diff --git a/baselines/baseline_of_blocked_outbound_traffic_from_aws.yml b/baselines/baseline_of_blocked_outbound_traffic_from_aws.yml index c8a73d3a63..bb569450bc 100644 --- a/baselines/baseline_of_blocked_outbound_traffic_from_aws.yml +++ b/baselines/baseline_of_blocked_outbound_traffic_from_aws.yml @@ -28,8 +28,6 @@ tags: - AWS Network ACL Activity - Suspicious AWS Traffic - Command and Control - deployments: - - Daily Cache Updates detections: - Detect Spike in blocked Outbound Traffic from your AWS product: diff --git a/baselines/baseline_of_cloud_infrastructure_api_calls_per_user.yml b/baselines/baseline_of_cloud_infrastructure_api_calls_per_user.yml index 6f573ad0f8..00c8592839 100644 --- a/baselines/baseline_of_cloud_infrastructure_api_calls_per_user.yml +++ b/baselines/baseline_of_cloud_infrastructure_api_calls_per_user.yml @@ -34,8 +34,6 @@ references: [] tags: analytic_story: - Suspicious Cloud User Activities - deployments: - - Weekly Model Rebuild 90 Day Lookback detections: - Abnormally High Number Of Cloud Infrastructure API Calls product: @@ -47,3 +45,9 @@ tags: - All_Changes.user - All_Changes.status security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/baseline_of_cloud_instances_destroyed.yml b/baselines/baseline_of_cloud_instances_destroyed.yml index 849525c2bb..998df09902 100644 --- a/baselines/baseline_of_cloud_instances_destroyed.yml +++ b/baselines/baseline_of_cloud_instances_destroyed.yml @@ -37,8 +37,6 @@ tags: analytic_story: - Suspicious Cloud Instance Activities - Cloud Cryptomining - deployments: - - Weekly Model Rebuild 90 Day Lookback detections: - Abnormally High Number Of Cloud Instances Destroyed product: @@ -51,3 +49,9 @@ tags: - All_Changes.status - All_Changes.object_category security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/baseline_of_cloud_instances_launched.yml b/baselines/baseline_of_cloud_instances_launched.yml index 3e52c6b7ed..811b22f7cf 100644 --- a/baselines/baseline_of_cloud_instances_launched.yml +++ b/baselines/baseline_of_cloud_instances_launched.yml @@ -37,8 +37,6 @@ tags: analytic_story: - Cloud Cryptomining - Suspicious Cloud Instance Activities - deployments: - - Weekly Model Rebuild 90 Day Lookback detections: - Abnormally High Number Of Cloud Instances Launched product: @@ -51,3 +49,9 @@ tags: - All_Changes.status - All_Changes.object_category security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/baseline_of_cloud_security_group_api_calls_per_user.yml b/baselines/baseline_of_cloud_security_group_api_calls_per_user.yml index 235ec8557c..9f8e1bad53 100644 --- a/baselines/baseline_of_cloud_security_group_api_calls_per_user.yml +++ b/baselines/baseline_of_cloud_security_group_api_calls_per_user.yml @@ -33,8 +33,6 @@ references: [] tags: analytic_story: - Suspicious Cloud User Activities - deployments: - - Weekly Model Rebuild 90 Day Lookback detections: - Abnormally High Number Of Cloud Security Group API Calls product: @@ -47,3 +45,9 @@ tags: - All_Changes.status - All_Changes.object_category security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/baseline_of_command_line_length___mltk.yml b/baselines/baseline_of_command_line_length___mltk.yml index be1b32c2ca..ac7c7b3acb 100644 --- a/baselines/baseline_of_command_line_length___mltk.yml +++ b/baselines/baseline_of_command_line_length___mltk.yml @@ -34,8 +34,6 @@ tags: - Suspicious Command-Line Executions - Suspicious MSHTA Activity - Unusual Processes - deployments: - - Daily Cache Updates detections: - Detect Prohibited Applications Spawning cmd.exe - Unusually Long Command Line - MLTK @@ -50,3 +48,4 @@ tags: - Processes.process_name - Processes.process security_domain: endpoint + diff --git a/baselines/baseline_of_dns_query_length___mltk.yml b/baselines/baseline_of_dns_query_length___mltk.yml index d62c26dd4e..04daab4d50 100644 --- a/baselines/baseline_of_dns_query_length___mltk.yml +++ b/baselines/baseline_of_dns_query_length___mltk.yml @@ -30,8 +30,6 @@ tags: - Hidden Cobra Malware - Suspicious DNS Traffic - Command and Control - deployments: - - Daily Cache Updates detections: - DNS Query Length Outliers - MLTK product: diff --git a/baselines/baseline_of_network_acl_activity_by_arn.yml b/baselines/baseline_of_network_acl_activity_by_arn.yml index 4df783bff3..b3b816c5d4 100644 --- a/baselines/baseline_of_network_acl_activity_by_arn.yml +++ b/baselines/baseline_of_network_acl_activity_by_arn.yml @@ -23,8 +23,6 @@ references: [] tags: analytic_story: - AWS Network ACL Activity - deployments: - - Daily Cache Updates detections: - Detect Spike in Network ACL Activity product: diff --git a/baselines/baseline_of_s3_bucket_deletion_activity_by_arn.yml b/baselines/baseline_of_s3_bucket_deletion_activity_by_arn.yml index e830524f77..a48856dc77 100644 --- a/baselines/baseline_of_s3_bucket_deletion_activity_by_arn.yml +++ b/baselines/baseline_of_s3_bucket_deletion_activity_by_arn.yml @@ -22,8 +22,6 @@ references: [] tags: analytic_story: - Suspicious AWS S3 Activities - deployments: - - Daily Cache Updates detections: - Detect Spike in S3 Bucket deletion product: diff --git a/baselines/baseline_of_security_group_activity_by_arn.yml b/baselines/baseline_of_security_group_activity_by_arn.yml index 850a043ea0..43cabcd1cb 100644 --- a/baselines/baseline_of_security_group_activity_by_arn.yml +++ b/baselines/baseline_of_security_group_activity_by_arn.yml @@ -23,8 +23,6 @@ references: [] tags: analytic_story: - AWS User Monitoring - deployments: - - Daily Cache Updates detections: - Detect Spike in Security Group Activity product: diff --git a/baselines/baseline_of_smb_traffic___mltk.yml b/baselines/baseline_of_smb_traffic___mltk.yml index c4849029ba..7ea60c16d6 100644 --- a/baselines/baseline_of_smb_traffic___mltk.yml +++ b/baselines/baseline_of_smb_traffic___mltk.yml @@ -40,8 +40,6 @@ tags: - Hidden Cobra Malware - Netsh Abuse - Ransomware - deployments: - - Daily Cache Updates detections: - Processes launching netsh - SMB Traffic Spike - MLTK diff --git a/baselines/count_of_assets_by_category.yml b/baselines/count_of_assets_by_category.yml index 385aa3bb81..2e3ff8569a 100644 --- a/baselines/count_of_assets_by_category.yml +++ b/baselines/count_of_assets_by_category.yml @@ -19,8 +19,6 @@ references: [] tags: analytic_story: - Asset Tracking - deployments: - - Daily Cache Updates detections: - Detect Unauthorized Assets by MAC address product: diff --git a/baselines/count_of_unique_ips_connecting_to_ports.yml b/baselines/count_of_unique_ips_connecting_to_ports.yml index 2e23bd688e..10283d24ef 100644 --- a/baselines/count_of_unique_ips_connecting_to_ports.yml +++ b/baselines/count_of_unique_ips_connecting_to_ports.yml @@ -20,8 +20,6 @@ tags: - Prohibited Traffic Allowed or Protocol Mismatch - Ransomware - Command and Control - deployments: - - Daily Cache Updates detections: - Prohibited Network Traffic Allowed product: diff --git a/baselines/create_a_list_of_approved_aws_service_accounts.yml b/baselines/create_a_list_of_approved_aws_service_accounts.yml index 3e06e9c5bb..b60bf256a4 100644 --- a/baselines/create_a_list_of_approved_aws_service_accounts.yml +++ b/baselines/create_a_list_of_approved_aws_service_accounts.yml @@ -21,8 +21,6 @@ references: [] tags: analytic_story: - AWS User Monitoring - deployments: - - Daily Cache Updates detections: - Detect AWS API Activities From Unapproved Accounts product: diff --git a/baselines/deprecated/add_prohibited_processes_to_enterprise_security.yml b/baselines/deprecated/add_prohibited_processes_to_enterprise_security.yml index 2b99cc4fe8..662b49bef6 100644 --- a/baselines/deprecated/add_prohibited_processes_to_enterprise_security.yml +++ b/baselines/deprecated/add_prohibited_processes_to_enterprise_security.yml @@ -21,8 +21,6 @@ tags: - Monitor for Unauthorized Software - SamSam Ransomware asset_type: Endpoint - deployments: - - Daily Cache Updates detections: - Prohibited Software On Endpoint product: diff --git a/baselines/deprecated/baseline_of_api_calls_per_user_arn.yml b/baselines/deprecated/baseline_of_api_calls_per_user_arn.yml index c27e8beefb..02874c9c4a 100644 --- a/baselines/deprecated/baseline_of_api_calls_per_user_arn.yml +++ b/baselines/deprecated/baseline_of_api_calls_per_user_arn.yml @@ -22,8 +22,6 @@ references: [] tags: analytic_story: - AWS User Monitoring - deployments: - - Daily Cache Updates detections: - Detect Spike in AWS API Activity product: diff --git a/baselines/deprecated/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml b/baselines/deprecated/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml index 0b94c6e35a..0df12d399b 100644 --- a/baselines/deprecated/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml +++ b/baselines/deprecated/baseline_of_excessive_aws_instances_launched_by_user___mltk.yml @@ -33,8 +33,6 @@ tags: analytic_story: - AWS Cryptomining - Suspicious AWS EC2 Activities - deployments: - - Daily Cache Updates detections: - Abnormally High AWS Instances Launched by User - MLTK product: diff --git a/baselines/deprecated/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml b/baselines/deprecated/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml index bcbcff72a3..4369184ddb 100644 --- a/baselines/deprecated/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml +++ b/baselines/deprecated/baseline_of_excessive_aws_instances_terminated_by_user___mltk.yml @@ -33,8 +33,6 @@ references: [] tags: analytic_story: - Suspicious AWS EC2 Activities - deployments: - - Daily Cache Updates detections: - Abnormally High AWS Instances Terminated by User - MLTK product: diff --git a/baselines/deprecated/previously_seen_api_call_per_user_roles_in_cloudtrail.yml b/baselines/deprecated/previously_seen_api_call_per_user_roles_in_cloudtrail.yml index 9568800eab..cfb61398a8 100644 --- a/baselines/deprecated/previously_seen_api_call_per_user_roles_in_cloudtrail.yml +++ b/baselines/deprecated/previously_seen_api_call_per_user_roles_in_cloudtrail.yml @@ -22,8 +22,6 @@ references: [] tags: analytic_story: - AWS User Monitoring - deployments: - - Daily Cache Updates detections: - Detect new API calls from user roles product: diff --git a/baselines/deprecated/previously_seen_aws_provisioning_activity_sources.yml b/baselines/deprecated/previously_seen_aws_provisioning_activity_sources.yml index 4e69e66ab7..1b62095d7d 100644 --- a/baselines/deprecated/previously_seen_aws_provisioning_activity_sources.yml +++ b/baselines/deprecated/previously_seen_aws_provisioning_activity_sources.yml @@ -20,8 +20,6 @@ references: [] tags: analytic_story: - AWS Suspicious Provisioning Activities - deployments: - - Daily Cache Updates detections: - AWS Cloud Provisioning From Previously Unseen IP Address - AWS Cloud Provisioning From Previously Unseen City diff --git a/baselines/deprecated/previously_seen_ec2_amis.yml b/baselines/deprecated/previously_seen_ec2_amis.yml index 859e17dfe2..2d4db54842 100644 --- a/baselines/deprecated/previously_seen_ec2_amis.yml +++ b/baselines/deprecated/previously_seen_ec2_amis.yml @@ -18,8 +18,6 @@ references: [] tags: analytic_story: - AWS Cryptomining - deployments: - - Daily Cache Updates detections: - EC2 Instance Started With Previously Unseen AMI product: diff --git a/baselines/deprecated/previously_seen_ec2_instance_types.yml b/baselines/deprecated/previously_seen_ec2_instance_types.yml index d7b4b41ac2..07f828a99f 100644 --- a/baselines/deprecated/previously_seen_ec2_instance_types.yml +++ b/baselines/deprecated/previously_seen_ec2_instance_types.yml @@ -18,8 +18,6 @@ references: [] tags: analytic_story: - AWS Cryptomining - deployments: - - Daily Cache Updates detections: - EC2 Instance Started With Previously Unseen Instance Type product: diff --git a/baselines/deprecated/previously_seen_ec2_launches_by_user.yml b/baselines/deprecated/previously_seen_ec2_launches_by_user.yml index fc7cde6810..8593df9832 100644 --- a/baselines/deprecated/previously_seen_ec2_launches_by_user.yml +++ b/baselines/deprecated/previously_seen_ec2_launches_by_user.yml @@ -19,8 +19,6 @@ tags: analytic_story: - AWS Cryptomining - Suspicious AWS EC2 Activities - deployments: - - Daily Cache Updates detections: - EC2 Instance Started With Previously Unseen User product: diff --git a/baselines/deprecated/previously_seen_users_in_cloudtrail.yml b/baselines/deprecated/previously_seen_users_in_cloudtrail.yml index 60681d4489..c10e6be865 100644 --- a/baselines/deprecated/previously_seen_users_in_cloudtrail.yml +++ b/baselines/deprecated/previously_seen_users_in_cloudtrail.yml @@ -23,8 +23,6 @@ references: [] tags: analytic_story: - Suspicious AWS Login Activities - deployments: - - Daily Cache Updates detections: - Detect AWS Console Login by User from New Country - Detect AWS Console Login by User from New Region diff --git a/baselines/deprecated/update_previously_seen_users_in_cloudtrail.yml b/baselines/deprecated/update_previously_seen_users_in_cloudtrail.yml index e9133f2cac..f7672203b6 100644 --- a/baselines/deprecated/update_previously_seen_users_in_cloudtrail.yml +++ b/baselines/deprecated/update_previously_seen_users_in_cloudtrail.yml @@ -25,8 +25,6 @@ references: [] tags: analytic_story: - Suspicious AWS Login Activities - deployments: - - Daily Cache Updates