resolved merge conflict

This commit is contained in:
P4T12ICK
2023-01-20 08:02:00 +01:00
164 changed files with 182 additions and 1464 deletions
@@ -28,8 +28,6 @@ tags:
- AWS Network ACL Activity
- Suspicious AWS Traffic
- Command and Control
deployments:
- Daily Cache Updates
detections:
- Detect Spike in blocked Outbound Traffic from your AWS
product:
@@ -34,8 +34,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud User Activities
deployments:
- Weekly Model Rebuild 90 Day Lookback
detections:
- Abnormally High Number Of Cloud Infrastructure API Calls
product:
@@ -47,3 +45,9 @@ tags:
- All_Changes.user
- All_Changes.status
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -37,8 +37,6 @@ tags:
analytic_story:
- Suspicious Cloud Instance Activities
- Cloud Cryptomining
deployments:
- Weekly Model Rebuild 90 Day Lookback
detections:
- Abnormally High Number Of Cloud Instances Destroyed
product:
@@ -51,3 +49,9 @@ tags:
- All_Changes.status
- All_Changes.object_category
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -37,8 +37,6 @@ tags:
analytic_story:
- Cloud Cryptomining
- Suspicious Cloud Instance Activities
deployments:
- Weekly Model Rebuild 90 Day Lookback
detections:
- Abnormally High Number Of Cloud Instances Launched
product:
@@ -51,3 +49,9 @@ tags:
- All_Changes.status
- All_Changes.object_category
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -33,8 +33,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud User Activities
deployments:
- Weekly Model Rebuild 90 Day Lookback
detections:
- Abnormally High Number Of Cloud Security Group API Calls
product:
@@ -47,3 +45,9 @@ tags:
- All_Changes.status
- All_Changes.object_category
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -34,8 +34,6 @@ tags:
- Suspicious Command-Line Executions
- Suspicious MSHTA Activity
- Unusual Processes
deployments:
- Daily Cache Updates
detections:
- Detect Prohibited Applications Spawning cmd.exe
- Unusually Long Command Line - MLTK
@@ -50,3 +48,4 @@ tags:
- Processes.process_name
- Processes.process
security_domain: endpoint
@@ -30,8 +30,6 @@ tags:
- Hidden Cobra Malware
- Suspicious DNS Traffic
- Command and Control
deployments:
- Daily Cache Updates
detections:
- DNS Query Length Outliers - MLTK
product:
@@ -23,8 +23,6 @@ references: []
tags:
analytic_story:
- AWS Network ACL Activity
deployments:
- Daily Cache Updates
detections:
- Detect Spike in Network ACL Activity
product:
@@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- Suspicious AWS S3 Activities
deployments:
- Daily Cache Updates
detections:
- Detect Spike in S3 Bucket deletion
product:
@@ -23,8 +23,6 @@ references: []
tags:
analytic_story:
- AWS User Monitoring
deployments:
- Daily Cache Updates
detections:
- Detect Spike in Security Group Activity
product:
@@ -40,8 +40,6 @@ tags:
- Hidden Cobra Malware
- Netsh Abuse
- Ransomware
deployments:
- Daily Cache Updates
detections:
- Processes launching netsh
- SMB Traffic Spike - MLTK
@@ -19,8 +19,6 @@ references: []
tags:
analytic_story:
- Asset Tracking
deployments:
- Daily Cache Updates
detections:
- Detect Unauthorized Assets by MAC address
product:
@@ -20,8 +20,6 @@ tags:
- Prohibited Traffic Allowed or Protocol Mismatch
- Ransomware
- Command and Control
deployments:
- Daily Cache Updates
detections:
- Prohibited Network Traffic Allowed
product:
@@ -21,8 +21,6 @@ references: []
tags:
analytic_story:
- AWS User Monitoring
deployments:
- Daily Cache Updates
detections:
- Detect AWS API Activities From Unapproved Accounts
product:
@@ -21,8 +21,6 @@ tags:
- Monitor for Unauthorized Software
- SamSam Ransomware
asset_type: Endpoint
deployments:
- Daily Cache Updates
detections:
- Prohibited Software On Endpoint
product:
@@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- AWS User Monitoring
deployments:
