@@ -35,3 +33,9 @@ tags:
|
||||
- All_Changes.status
|
||||
- All_Changes.user
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -24,8 +24,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud Instance Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Cloud Instance Modified By Previously Unseen User
|
||||
product:
|
||||
|
||||
@@ -24,8 +24,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud Provisioning Activities
|
||||
deployments:
|
||||
- 90 Day Baseline
|
||||
detections:
|
||||
- Cloud Provisioning Activity From Previously Unseen IP Address
|
||||
- Cloud Provisioning Activity From Previously Unseen City
|
||||
@@ -41,3 +39,9 @@ tags:
|
||||
- All_Changes.src
|
||||
- All_Changes.status
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -29,8 +29,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud Provisioning Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Cloud Provisioning Activity From Previously Unseen IP Address
|
||||
- Cloud Provisioning Activity From Previously Unseen City
|
||||
|
||||
@@ -22,8 +22,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cloud Cryptomining
|
||||
deployments:
|
||||
- 90 Day Baseline
|
||||
detections:
|
||||
- Cloud Compute Instance Created In Previously Unused Region
|
||||
product:
|
||||
@@ -35,3 +33,9 @@ tags:
|
||||
- All_Changes.action
|
||||
- All_Changes.vendor_region
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -25,8 +25,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cloud Cryptomining
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Cloud Compute Instance Created In Previously Unused Region
|
||||
product:
|
||||
|
||||
@@ -30,8 +30,6 @@ tags:
|
||||
- Suspicious Command-Line Executions
|
||||
- Suspicious MSHTA Activity
|
||||
- IcedID
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- First time seen command line argument
|
||||
product:
|
||||
|
||||
@@ -18,8 +18,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Unusual AWS EC2 Modifications
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- EC2 Instance Modified With Previously Unseen User
|
||||
product:
|
||||
|
||||
@@ -20,8 +20,6 @@ tags:
|
||||
- Orangeworm Attack Group
|
||||
- Windows Service Abuse
|
||||
- NOBELIUM Group
|
||||
deployments:
|
||||
- 90 Day Baseline
|
||||
detections:
|
||||
- First Time Seen Running Windows Service
|
||||
product:
|
||||
@@ -33,3 +31,9 @@ tags:
|
||||
- EventCode
|
||||
- Message
|
||||
security_domain: endpoint
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -25,8 +25,6 @@ tags:
|
||||
- Orangeworm Attack Group
|
||||
- Windows Service Abuse
|
||||
- NOBELIUM Group
|
||||
deployments:
|
||||
- Hourly Cache Updates
|
||||
detections:
|
||||
- First Time Seen Running Windows Service
|
||||
product:
|
||||
@@ -38,3 +36,9 @@ tags:
|
||||
- EventCode
|
||||
- Message
|
||||
security_domain: endpoint
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 55 * * * *
|
||||
earliest_time: -70m@m
|
||||
latest_time: -10m@m
|
||||
schedule_window: auto
|
||||
@@ -21,8 +21,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious AWS S3 Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect S3 access from a new IP
|
||||
product:
|
||||
|
||||
@@ -25,8 +25,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud Authentication Activities
|
||||
deployments:
|
||||
- 90 Day Baseline
|
||||
detections:
|
||||
- Detect AWS Console Login by User from New Country
|
||||
- Detect AWS Console Login by User from New Region
|
||||
@@ -42,3 +40,9 @@ tags:
|
||||
- Authentication.user
|
||||
- Authentication.src
|
||||
security_domain: network
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -25,8 +25,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud Authentication Activities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Detect AWS Console Login by User from New Country
|
||||
- Detect AWS Console Login by User from New Region
|
||||
|
||||
@@ -22,8 +22,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Zoom Child Processes
|
||||
deployments:
|
||||
- 90 Day Baseline
|
||||
detections:
|
||||
- First Time Seen Child Process of Zoom
|
||||
product:
|
||||
@@ -36,3 +34,9 @@ tags:
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
security_domain: endpoint
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
@@ -27,8 +27,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Zoom Child Processes
|
||||
deployments:
|
||||
- Hourly Cache Updates
|
||||
detections:
|
||||
- First Time Seen Child Process of Zoom
|
||||
product:
|
||||
@@ -41,3 +39,9 @@ tags:
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
security_domain: endpoint
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 55 * * * *
|
||||
earliest_time: -70m@m
|
||||
latest_time: -10m@m
|
||||
schedule_window: auto
|
||||
@@ -77,4 +77,9 @@ tags:
|
||||
security_domain: audit
|
||||
detections:
|
||||
- Splunk Command and Scripting Interpreter Risky SPL MLTK
|
||||
|
||||
deployment:
|
||||
scheduling:
|
||||
cron_schedule: 55 * * * *
|
||||
earliest_time: -70m@m
|
||||
latest_time: -10m@m
|
||||
schedule_window: auto
|
||||
|
||||
@@ -24,8 +24,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Spectre And Meltdown Vulnerabilities
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- Spectre and Meltdown Vulnerable Systems
|
||||
product:
|
||||
|
||||
@@ -17,8 +17,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Monitor for Updates
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- No Windows Updates in a time frame
|
||||
product:
|
||||
|
||||
@@ -17,8 +17,6 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Monitor for Updates
|
||||
deployments:
|
||||
- Daily Cache Updates
|
||||
detections:
|
||||
- No Windows Updates in a time frame
|
||||
product:
|
||||
|
||||
@@ -4,8 +4,8 @@ date: '2021-12-21'
|
||||
author: Patrick Bareiss
|
||||
description: This configuration file applies to all detections of type baseline.