detections: - Detect AWS Console Login by User from New Country - Detect AWS Console Login by User from New Region diff --git a/baselines/discover_dns_records.yml b/baselines/discover_dns_records.yml index bfc22c151e..ea2d436f9d 100644 --- a/baselines/discover_dns_records.yml +++ b/baselines/discover_dns_records.yml @@ -27,8 +27,6 @@ references: [] tags: analytic_story: - DNS Hijacking - deployments: - - Daily Cache Updates detections: - DNS record changed product: diff --git a/baselines/dnstwist_domain_names.yml b/baselines/dnstwist_domain_names.yml index 95b3b54dbc..56d143e729 100644 --- a/baselines/dnstwist_domain_names.yml +++ b/baselines/dnstwist_domain_names.yml @@ -20,8 +20,6 @@ tags: - Brand Monitoring - Suspicious Emails asset_type: Endpoint - deployments: - - Daily Cache Updates detections: - Monitor Email For Brand Abuse - Monitor DNS For Brand Abuse diff --git a/baselines/identify_systems_creating_remote_desktop_traffic.yml b/baselines/identify_systems_creating_remote_desktop_traffic.yml index ece8d2d0d0..6ed4f0c880 100644 --- a/baselines/identify_systems_creating_remote_desktop_traffic.yml +++ b/baselines/identify_systems_creating_remote_desktop_traffic.yml @@ -21,8 +21,6 @@ tags: - Ryuk Ransomware - Hidden Cobra Malware - Active Directory Lateral Movement - deployments: - - Daily Cache Updates detections: - Remote Desktop Network Traffic product: diff --git a/baselines/identify_systems_receiving_remote_desktop_traffic.yml b/baselines/identify_systems_receiving_remote_desktop_traffic.yml index ad0dafe2b9..82ce7d8312 100644 --- a/baselines/identify_systems_receiving_remote_desktop_traffic.yml +++ b/baselines/identify_systems_receiving_remote_desktop_traffic.yml @@ -22,8 +22,6 @@ tags: - Ryuk Ransomware - Hidden Cobra Malware - Active Directory Lateral Movement - deployments: - - Daily Cache Updates detections: - Remote Desktop Network Traffic product: diff --git a/baselines/identify_systems_using_remote_desktop.yml b/baselines/identify_systems_using_remote_desktop.yml index b4ac09f901..aad6d64306 100644 --- a/baselines/identify_systems_using_remote_desktop.yml +++ b/baselines/identify_systems_using_remote_desktop.yml @@ -21,8 +21,6 @@ tags: - Ryuk Ransomware - Hidden Cobra Malware - Active Directory Lateral Movement - deployments: - - Daily Cache Updates detections: - Remote Desktop Network Traffic product: diff --git a/baselines/monitor_successful_backups.yml b/baselines/monitor_successful_backups.yml index cce8e80196..469a6b3876 100644 --- a/baselines/monitor_successful_backups.yml +++ b/baselines/monitor_successful_backups.yml @@ -18,8 +18,6 @@ references: [] tags: analytic_story: - Monitor Backup Solution - deployments: - - Daily Cache Updates detections: - Unsuccessful Netbackup backups product: diff --git a/baselines/monitor_unsuccessful_backups.yml b/baselines/monitor_unsuccessful_backups.yml index 36287b86fc..08267228d4 100644 --- a/baselines/monitor_unsuccessful_backups.yml +++ b/baselines/monitor_unsuccessful_backups.yml @@ -17,8 +17,6 @@ references: [] tags: analytic_story: - Monitor Backup Solution - deployments: - - Daily Cache Updates detections: - Unsuccessful Netbackup backups product: diff --git a/baselines/previously_seen_aws_cross_account_activity.yml b/baselines/previously_seen_aws_cross_account_activity.yml index 44fcaee040..9cac5a7a27 100644 --- a/baselines/previously_seen_aws_cross_account_activity.yml +++ b/baselines/previously_seen_aws_cross_account_activity.yml @@ -22,8 +22,6 @@ references: [] tags: analytic_story: - AWS Cross Account Activity - deployments: - - Daily Cache Updates detections: - AWS Cross Account Activity From Previously Unseen Account product: diff --git a/baselines/previously_seen_aws_cross_account_activity___initial.yml b/baselines/previously_seen_aws_cross_account_activity___initial.yml index d638bb374d..f615b6c25e 100644 --- a/baselines/previously_seen_aws_cross_account_activity___initial.yml +++ b/baselines/previously_seen_aws_cross_account_activity___initial.yml @@ -26,8 +26,6 @@ references: [] tags: analytic_story: - Suspicious Cloud Authentication Activities - deployments: - - 90 Day Baseline detections: - AWS Cross Account Activity From Previously Unseen Account product: @@ -42,3 +40,9 @@ tags: - Authentication.src - Authentication.user_role security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_aws_cross_account_activity___update.yml b/baselines/previously_seen_aws_cross_account_activity___update.yml index 7f39a483ed..dfc483e769 100644 --- a/baselines/previously_seen_aws_cross_account_activity___update.yml +++ b/baselines/previously_seen_aws_cross_account_activity___update.yml @@ -27,8 +27,6 @@ references: [] tags: analytic_story: - Suspicious Cloud Authentication Activities - deployments: - - Daily Cache Updates detections: - AWS Cross Account Activity From Previously Unseen Account product: diff --git a/baselines/previously_seen_aws_regions.yml b/baselines/previously_seen_aws_regions.yml index 2259bcab51..39109032a1 100644 --- a/baselines/previously_seen_aws_regions.yml +++ b/baselines/previously_seen_aws_regions.yml @@ -20,8 +20,6 @@ tags: analytic_story: - AWS Cryptomining - Suspicious AWS EC2 Activities - deployments: - - Daily Cache Updates detections: - EC2 Instance Started In Previously Unseen Region product: diff --git a/baselines/previously_seen_cloud_api_calls_per_user_role___initial.yml b/baselines/previously_seen_cloud_api_calls_per_user_role___initial.yml index db887a270e..1625cba2d3 100644 --- a/baselines/previously_seen_cloud_api_calls_per_user_role___initial.yml +++ b/baselines/previously_seen_cloud_api_calls_per_user_role___initial.yml @@ -22,8 +22,6 @@ references: [] tags: analytic_story: - Suspicious Cloud User Activities - deployments: - - 90 Day Baseline detections: - Cloud API Calls From Previously Unseen User Roles product: @@ -37,3 +35,9 @@ tags: - All_Changes.user - All_Changes.command security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_cloud_api_calls_per_user_role___update.yml b/baselines/previously_seen_cloud_api_calls_per_user_role___update.yml index 5ddbe2e8f4..5171f6a2fe 100644 --- a/baselines/previously_seen_cloud_api_calls_per_user_role___update.yml +++ b/baselines/previously_seen_cloud_api_calls_per_user_role___update.yml @@ -24,8 +24,6 @@ references: [] tags: analytic_story: - Suspicious Cloud User Activities - deployments: - - Daily Cache Updates detections: - Cloud API Calls From Previously Unseen User Roles product: diff --git a/baselines/previously_seen_cloud_compute_creations_by_user___initial.yml b/baselines/previously_seen_cloud_compute_creations_by_user___initial.yml