- Daily Cache Updates
detections:
- Detect Spike in AWS API Activity
product:
@@ -33,8 +33,6 @@ tags:
analytic_story:
- AWS Cryptomining
- Suspicious AWS EC2 Activities
deployments:
- Daily Cache Updates
detections:
- Abnormally High AWS Instances Launched by User - MLTK
product:
@@ -33,8 +33,6 @@ references: []
tags:
analytic_story:
- Suspicious AWS EC2 Activities
deployments:
- Daily Cache Updates
detections:
- Abnormally High AWS Instances Terminated by User - MLTK
product:
@@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- AWS User Monitoring
deployments:
- Daily Cache Updates
detections:
- Detect new API calls from user roles
product:
@@ -20,8 +20,6 @@ references: []
tags:
analytic_story:
- AWS Suspicious Provisioning Activities
deployments:
- Daily Cache Updates
detections:
- AWS Cloud Provisioning From Previously Unseen IP Address
- AWS Cloud Provisioning From Previously Unseen City
@@ -18,8 +18,6 @@ references: []
tags:
analytic_story:
- AWS Cryptomining
deployments:
- Daily Cache Updates
detections:
- EC2 Instance Started With Previously Unseen AMI
product:
@@ -18,8 +18,6 @@ references: []
tags:
analytic_story:
- AWS Cryptomining
deployments:
- Daily Cache Updates
detections:
- EC2 Instance Started With Previously Unseen Instance Type
product:
@@ -19,8 +19,6 @@ tags:
analytic_story:
- AWS Cryptomining
- Suspicious AWS EC2 Activities
deployments:
- Daily Cache Updates
detections:
- EC2 Instance Started With Previously Unseen User
product:
@@ -23,8 +23,6 @@ references: []
tags:
analytic_story:
- Suspicious AWS Login Activities
deployments:
- Daily Cache Updates
detections:
- Detect AWS Console Login by User from New Country
- Detect AWS Console Login by User from New Region
@@ -25,8 +25,6 @@ references: []
tags:
analytic_story:
- Suspicious AWS Login Activities
deployments:
- Daily Cache Updates
detections:
- Detect AWS Console Login by User from New Country
- Detect AWS Console Login by User from New Region
-2
View File
@@ -27,8 +27,6 @@ references: []
tags:
analytic_story:
- DNS Hijacking
deployments:
- Daily Cache Updates
detections:
- DNS record changed
product:
-2
View File
@@ -20,8 +20,6 @@ tags:
- Brand Monitoring
- Suspicious Emails
asset_type: Endpoint
deployments:
- Daily Cache Updates
detections:
- Monitor Email For Brand Abuse
- Monitor DNS For Brand Abuse
@@ -21,8 +21,6 @@ tags:
- Ryuk Ransomware
- Hidden Cobra Malware
- Active Directory Lateral Movement
deployments:
- Daily Cache Updates
detections:
- Remote Desktop Network Traffic
product:
@@ -22,8 +22,6 @@ tags:
- Ryuk Ransomware
- Hidden Cobra Malware
- Active Directory Lateral Movement
deployments:
- Daily Cache Updates
detections:
- Remote Desktop Network Traffic
product:
@@ -21,8 +21,6 @@ tags:
- Ryuk Ransomware
- Hidden Cobra Malware
- Active Directory Lateral Movement
deployments:
- Daily Cache Updates
detections:
- Remote Desktop Network Traffic
product:
-2
View File
@@ -18,8 +18,6 @@ references: []
tags:
analytic_story:
- Monitor Backup Solution
deployments:
- Daily Cache Updates
detections:
- Unsuccessful Netbackup backups
product:
@@ -17,8 +17,6 @@ references: []
tags:
analytic_story:
- Monitor Backup Solution
deployments:
- Daily Cache Updates
detections:
- Unsuccessful Netbackup backups
product:
@@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- AWS Cross Account Activity
deployments:
- Daily Cache Updates
detections:
- AWS Cross Account Activity From Previously Unseen Account
product:
@@ -26,8 +26,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud Authentication Activities
deployments:
- 90 Day Baseline
detections:
- AWS Cross Account Activity From Previously Unseen Account
product:
@@ -42,3 +40,9 @@ tags:
- Authentication.src
- Authentication.user_role