|
||||
scheduling:
|
||||
cron_schedule: 0 * * * *
|
||||
earliest_time: -70m@m
|
||||
cron_schedule: 10 0 * * *
|
||||
earliest_time: -1450m@m
|
||||
latest_time: -10m@m
|
||||
schedule_window: auto
|
||||
tags:
|
||||
|
||||
@@ -1,22 +0,0 @@
|
||||
name: Detect ARP Poisoning deployment configuration
|
||||
id: e1d5b4dc-4cf3-404f-905c-b478bbb20474
|
||||
date: '2020-08-14'
|
||||
author: Mikael Bjerkeland
|
||||
description: This configuration file applies to the Detect ARP Poisoning detection
|
||||
scheduling:
|
||||
cron_schedule: 59 * * * *
|
||||
earliest_time: -70m@m
|
||||
latest_time: -10m@m
|
||||
schedule_window: auto
|
||||
alert_action:
|
||||
notable:
|
||||
rule_description: ARP Poisoning has been detected on interface $src_interface$
|
||||
on host $orig_host$. This may be an indication of a MITM attack.
|
||||
rule_title: ARP Poisoning Detected on $orig_host$
|
||||
nes_fields:
|
||||
- src_interface
|
||||
- firstTime
|
||||
- lastTime
|
||||
- count
|
||||
tags:
|
||||
name: Detect ARP Poisoning
|
||||
@@ -1,23 +0,0 @@
|
||||
name: Detect Rogue DHCP Server deployment configuration
|
||||
id: 6e4e20ac-e719-4ebe-a52d-d672cd451dbb
|
||||
date: '2020-08-14'
|
||||
author: Mikael Bjerkeland
|
||||
description: This configuration file applies to the Detect Rogue DHCP Server detection
|
||||
scheduling:
|
||||
cron_schedule: 59 * * * *
|
||||
earliest_time: -70m@m
|
||||
latest_time: -10m@m
|
||||
schedule_window: auto
|
||||
alert_action:
|
||||
notable:
|
||||
rule_description: DHCP Snooping has detected a Rogue DHCP Server on $orig_host$
|
||||
from $src_mac$. This may be an indication of a MITM attack.