index db0f614cdb..2be9d42b51 100644 --- a/baselines/previously_seen_cloud_compute_creations_by_user___initial.yml +++ b/baselines/previously_seen_cloud_compute_creations_by_user___initial.yml @@ -19,8 +19,6 @@ references: [] tags: analytic_story: - Cloud Cryptomining - deployments: - - Hourly Cache Updates detections: - Cloud Compute Instance Created By Previously Unseen User product: @@ -33,3 +31,9 @@ tags: - All_Changes.object_category - All_Changes.user security_domain: network +deployment: + scheduling: + cron_schedule: 55 * * * * + earliest_time: -70m@m + latest_time: -10m@m + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_cloud_compute_creations_by_user___update.yml b/baselines/previously_seen_cloud_compute_creations_by_user___update.yml index 0ed37e5ef6..4896094581 100644 --- a/baselines/previously_seen_cloud_compute_creations_by_user___update.yml +++ b/baselines/previously_seen_cloud_compute_creations_by_user___update.yml @@ -22,8 +22,6 @@ references: [] tags: analytic_story: - Cloud Cryptomining - deployments: - - Daily Cache Updates detections: - Cloud Compute Instance Created By Previously Unseen User product: diff --git a/baselines/previously_seen_cloud_compute_images___initial.yml b/baselines/previously_seen_cloud_compute_images___initial.yml index 52816b728c..1e8db27323 100644 --- a/baselines/previously_seen_cloud_compute_images___initial.yml +++ b/baselines/previously_seen_cloud_compute_images___initial.yml @@ -21,8 +21,6 @@ references: [] tags: analytic_story: - Cloud Cryptomining - deployments: - - 90 Day Baseline detections: - Cloud Compute Instance Created With Previously Unseen Image product: @@ -34,3 +32,9 @@ tags: - All_Changes.action - All_Changes.Instance_Changes.image_id security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_cloud_compute_images___update.yml b/baselines/previously_seen_cloud_compute_images___update.yml index a30c726f8a..cefb0afda5 100644 --- a/baselines/previously_seen_cloud_compute_images___update.yml +++ b/baselines/previously_seen_cloud_compute_images___update.yml @@ -22,8 +22,6 @@ references: [] tags: analytic_story: - Cloud Cryptomining - deployments: - - Daily Cache Updates detections: - Cloud Compute Instance Created With Previously Unseen Image product: diff --git a/baselines/previously_seen_cloud_compute_instance_types___initial.yml b/baselines/previously_seen_cloud_compute_instance_types___initial.yml index 1901b8974a..4dd9476dbd 100644 --- a/baselines/previously_seen_cloud_compute_instance_types___initial.yml +++ b/baselines/previously_seen_cloud_compute_instance_types___initial.yml @@ -20,8 +20,6 @@ references: [] tags: analytic_story: - Cloud Cryptomining - deployments: - - 90 Day Baseline detections: - Cloud Compute Instance Created With Previously Unseen Instance Type product: @@ -33,3 +31,9 @@ tags: - All_Changes.action - All_Changes.Instance_Changes.instance_type security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_cloud_compute_instance_types___update.yml b/baselines/previously_seen_cloud_compute_instance_types___update.yml index daa987c47f..7a6540e378 100644 --- a/baselines/previously_seen_cloud_compute_instance_types___update.yml +++ b/baselines/previously_seen_cloud_compute_instance_types___update.yml @@ -22,8 +22,6 @@ references: [] tags: analytic_story: - Cloud Cryptomining - deployments: - - Daily Cache Updates detections: - Cloud Compute Instance Created With Previously Unseen Instance Type product: diff --git a/baselines/previously_seen_cloud_instance_modifications_by_user___initial.yml b/baselines/previously_seen_cloud_instance_modifications_by_user___initial.yml index b03acd9d3e..48b1d73252 100644 --- a/baselines/previously_seen_cloud_instance_modifications_by_user___initial.yml +++ b/baselines/previously_seen_cloud_instance_modifications_by_user___initial.yml @@ -20,8 +20,6 @@ references: [] tags: analytic_story: - Suspicious Cloud Instance Activities - deployments: - - 90 Day Baseline detections: - Cloud Instance Modified By Previously Unseen User product: @@ -35,3 +33,9 @@ tags: - All_Changes.status - All_Changes.user security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_cloud_instance_modifications_by_user___update.yml b/baselines/previously_seen_cloud_instance_modifications_by_user___update.yml index c95a1e7a7b..b51943b350 100644 --- a/baselines/previously_seen_cloud_instance_modifications_by_user___update.yml +++ b/baselines/previously_seen_cloud_instance_modifications_by_user___update.yml @@ -24,8 +24,6 @@ references: [] tags: analytic_story: - Suspicious Cloud Instance Activities - deployments: - - Daily Cache Updates detections: - Cloud Instance Modified By Previously Unseen User product: diff --git a/baselines/previously_seen_cloud_provisioning_activity_sources___initial.yml b/baselines/previously_seen_cloud_provisioning_activity_sources___initial.yml index f103ce58ce..22542e4d13 100644 --- a/baselines/previously_seen_cloud_provisioning_activity_sources___initial.yml +++ b/baselines/previously_seen_cloud_provisioning_activity_sources___initial.yml @@ -24,8 +24,6 @@ references: [] tags: analytic_story: - Suspicious Cloud Provisioning Activities - deployments: - - 90 Day Baseline detections: - Cloud Provisioning Activity From Previously Unseen IP Address - Cloud Provisioning Activity From Previously Unseen City @@ -41,3 +39,9 @@ tags: - All_Changes.src - All_Changes.status security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_cloud_provisioning_activity_sources___update.yml b/baselines/previously_seen_cloud_provisioning_activity_sources___update.yml index ce01a7c493..104740b59d 100644 --- a/baselines/previously_seen_cloud_provisioning_activity_sources___update.yml +++ b/baselines/previously_seen_cloud_provisioning_activity_sources___update.yml @@ -29,8 +29,6 @@ references: [] tags: analytic_story: - Suspicious Cloud Provisioning Activities - deployments: - - Daily Cache Updates detections: - Cloud Provisioning Activity From Previously Unseen IP Address - Cloud Provisioning Activity From Previously Unseen City diff --git a/baselines/previously_seen_cloud_regions___initial.yml b/baselines/previously_seen_cloud_regions___initial.yml index 1c710097d9..8c83ae3cb2 100644 --- a/baselines/previously_seen_cloud_regions___initial.yml +++ b/baselines/previously_seen_cloud_regions___initial.yml @@ -22,8 +22,6 @@ references: [] tags: analytic_story: - Cloud Cryptomining - deployments: - - 90 Day Baseline detections: - Cloud Compute Instance Created In Previously Unused Region product: @@ -35,3 +33,9 @@ tags: - All_Changes.action - All_Changes.vendor_region