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -27,8 +27,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud Authentication Activities
deployments:
- Daily Cache Updates
detections:
- AWS Cross Account Activity From Previously Unseen Account
product:
@@ -20,8 +20,6 @@ tags:
analytic_story:
- AWS Cryptomining
- Suspicious AWS EC2 Activities
deployments:
- Daily Cache Updates
detections:
- EC2 Instance Started In Previously Unseen Region
product:
@@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud User Activities
deployments:
- 90 Day Baseline
detections:
- Cloud API Calls From Previously Unseen User Roles
product:
@@ -37,3 +35,9 @@ tags:
- All_Changes.user
- All_Changes.command
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -24,8 +24,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud User Activities
deployments:
- Daily Cache Updates
detections:
- Cloud API Calls From Previously Unseen User Roles
product:
@@ -19,8 +19,6 @@ references: []
tags:
analytic_story:
- Cloud Cryptomining
deployments:
- Hourly Cache Updates
detections:
- Cloud Compute Instance Created By Previously Unseen User
product:
@@ -33,3 +31,9 @@ tags:
- All_Changes.object_category
- All_Changes.user
security_domain: network
deployment:
scheduling:
cron_schedule: 55 * * * *
earliest_time: -70m@m
latest_time: -10m@m
schedule_window: auto
@@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- Cloud Cryptomining
deployments:
- Daily Cache Updates
detections:
- Cloud Compute Instance Created By Previously Unseen User
product:
@@ -21,8 +21,6 @@ references: []
tags:
analytic_story:
- Cloud Cryptomining
deployments:
- 90 Day Baseline
detections:
- Cloud Compute Instance Created With Previously Unseen Image
product:
@@ -34,3 +32,9 @@ tags:
- All_Changes.action
- All_Changes.Instance_Changes.image_id
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- Cloud Cryptomining
deployments:
- Daily Cache Updates
detections:
- Cloud Compute Instance Created With Previously Unseen Image
product:
@@ -20,8 +20,6 @@ references: []
tags:
analytic_story:
- Cloud Cryptomining
deployments:
- 90 Day Baseline
detections:
- Cloud Compute Instance Created With Previously Unseen Instance Type
product:
@@ -33,3 +31,9 @@ tags:
- All_Changes.action
- All_Changes.Instance_Changes.instance_type
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- Cloud Cryptomining
deployments:
- Daily Cache Updates
detections:
- Cloud Compute Instance Created With Previously Unseen Instance Type
product:
@@ -20,8 +20,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud Instance Activities
deployments:
- 90 Day Baseline
detections:
- Cloud Instance Modified By Previously Unseen User
product:
@@ -35,3 +33,9 @@ tags:
- All_Changes.status
- All_Changes.user
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -24,8 +24,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud Instance Activities
deployments:
- Daily Cache Updates
detections:
- Cloud Instance Modified By Previously Unseen User
product:
@@ -24,8 +24,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud Provisioning Activities
deployments:
- 90 Day Baseline
detections:
- Cloud Provisioning Activity From Previously Unseen IP Address
- Cloud Provisioning Activity From Previously Unseen City
@@ -41,3 +39,9 @@ tags:
- All_Changes.src
- All_Changes.status
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -29,8 +29,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud Provisioning Activities
deployments:
- Daily Cache Updates
detections:
- Cloud Provisioning Activity From Previously Unseen IP Address
- Cloud Provisioning Activity From Previously Unseen City
@@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- Cloud Cryptomining
deployments:
- 90 Day Baseline
detections:
- Cloud Compute Instance Created In Previously Unused Region
product:
@@ -35,3 +33,9 @@ tags:
- All_Changes.action