|
||||
rule_title: Rogue DHCP Server Detected on $orig_host$
|
||||
nes_fields:
|
||||
- src_mac
|
||||
- firstTime
|
||||
- lastTime
|
||||
- count
|
||||
- message_type
|
||||
tags:
|
||||
name: Detect Rogue DHCP Server
|
||||
@@ -1,13 +0,0 @@
|
||||
name: Baseline Cache Hourly Updates
|
||||
id: 1030c701-2acf-4b1a-9970-46c7145caf2d
|
||||
date: '2020-06-24'
|
||||
author: Bhavin Patel
|
||||
description: This configuration file applies to all baselines with tag deployments
|
||||
Hourly Cache Updates
|
||||
scheduling:
|
||||
cron_schedule: 55 * * * *
|
||||
earliest_time: -70m@m
|
||||
latest_time: -10m@m
|
||||
schedule_window: auto
|
||||
tags:
|
||||
deployments: Hourly Cache Updates
|
||||
@@ -1,13 +0,0 @@
|
||||
name: Baseline Cache Daily Updates
|
||||
id: 9541d6f8-fa58-4d48-bb44-6720e39b7b0d
|
||||
date: '2020-08-18'
|
||||
author: David Dorsey
|
||||
description: This configuration file applies to all baselines with tag deployments
|
||||
Daily Cache Updates
|
||||
scheduling:
|
||||
cron_schedule: 10 0 * * *
|
||||
earliest_time: -1450m@m
|
||||
latest_time: -10m@m
|
||||
schedule_window: auto
|
||||
tags:
|
||||
deployments: Daily Cache Updates
|
||||
@@ -1,13 +0,0 @@
|
||||
name: 90 Day Baseline Searches
|
||||
id: 6eac9f8b-a35d-4b64-b57f-e5ecde43be6b
|
||||
date: '2020-06-24'
|
||||
author: Bhavin Patel
|
||||
description: This configuration file applies to all baselines with tag deployments
|
||||
Long Running Baseline
|
||||
scheduling:
|
||||
cron_schedule: 0 1 1 1,4,7,10 *
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
tags:
|
||||
deployments: 90 Day Baseline
|
||||
@@ -1,13 +0,0 @@
|
||||
name: Weekly Model Rebuild 90 Day Lookback
|
||||
id: 4b329568-bcff-49fa-8c85-92e95f0f270d
|
||||
date: '2020-09-07'
|
||||
author: David Dorsey
|
||||
description: This configuration file applies to all baselines with tag deployments
|
||||
Weekly Model Rebuild 90 Day Lookback
|
||||
scheduling:
|
||||
cron_schedule: 0 2 * * 0
|
||||
earliest_time: -90d@d
|
||||
latest_time: -1d@d
|
||||
schedule_window: auto
|
||||
tags:
|
||||
deployments: Weekly Model Rebuild 90 Day Lookback
|
||||
@@ -63,3 +63,14 @@ tags:
|
||||
- Splunk Cloud
|
||||
risk_score: 90
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/crowdstrike_falcon.log
|
||||
source: crowdstrike
|
||||
sourcetype: crowdstrike:events:sensor
|
||||
|
||||
@@ -16,7 +16,11 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime
|
||||
OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify*
|
||||
OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet*
|
||||
OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices*
|
||||
OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows
|
||||
OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\*
|
||||
OR Registry.registry_path= "*\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Common Startup"
|
||||
OR Registry.registry_path= *\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler
|
||||
OR Registry.registry_path= *\\Classes\\htmlfile\\shell\\open\\command
|
||||
OR (Registry.registry_path="*Microsoft\\Windows
|
||||
NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger)
|
||||
OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security
|
||||
Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig"
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2023-01-03T12:38:50 UTC
|
||||
# On Date: 2023-01-09T11:37:43 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
Vendored
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2023-01-03T12:38:50 UTC
|
||||
# On Date: 2023-01-09T11:37:43 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2023-01-03T12:38:50 UTC
|
||||
# On Date: 2023-01-09T11:37:43 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
Vendored
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2023-01-03T12:38:50 UTC
|
||||
# On Date: 2023-01-09T11:37:43 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
Vendored
+31
-1029
File diff suppressed because it is too large
Load Diff
Vendored
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2023-01-03T12:38:50 UTC
|
||||
# On Date: 2023-01-09T11:37:43 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2023-01-03T12:38:50 UTC
|
||||
# On Date: 2023-01-09T11:37:43 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
@@ -36,9 +36,7 @@ tags:
|
||||
- Unusual Processes
|
||||
- Credential Dumping
|
||||
asset_type: Windows
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: Malicious actor is accessing stored credentials via FGDump or CacheDump
|
||||
tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$
|
||||
|
||||
-2
@@ -51,9 +51,7 @@ tags:
|
||||
analytic_story:
|
||||
- Active Directory Lateral Movement
|
||||
asset_type: Windows
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: Potential lateral movement and credential stealing via Pass the Token or
|
||||
Pass the Hash techniques. Operation is performed via credentials of the account
|
||||
|
||||
-2
@@ -52,9 +52,7 @@ tags:
|
||||
analytic_story:
|
||||
- Active Directory Lateral Movement
|
||||
asset_type: Windows
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: Potential lateral movement and credential stealing via Pass the Token or
|
||||
Pass the Hash techniques. Operation is performed via credentials of the account
|
||||
|
||||
@@ -55,9 +55,7 @@ tags:
|
||||
analytic_story:
|
||||
- Unusual Processes
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: A system process $process_name$ with commandline $cmd_line$ spawn iin short
|
||||
period of time in host $dest_device_id$
|
||||
|
||||
@@ -37,9 +37,7 @@ tags:
|
||||
analytic_story:
|
||||
- Unusual Processes
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 40
|
||||
drilldown_search: []
|
||||
impact: 30
|
||||
message: A process $process_name$ with a long commandline $cmd_line$ executed in
|
||||
host $dest_device_id$
|
||||
|
||||
@@ -30,9 +30,7 @@ tags:
|
||||
analytic_story:
|
||||
- Insider Threat
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 30
|
||||
drilldown_search: []
|
||||
impact: 20
|
||||
message: Multiple interactive logins detected on $device$
|
||||
mitre_attack_id:
|
||||
|
||||
@@ -35,9 +35,7 @@ tags:
|
||||
- NOBELIUM Group
|
||||
- Insider Threat
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 60
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading
|
||||
|
||||
@@ -37,9 +37,7 @@ tags:
|
||||
- XMRig
|
||||
- Ransomware
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 60
|
||||
drilldown_search: []
|
||||
impact: 60
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service.