security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_cloud_regions___update.yml b/baselines/previously_seen_cloud_regions___update.yml index f00ff4dc49..d51eeb25b1 100644 --- a/baselines/previously_seen_cloud_regions___update.yml +++ b/baselines/previously_seen_cloud_regions___update.yml @@ -25,8 +25,6 @@ references: [] tags: analytic_story: - Cloud Cryptomining - deployments: - - Daily Cache Updates detections: - Cloud Compute Instance Created In Previously Unused Region product: diff --git a/baselines/previously_seen_command_line_arguments.yml b/baselines/previously_seen_command_line_arguments.yml index f23a273e6c..6f29d709d1 100644 --- a/baselines/previously_seen_command_line_arguments.yml +++ b/baselines/previously_seen_command_line_arguments.yml @@ -30,8 +30,6 @@ tags: - Suspicious Command-Line Executions - Suspicious MSHTA Activity - IcedID - deployments: - - Daily Cache Updates detections: - First time seen command line argument product: diff --git a/baselines/previously_seen_ec2_modifications_by_user.yml b/baselines/previously_seen_ec2_modifications_by_user.yml index 12d35bb7e7..86e14cc330 100644 --- a/baselines/previously_seen_ec2_modifications_by_user.yml +++ b/baselines/previously_seen_ec2_modifications_by_user.yml @@ -18,8 +18,6 @@ references: [] tags: analytic_story: - Unusual AWS EC2 Modifications - deployments: - - Daily Cache Updates detections: - EC2 Instance Modified With Previously Unseen User product: diff --git a/baselines/previously_seen_running_windows_services___initial.yml b/baselines/previously_seen_running_windows_services___initial.yml index 21c9c2e00b..2a4504f319 100644 --- a/baselines/previously_seen_running_windows_services___initial.yml +++ b/baselines/previously_seen_running_windows_services___initial.yml @@ -20,8 +20,6 @@ tags: - Orangeworm Attack Group - Windows Service Abuse - NOBELIUM Group - deployments: - - 90 Day Baseline detections: - First Time Seen Running Windows Service product: @@ -33,3 +31,9 @@ tags: - EventCode - Message security_domain: endpoint +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_running_windows_services___update.yml b/baselines/previously_seen_running_windows_services___update.yml index 2ba9a0d4f4..c67fa5c292 100644 --- a/baselines/previously_seen_running_windows_services___update.yml +++ b/baselines/previously_seen_running_windows_services___update.yml @@ -25,8 +25,6 @@ tags: - Orangeworm Attack Group - Windows Service Abuse - NOBELIUM Group - deployments: - - Hourly Cache Updates detections: - First Time Seen Running Windows Service product: @@ -38,3 +36,9 @@ tags: - EventCode - Message security_domain: endpoint +deployment: + scheduling: + cron_schedule: 55 * * * * + earliest_time: -70m@m + latest_time: -10m@m + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_s3_bucket_access_by_remote_ip.yml b/baselines/previously_seen_s3_bucket_access_by_remote_ip.yml index 7d6bcad9b4..afff188900 100644 --- a/baselines/previously_seen_s3_bucket_access_by_remote_ip.yml +++ b/baselines/previously_seen_s3_bucket_access_by_remote_ip.yml @@ -21,8 +21,6 @@ references: [] tags: analytic_story: - Suspicious AWS S3 Activities - deployments: - - Daily Cache Updates detections: - Detect S3 access from a new IP product: diff --git a/baselines/previously_seen_users_in_cloudtrail___initial.yml b/baselines/previously_seen_users_in_cloudtrail___initial.yml index 3e428d1d28..8982ce24cb 100644 --- a/baselines/previously_seen_users_in_cloudtrail___initial.yml +++ b/baselines/previously_seen_users_in_cloudtrail___initial.yml @@ -25,8 +25,6 @@ references: [] tags: analytic_story: - Suspicious Cloud Authentication Activities - deployments: - - 90 Day Baseline detections: - Detect AWS Console Login by User from New Country - Detect AWS Console Login by User from New Region @@ -42,3 +40,9 @@ tags: - Authentication.user - Authentication.src security_domain: network +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_users_in_cloudtrail___update.yml b/baselines/previously_seen_users_in_cloudtrail___update.yml index 406b44379a..60e463be04 100644 --- a/baselines/previously_seen_users_in_cloudtrail___update.yml +++ b/baselines/previously_seen_users_in_cloudtrail___update.yml @@ -25,8 +25,6 @@ references: [] tags: analytic_story: - Suspicious Cloud Authentication Activities - deployments: - - Daily Cache Updates detections: - Detect AWS Console Login by User from New Country - Detect AWS Console Login by User from New Region diff --git a/baselines/previously_seen_zoom_child_processes___initial.yml b/baselines/previously_seen_zoom_child_processes___initial.yml index a844bf188e..94e2d11d9a 100644 --- a/baselines/previously_seen_zoom_child_processes___initial.yml +++ b/baselines/previously_seen_zoom_child_processes___initial.yml @@ -22,8 +22,6 @@ references: [] tags: analytic_story: - Suspicious Zoom Child Processes - deployments: - - 90 Day Baseline detections: - First Time Seen Child Process of Zoom product: @@ -36,3 +34,9 @@ tags: - Processes.process_name - Processes.dest security_domain: endpoint +deployment: + scheduling: + cron_schedule: 0 2 * * 0 + earliest_time: -90d@d + latest_time: -1d@d + schedule_window: auto \ No newline at end of file diff --git a/baselines/previously_seen_zoom_child_processes___update.yml b/baselines/previously_seen_zoom_child_processes___update.yml index 2f6d459d7b..dc968e2e40 100644 --- a/baselines/previously_seen_zoom_child_processes___update.yml +++ b/baselines/previously_seen_zoom_child_processes___update.yml @@ -27,8 +27,6 @@ references: [] tags: analytic_story: - Suspicious Zoom Child Processes - deployments: - - Hourly Cache Updates detections: - First Time Seen Child Process of Zoom product: @@ -41,3 +39,9 @@ tags: - Processes.process_name - Processes.dest security_domain: endpoint +deployment: + scheduling: + cron_schedule: 55 * * * * + earliest_time: -70m@m + latest_time: -10m@m + schedule_window: auto \ No newline at end of file diff --git a/baselines/splunk_command_and_scripting_interpreter_risky_spl_mltk_baseline.yml b/baselines/splunk_command_and_scripting_interpreter_risky_spl_mltk_baseline.yml index b9275b04d1..47f8f861b7 100644 --- a/baselines/splunk_command_and_scripting_interpreter_risky_spl_mltk_baseline.yml +++ b/baselines/splunk_command_and_scripting_interpreter_risky_spl_mltk_baseline.yml @@ -77,4 +77,9 @@ tags: security_domain: audit detections: - Splunk Command and Scripting Interpreter Risky SPL MLTK - +deployment: + scheduling: + cron_schedule: 55 * * * * + earliest_time: -70m@m + latest_time: -10m@m + schedule_window: auto diff --git a/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml b/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml index 933e33e7a3..40628afaf9 100644 --- a/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml +++ b/baselines/systems_ready_for_spectre_meltdown_windows_patch.yml @@ -24,8 +24,6 @@ references: [] tags: analytic_story: - Spectre And Meltdown Vulnerabilities - deployments: - - Daily Cache Updates detections: - Spectre and Meltdown Vulnerable Systems product: diff --git a/baselines/windows_updates_install_failures.yml b/baselines/windows_updates_install_failures.yml index 7404faf256..c74fffda1d 100644 --- a/baselines/windows_updates_install_failures.yml +++ b/baselines/windows_updates_install_failures.yml @@ -17,8 +17,6 @@ references: [] tags: analytic_story: - Monitor for Updates - deployments: - - Daily Cache Updates detections: - No Windows Updates in a time frame product: diff --git a/baselines/windows_updates_install_successes.yml b/baselines/windows_updates_install_successes.yml index 3786be1bc5..ea2bd56702 100644 --- a/baselines/windows_updates_install_successes.yml +++ b/baselines/windows_updates_install_successes.yml @@ -17,8 +17,6 @@ references: [] tags: analytic_story: - Monitor for Updates - deployments: - - Daily Cache Updates detections: - No Windows Updates in a time frame product: diff --git a/deployments/00_default_baseline.yml b/deployments/00_default_baseline.yml index 10bdc8d357..b9d5b21ced 100644 --- a/deployments/00_default_baseline.yml +++ b/deployments/00_default_baseline.yml @@ -4,8 +4,8 @@ date: '2021-12-21' author: Patrick Bareiss description: This configuration file applies to all detections of type baseline. scheduling: - cron_schedule: 0 * * * * - earliest_time: -70m@m + cron_schedule: 10 0 * * * + earliest_time: -1450m@m latest_time: -10m@m schedule_window: auto tags: diff --git a/deployments/11_detect_arp_poisoning.yml b/deployments/11_detect_arp_poisoning.yml deleted file mode 100644 index c8ab23b4e9..0000000000 --- a/deployments/11_detect_arp_poisoning.yml +++ /dev/null @@ -1,22 +0,0 @@ -name: Detect ARP Poisoning deployment configuration -id: e1d5b4dc-4cf3-404f-905c-b478bbb20474 -date: '2020-08-14' -author: Mikael Bjerkeland -description: This configuration file applies to the Detect ARP Poisoning detection -scheduling: - cron_schedule: 59 * * * * - earliest_time: -70m@m - latest_time: -10m@m - schedule_window: auto -alert_action: - notable: - rule_description: ARP Poisoning has been detected on interface $src_interface$ - on host $orig_host$. This may be an indication of a MITM attack. - rule_title: ARP Poisoning Detected on $orig_host$ - nes_fields: - - src_interface - - firstTime - - lastTime - - count -tags: - name: Detect ARP Poisoning diff --git a/deployments/12_detect_dhcp_poisoning.yml b/deployments/12_detect_dhcp_poisoning.yml deleted file mode 100644 index eb52b57951..0000000000 --- a/deployments/12_detect_dhcp_poisoning.yml +++ /dev/null @@ -1,23 +0,0 @@ -name: Detect Rogue DHCP Server deployment configuration -id: 6e4e20ac-e719-4ebe-a52d-d672cd451dbb -date: '2020-08-14' -author: Mikael Bjerkeland -description: This configuration file applies to the Detect Rogue DHCP Server detection -scheduling: - cron_schedule: 59 * * * * - earliest_time: -70m@m - latest_time: -10m@m - schedule_window: auto -alert_action: - notable: - rule_description: DHCP Snooping has detected a Rogue DHCP Server on $orig_host$ - from $src_mac$. This may be an indication of a MITM attack. - rule_title: Rogue DHCP Server Detected on $orig_host$ - nes_fields: - - src_mac - - firstTime - - lastTime - - count - - message_type -tags: - name: Detect Rogue DHCP Server diff --git a/deployments/20_baseline_cache_hourly_updates.yml b/deployments/20_baseline_cache_hourly_updates.yml deleted file mode 100644 index a29fb96a55..0000000000 --- a/deployments/20_baseline_cache_hourly_updates.yml +++ /dev/null @@ -1,13 +0,0 @@ -name: Baseline Cache Hourly Updates -id: 1030c701-2acf-4b1a-9970-46c7145caf2d -date: '2020-06-24' -author: Bhavin Patel -description: This configuration file applies to all baselines with tag deployments - Hourly Cache Updates -scheduling: - cron_schedule: 55 * * * * - earliest_time: -70m@m - latest_time: -10m@m - schedule_window: auto -tags: - deployments: Hourly Cache Updates diff --git a/deployments/21_baseline_cache_daily_updates.yml b/deployments/21_baseline_cache_daily_updates.yml deleted file mode 100644 index 66b23dad71..0000000000 --- a/deployments/21_baseline_cache_daily_updates.yml +++ /dev/null @@ -1,13 +0,0 @@ -name: Baseline Cache Daily Updates -id: 9541d6f8-fa58-4d48-bb44-6720e39b7b0d -date: '2020-08-18' -author: David Dorsey -description: This configuration file applies to all baselines with tag deployments - Daily Cache Updates -scheduling: - cron_schedule: 10 0 * * * - earliest_time: -1450m@m - latest_time: -10m@m - schedule_window: auto -tags: - deployments: Daily Cache Updates diff --git a/deployments/30_long_running_baseline_searches.yml b/deployments/30_long_running_baseline_searches.yml deleted file mode 100644 index f8d47d43ad..0000000000 --- a/deployments/30_long_running_baseline_searches.yml +++ /dev/null @@ -1,13 +0,0 @@ -name: 90 Day Baseline Searches -id: 6eac9f8b-a35d-4b64-b57f-e5ecde43be6b -date: '2020-06-24' -author: Bhavin Patel -description: This configuration file applies to all baselines with tag deployments - Long Running Baseline -scheduling: - cron_schedule: 0 1 1 1,4,7,10 * - earliest_time: -90d@d - latest_time: -1d@d - schedule_window: auto -tags: - deployments: 90 Day Baseline diff --git a/deployments/31_weeky_model_rebuild_90_days.yml b/deployments/31_weeky_model_rebuild_90_days.yml deleted file mode 100644 index be6eaae38c..0000000000 --- a/deployments/31_weeky_model_rebuild_90_days.yml +++ /dev/null @@ -1,13 +0,0 @@ -name: Weekly Model Rebuild 90 Day Lookback -id: 4b329568-bcff-49fa-8c85-92e95f0f270d -date: '2020-09-07' -author: David Dorsey -description: This configuration file applies to all baselines with tag deployments - Weekly Model Rebuild 90 Day Lookback -scheduling: - cron_schedule: 0 2 * * 0 - earliest_time: -90d@d - latest_time: -1d@d - schedule_window: auto -tags: - deployments: Weekly Model Rebuild 90 Day Lookback diff --git a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml index a70c414c67..b7df11a0bb 100644 --- a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -63,3 +63,14 @@ tags: - Splunk Cloud risk_score: 90 security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/crowdstrike_falcon.log + source: crowdstrike + sourcetype: crowdstrike:events:sensor diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 1b6e6224a4..3252b1bb42 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -16,7 +16,11 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* - OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows + OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* + OR Registry.registry_path= "*\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Common Startup" + OR Registry.registry_path= *\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler + OR Registry.registry_path= *\\Classes\\htmlfile\\shell\\open\\command + OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" diff --git a/dist/escu/default/analyticstories.conf b/dist/escu/default/analyticstories.conf index a7fd782478..c440e00ea3 100644 --- a/dist/escu/default/analyticstories.conf +++ b/dist/escu/default/analyticstories.