- All_Changes.vendor_region
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -25,8 +25,6 @@ references: []
tags:
analytic_story:
- Cloud Cryptomining
deployments:
- Daily Cache Updates
detections:
- Cloud Compute Instance Created In Previously Unused Region
product:
@@ -30,8 +30,6 @@ tags:
- Suspicious Command-Line Executions
- Suspicious MSHTA Activity
- IcedID
deployments:
- Daily Cache Updates
detections:
- First time seen command line argument
product:
@@ -18,8 +18,6 @@ references: []
tags:
analytic_story:
- Unusual AWS EC2 Modifications
deployments:
- Daily Cache Updates
detections:
- EC2 Instance Modified With Previously Unseen User
product:
@@ -20,8 +20,6 @@ tags:
- Orangeworm Attack Group
- Windows Service Abuse
- NOBELIUM Group
deployments:
- 90 Day Baseline
detections:
- First Time Seen Running Windows Service
product:
@@ -33,3 +31,9 @@ tags:
- EventCode
- Message
security_domain: endpoint
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -25,8 +25,6 @@ tags:
- Orangeworm Attack Group
- Windows Service Abuse
- NOBELIUM Group
deployments:
- Hourly Cache Updates
detections:
- First Time Seen Running Windows Service
product:
@@ -38,3 +36,9 @@ tags:
- EventCode
- Message
security_domain: endpoint
deployment:
scheduling:
cron_schedule: 55 * * * *
earliest_time: -70m@m
latest_time: -10m@m
schedule_window: auto
@@ -21,8 +21,6 @@ references: []
tags:
analytic_story:
- Suspicious AWS S3 Activities
deployments:
- Daily Cache Updates
detections:
- Detect S3 access from a new IP
product:
@@ -25,8 +25,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud Authentication Activities
deployments:
- 90 Day Baseline
detections:
- Detect AWS Console Login by User from New Country
- Detect AWS Console Login by User from New Region
@@ -42,3 +40,9 @@ tags:
- Authentication.user
- Authentication.src
security_domain: network
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -25,8 +25,6 @@ references: []
tags:
analytic_story:
- Suspicious Cloud Authentication Activities
deployments:
- Daily Cache Updates
detections:
- Detect AWS Console Login by User from New Country
- Detect AWS Console Login by User from New Region
@@ -22,8 +22,6 @@ references: []
tags:
analytic_story:
- Suspicious Zoom Child Processes
deployments:
- 90 Day Baseline
detections:
- First Time Seen Child Process of Zoom
product:
@@ -36,3 +34,9 @@ tags:
- Processes.process_name
- Processes.dest
security_domain: endpoint
deployment:
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
@@ -27,8 +27,6 @@ references: []
tags:
analytic_story:
- Suspicious Zoom Child Processes
deployments:
- Hourly Cache Updates
detections:
- First Time Seen Child Process of Zoom
product:
@@ -41,3 +39,9 @@ tags:
- Processes.process_name
- Processes.dest
security_domain: endpoint
deployment:
scheduling:
cron_schedule: 55 * * * *
earliest_time: -70m@m
latest_time: -10m@m
schedule_window: auto
@@ -77,4 +77,9 @@ tags:
security_domain: audit
detections:
- Splunk Command and Scripting Interpreter Risky SPL MLTK
deployment:
scheduling:
cron_schedule: 55 * * * *
earliest_time: -70m@m
latest_time: -10m@m
schedule_window: auto
@@ -24,8 +24,6 @@ references: []
tags:
analytic_story:
- Spectre And Meltdown Vulnerabilities
deployments:
- Daily Cache Updates
detections:
- Spectre and Meltdown Vulnerable Systems
product:
@@ -17,8 +17,6 @@ references: []
tags:
analytic_story:
- Monitor for Updates
deployments:
- Daily Cache Updates
detections:
- No Windows Updates in a time frame
product:
@@ -17,8 +17,6 @@ references: []
tags:
analytic_story:
- Monitor for Updates
deployments:
- Daily Cache Updates
detections:
- No Windows Updates in a time frame
product:
+2 -2
View File
@@ -4,8 +4,8 @@ date: '2021-12-21'
author: Patrick Bareiss
description: This configuration file applies to all detections of type baseline.