|
||||
|
||||
@@ -39,9 +39,7 @@ tags:
|
||||
- XMRig
|
||||
- Ransomware
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 60
|
||||
drilldown_search: []
|
||||
impact: 60
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service.
|
||||
|
||||
@@ -35,9 +35,7 @@ tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: An attempt to save registry keys storing credentials has been performed
|
||||
on $dest_device_id$ by $dest_user_id$ via process $process_name$.
|
||||
|
||||
@@ -34,9 +34,7 @@ tags:
|
||||
- Ransomware
|
||||
- Information Sabotage
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
drilldown_search: []
|
||||
impact: 100
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability
|
||||
@@ -78,7 +76,5 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
update_timestamp: true
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-security_bcdedit_wbadmin.log
|
||||
source: WinEventLog:Security
|
||||
|
||||
@@ -33,9 +33,7 @@ tags:
|
||||
- Ransomware
|
||||
- Information Sabotage
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
drilldown_search: []
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to clear the unallocated sectors
|
||||
@@ -82,6 +80,5 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.004/cipher/security.log
|
||||
source: WinEventLog:Security
|
||||
|
||||
@@ -37,9 +37,7 @@ tags:
|
||||
- XMRig
|
||||
- Ransomware
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user
|
||||
|
||||
@@ -35,9 +35,7 @@ tags:
|
||||
- XMRig
|
||||
- Information Sabotage
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: A cacls process $process_name$ with commandline $cmd_line$ try to deny
|
||||
a permission of a file or directory in host $dest_device_id$
|
||||
|
||||
@@ -33,9 +33,7 @@ tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 20
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: Kerberoasting malware is potentially applying stolen credentials. Operation
|
||||
is performed at the device $dest_device_id$, by the account $dest_user_id$ via
|
||||
|
||||
@@ -40,9 +40,7 @@ tags:
|
||||
- Suspicious Command-Line Executions
|
||||
- Insider Threat
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event
|
||||
@@ -82,6 +80,5 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-security.log
|
||||
source: WinEventLog:Security
|
||||
|
||||
@@ -46,9 +46,7 @@ tags:
|
||||
- Ransomware
|
||||
- Insider Threat
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a
|
||||
@@ -90,6 +88,5 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-security.log
|
||||
source: WinEventLog:Security
|
||||
|
||||
@@ -34,9 +34,7 @@ tags:
|
||||
analytic_story:
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: Modified/added/deleted registry entry $registry_path$ in $dest$
|
||||
mitre_attack_id:
|
||||
@@ -65,9 +63,3 @@ tags:
|
||||
- Exploitation
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
|
||||
@@ -37,9 +37,7 @@ tags:
|
||||
- XMRig
|
||||
- Ransomware
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts.
|
||||
|
||||
@@ -42,9 +42,7 @@ tags:
|
||||
- Data Exfiltration
|
||||
- Command and Control
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
drilldown_search: []
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related
|
||||
@@ -86,6 +84,5 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-security.log
|
||||
source: WinEventLog:Security
|
||||
|
||||
@@ -28,9 +28,7 @@ tags:
|
||||
analytic_story:
|
||||
- Insider Threat
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
drilldown_search: []
|
||||
impact: 90
|
||||
message: High number of files copied
|
||||
mitre_attack_id:
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user