scheduling:
cron_schedule: 0 * * * *
earliest_time: -70m@m
cron_schedule: 10 0 * * *
earliest_time: -1450m@m
latest_time: -10m@m
schedule_window: auto
tags:
-22
View File
@@ -1,22 +0,0 @@
name: Detect ARP Poisoning deployment configuration
id: e1d5b4dc-4cf3-404f-905c-b478bbb20474
date: '2020-08-14'
author: Mikael Bjerkeland
description: This configuration file applies to the Detect ARP Poisoning detection
scheduling:
cron_schedule: 59 * * * *
earliest_time: -70m@m
latest_time: -10m@m
schedule_window: auto
alert_action:
notable:
rule_description: ARP Poisoning has been detected on interface $src_interface$
on host $orig_host$. This may be an indication of a MITM attack.
rule_title: ARP Poisoning Detected on $orig_host$
nes_fields:
- src_interface
- firstTime
- lastTime
- count
tags:
name: Detect ARP Poisoning
-23
View File
@@ -1,23 +0,0 @@
name: Detect Rogue DHCP Server deployment configuration
id: 6e4e20ac-e719-4ebe-a52d-d672cd451dbb
date: '2020-08-14'
author: Mikael Bjerkeland
description: This configuration file applies to the Detect Rogue DHCP Server detection
scheduling:
cron_schedule: 59 * * * *
earliest_time: -70m@m
latest_time: -10m@m
schedule_window: auto
alert_action:
notable:
rule_description: DHCP Snooping has detected a Rogue DHCP Server on $orig_host$
from $src_mac$. This may be an indication of a MITM attack.
rule_title: Rogue DHCP Server Detected on $orig_host$
nes_fields:
- src_mac
- firstTime
- lastTime
- count
- message_type
tags:
name: Detect Rogue DHCP Server
@@ -1,13 +0,0 @@
name: Baseline Cache Hourly Updates
id: 1030c701-2acf-4b1a-9970-46c7145caf2d
date: '2020-06-24'
author: Bhavin Patel
description: This configuration file applies to all baselines with tag deployments
Hourly Cache Updates
scheduling:
cron_schedule: 55 * * * *
earliest_time: -70m@m
latest_time: -10m@m
schedule_window: auto
tags:
deployments: Hourly Cache Updates
@@ -1,13 +0,0 @@
name: Baseline Cache Daily Updates
id: 9541d6f8-fa58-4d48-bb44-6720e39b7b0d
date: '2020-08-18'
author: David Dorsey
description: This configuration file applies to all baselines with tag deployments
Daily Cache Updates
scheduling:
cron_schedule: 10 0 * * *
earliest_time: -1450m@m
latest_time: -10m@m
schedule_window: auto
tags:
deployments: Daily Cache Updates
@@ -1,13 +0,0 @@
name: 90 Day Baseline Searches
id: 6eac9f8b-a35d-4b64-b57f-e5ecde43be6b
date: '2020-06-24'
author: Bhavin Patel
description: This configuration file applies to all baselines with tag deployments
Long Running Baseline
scheduling:
cron_schedule: 0 1 1 1,4,7,10 *
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
tags:
deployments: 90 Day Baseline
@@ -1,13 +0,0 @@
name: Weekly Model Rebuild 90 Day Lookback
id: 4b329568-bcff-49fa-8c85-92e95f0f270d
date: '2020-09-07'
author: David Dorsey
description: This configuration file applies to all baselines with tag deployments
Weekly Model Rebuild 90 Day Lookback
scheduling:
cron_schedule: 0 2 * * 0
earliest_time: -90d@d
latest_time: -1d@d
schedule_window: auto
tags:
deployments: Weekly Model Rebuild 90 Day Lookback
@@ -63,3 +63,14 @@ tags:
- Splunk Cloud
risk_score: 90
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/crowdstrike_falcon.log
source: crowdstrike
sourcetype: crowdstrike:events:sensor
@@ -16,7 +16,11 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime
OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify*
OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet*
OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices*
OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows
OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\*
OR Registry.registry_path= "*\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Common Startup"
OR Registry.registry_path= *\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler
OR Registry.registry_path= *\\Classes\\htmlfile\\shell\\open\\command
OR (Registry.registry_path="*Microsoft\\Windows
NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger)
OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security
Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig"
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-01-03T12:38:50 UTC
# On Date: 2023-01-09T11:37:43 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-01-03T12:38:50 UTC
# On Date: 2023-01-09T11:37:43 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-01-03T12:38:50 UTC
# On Date: 2023-01-09T11:37:43 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-01-03T12:38:50 UTC
# On Date: 2023-01-09T11:37:43 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+31 -1029
View File
File diff suppressed because it is too large Load Diff
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-01-03T12:38:50 UTC
# On Date: 2023-01-09T11:37:43 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-01-03T12:38:50 UTC
# On Date: 2023-01-09T11:37:43 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -36,9 +36,7 @@ tags:
- Unusual Processes
- Credential Dumping
asset_type: Windows
atomic_guid: []
confidence: 90
drilldown_search: []
impact: 70
message: Malicious actor is accessing stored credentials via FGDump or CacheDump
tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$
@@ -51,9 +51,7 @@ tags:
analytic_story:
- Active Directory Lateral Movement
asset_type: Windows
atomic_guid: []
confidence: 90
drilldown_search: []
impact: 80
message: Potential lateral movement and credential stealing via Pass the Token or
Pass the Hash techniques. Operation is performed via credentials of the account
@@ -52,9 +52,7 @@ tags:
analytic_story:
- Active Directory Lateral Movement
asset_type: Windows
atomic_guid: []
confidence: 80
drilldown_search: []
impact: 80
message: Potential lateral movement and credential stealing via Pass the Token or
Pass the Hash techniques. Operation is performed via credentials of the account
@@ -55,9 +55,7 @@ tags:
analytic_story:
- Unusual Processes
asset_type: Endpoint
atomic_guid: []
confidence: 50
drilldown_search: []
impact: 50
message: A system process $process_name$ with commandline $cmd_line$ spawn iin short
period of time in host $dest_device_id$
@@ -37,9 +37,7 @@ tags:
analytic_story:
- Unusual Processes
asset_type: Endpoint
atomic_guid: []
confidence: 40
drilldown_search: []
impact: 30
message: A process $process_name$ with a long commandline $cmd_line$ executed in
host $dest_device_id$
@@ -30,9 +30,7 @@ tags:
analytic_story:
- Insider Threat
asset_type: Endpoint
atomic_guid: []
confidence: 30
drilldown_search: []
impact: 20
message: Multiple interactive logins detected on $device$
mitre_attack_id:
@@ -35,9 +35,7 @@ tags:
- NOBELIUM Group
- Insider Threat
asset_type: Endpoint
atomic_guid: []
confidence: 60
drilldown_search: []
impact: 70
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading
@@ -37,9 +37,7 @@ tags:
- XMRig
- Ransomware
asset_type: Endpoint
atomic_guid: []
confidence: 60
drilldown_search: []
impact: 60
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service.
@@ -39,9 +39,7 @@ tags:
- XMRig
- Ransomware
asset_type: Endpoint
atomic_guid: []
confidence: 60
drilldown_search: []
impact: 60
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service.
@@ -35,9 +35,7 @@ tags:
analytic_story:
- Credential Dumping
asset_type: Endpoint
atomic_guid: []
confidence: 90
drilldown_search: []
impact: 70
message: An attempt to save registry keys storing credentials has been performed
on $dest_device_id$ by $dest_user_id$ via process $process_name$.
@@ -34,9 +34,7 @@ tags:
- Ransomware
- Information Sabotage
asset_type: Endpoint
atomic_guid: []
confidence: 80
drilldown_search: []
impact: 100
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability
@@ -78,7 +76,5 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
update_timestamp: true
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-security_bcdedit_wbadmin.log
source: WinEventLog:Security
@@ -33,9 +33,7 @@ tags:
- Ransomware
- Information Sabotage
asset_type: Endpoint
atomic_guid: []
confidence: 100
drilldown_search: []
impact: 90
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting to clear the unallocated sectors
@@ -82,6 +80,5 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.004/cipher/security.log
source: WinEventLog:Security
@@ -37,9 +37,7 @@ tags:
- XMRig
- Ransomware
asset_type: Endpoint
atomic_guid: []
confidence: 70
drilldown_search: []
impact: 70
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user
@@ -35,9 +35,7 @@ tags:
- XMRig
- Information Sabotage
asset_type: Endpoint
atomic_guid: []
confidence: 70
drilldown_search: []
impact: 50
message: A cacls process $process_name$ with commandline $cmd_line$ try to deny
a permission of a file or directory in host $dest_device_id$
@@ -33,9 +33,7 @@ tags:
analytic_story:
- Credential Dumping
asset_type: Endpoint
atomic_guid: []
confidence: 20
drilldown_search: []
impact: 70
message: Kerberoasting malware is potentially applying stolen credentials. Operation
is performed at the device $dest_device_id$, by the account $dest_user_id$ via
@@ -40,9 +40,7 @@ tags:
- Suspicious Command-Line Executions
- Insider Threat
asset_type: Endpoint
atomic_guid: []
confidence: 50
drilldown_search: []
impact: 70
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event
@@ -82,6 +80,5 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-security.log
source: WinEventLog:Security
@@ -46,9 +46,7 @@ tags:
- Ransomware
- Insider Threat
asset_type: Endpoint
atomic_guid: []
confidence: 70
drilldown_search: []
impact: 50
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a
@@ -90,6 +88,5 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-security.log
source: WinEventLog:Security
@@ -34,9 +34,7 @@ tags:
analytic_story:
- IcedID
asset_type: Endpoint
atomic_guid: []
confidence: 70
drilldown_search: []
impact: 70
message: Modified/added/deleted registry entry $registry_path$ in $dest$
mitre_attack_id:
@@ -65,9 +63,3 @@ tags:
- Exploitation
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -37,9 +37,7 @@ tags:
- XMRig
- Ransomware
asset_type: Endpoint
atomic_guid: []
confidence: 70
drilldown_search: []
impact: 70
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts.
@@ -42,9 +42,7 @@ tags:
- Data Exfiltration
- Command and Control
asset_type: Endpoint
atomic_guid: []
confidence: 80
drilldown_search: []
impact: 90
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related
@@ -86,6 +84,5 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-security.log
source: WinEventLog:Security
@@ -28,9 +28,7 @@ tags:
analytic_story:
- Insider Threat
asset_type: Endpoint
atomic_guid: []
confidence: 80
drilldown_search: []
impact: 90
message: High number of files copied
mitre_attack_id:

Some files were not shown because too many files have changed in this diff Show More