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2023-01-03T12:38:50 UTC +# On Date: 2023-01-09T11:37:43 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/dist/escu/default/collections.conf b/dist/escu/default/collections.conf index b3665eff86..240d7c38f4 100644 --- a/dist/escu/default/collections.conf +++ b/dist/escu/default/collections.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2023-01-03T12:38:50 UTC +# On Date: 2023-01-09T11:37:43 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/dist/escu/default/es_investigations.conf b/dist/escu/default/es_investigations.conf index 9d239b5862..aaec61e48d 100644 --- a/dist/escu/default/es_investigations.conf +++ b/dist/escu/default/es_investigations.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2023-01-03T12:38:50 UTC +# On Date: 2023-01-09T11:37:43 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/dist/escu/default/macros.conf b/dist/escu/default/macros.conf index 6163d52260..5469d593d9 100644 --- a/dist/escu/default/macros.conf +++ b/dist/escu/default/macros.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2023-01-03T12:38:50 UTC +# On Date: 2023-01-09T11:37:43 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/dist/escu/default/savedsearches.conf b/dist/escu/default/savedsearches.conf index 57b4c1c93a..5c7b766d5d 100644 --- a/dist/escu/default/savedsearches.conf +++ b/dist/escu/default/savedsearches.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2023-01-03T12:38:50 UTC +# On Date: 2023-01-09T11:37:43 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -283,11 +283,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Suspicious Okta Activity"] -action.risk = 1 -action.risk.param._risk_message = Multple user accounts have failed to authenticate from a single IP. -action.risk.param._risk = [{"risk_object_field": "src_user", "risk_object_type": "user", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -323,11 +318,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Monitor for Updates"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -483,11 +473,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Suspicious Okta Activity", "Okta MFA Exhaustion"] -action.risk = 1 -action.risk.param._risk_message = $src_user$ account has rejected multiple Okta pushes. -action.risk.param._risk = [{"risk_object_field": "src_user", "risk_object_type": "user", "risk_score": 18}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -914,11 +899,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = Potential exploitation of Code Injection via Dashboard PDF generation. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -994,11 +974,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = A risky Splunk command has ran by $user$ and should be reviewed. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 20}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -1074,11 +1049,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = Potential data exfiltration attack using SID query by $user$ -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -1114,11 +1084,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = $splunk_server$ may not be properly validating TLS Certificates -action.risk.param._risk = [{"risk_object_field": "splunk_server", "risk_object_type": "system", "risk_score": 50}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -1286,11 +1251,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = $peer$ downloaded apps from $host$ -action.risk.param._risk = [{"risk_object_field": "host", "risk_object_type": "system", "risk_score": 35}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -1326,11 +1286,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = $splunk_server$ may not be properly validating TLS Certificates -action.risk.param._risk = [{"risk_object_field": "splunk_server", "risk_object_type": "system", "risk_score": 50}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -1366,11 +1321,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = Splunk default issued certificate at $host$ -action.risk.param._risk = [{"risk_object_field": "Hostname", "risk_object_type": "system", "risk_score": 40}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -1406,11 +1356,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = Failed to validate certificate on $host$ -action.risk.param._risk = [{"risk_object_field": "Hostname", "risk_object_type": "system", "risk_score": 40}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -1446,11 +1391,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = Possible exploitation attempt from $clientip$ -action.risk.param._risk = [{"risk_object_field": "clientip", "risk_object_type": "system", "risk_score": 81}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -1486,11 +1426,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = Potential XSS exploitation against radio template by $user$ -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -1526,11 +1461,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = A potential XSS attempt has been detected from $user$ -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -1658,11 +1588,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = Possible XSS exploitation attempt from $clientip$ -action.risk.param._risk = [{"risk_object_field": "clientip", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -1986,11 +1911,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Scanning Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -2026,11 +1946,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Scanning Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -2158,11 +2073,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] action.escu.analytic_story = ["AWS IAM Privilege Escalation"] -action.risk = 1 -action.risk.param._risk_message = User $user_arn$ is attempting to create access keys for $requestParameters.userName$ from this IP $src$ -action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 63}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 63}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -2508,11 +2418,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] action.escu.analytic_story = ["AWS Defense Evasion"] -action.risk = 1 -action.risk.param._risk_message = User $user_arn$ has made potentially risky api calls $eventName$ that could impair AWS security services for account id $aws_account_id$ -action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 42}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 42}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -2548,11 +2453,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] action.escu.analytic_story = ["AWS Defense Evasion"] -action.risk = 1 -action.risk.param._risk_message = User $user_arn$ has created a new rule to on an S3 bucket $bucket_name$ with short expiration days -action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 20}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 20}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -2680,11 +2580,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["AWS Cross Account Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -2720,11 +2615,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["AWS Cross Account Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -2760,11 +2650,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["AWS Cross Account Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -2800,11 +2685,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] action.escu.analytic_story = ["AWS Cross Account Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -2840,11 +2720,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["AWS Cross Account Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -3012,11 +2887,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] action.escu.analytic_story = ["Dev Sec Ops"] -action.risk = 1 -action.risk.param._risk_message = Vulnerabilities with severity high found in repository $repositoryName$ -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 7}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -3304,11 +3174,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] action.escu.analytic_story = ["AWS IAM Privilege Escalation"] -action.risk = 1 -action.risk.param._risk_message = User $user_arn$ has deleted AWS Policies from IP address $src$ by executing the following command $eventName$ -action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 10}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 10}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -3384,11 +3249,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] action.escu.analytic_story = ["AWS IAM Privilege Escalation"] -action.risk = 1 -action.risk.param._risk_message = User $user_arn$ has sucessfully deleted mulitple groups $group_deleted$ from $src$ -action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 5}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 5}, {"risk_object_field": "group_deleted", "risk_object_type": "user", "risk_score": 5}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -3424,11 +3284,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] action.escu.analytic_story = ["Suspicious Cloud User Activities"] -action.risk = 1 -action.risk.param._risk_message = User $user_arn$ is attempting to update the lambda function code of $function_updated$ from this IP $src_ip$ -action.risk.param._risk = [{"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 63}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 63}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -5466,11 +5321,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Suspicious Cloud Authentication Activities", "AWS Identity and Access Management Account Takeover"] -action.risk = 1 -action.risk.param._risk_message = User $user$ is logging into the AWS console for the first time -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 30}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -5506,11 +5356,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Suspicious AWS Login Activities", "Suspicious Cloud Authentication Activities", "AWS Identity and Access Management Account Takeover"] -action.risk = 1 -action.risk.param._risk_message = User $user$ is logging into the AWS console from City $City$ for the first time -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -5546,11 +5391,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Suspicious AWS Login Activities", "Suspicious Cloud Authentication Activities", "AWS Identity and Access Management Account Takeover"] -action.risk = 1 -action.risk.param._risk_message = User $user$ is logging into the AWS console from Country $Country$ for the first time -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -5586,11 +5426,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Suspicious AWS Login Activities", "Suspicious Cloud Authentication Activities", "AWS Identity and Access Management Account Takeover"] -action.risk = 1 -action.risk.param._risk_message = User $user$ is logging into the AWS console from Region $Region$ for the first time -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 36}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -6142,11 +5977,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Scanning Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -6400,11 +6230,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Spearphishing Attachments", "Data Exfiltration"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -6840,11 +6665,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Spearphishing Attachments"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "dest", "threat_object_type": "other"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -6960,11 +6780,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Object Access Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -7944,11 +7759,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Object Access Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -8078,11 +7888,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] action.escu.analytic_story = ["AWS User Monitoring"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -8124,11 +7929,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] action.escu.analytic_story = ["AWS User Monitoring"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -8346,11 +8146,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Amazon Web Services - Cloudtrail"] action.escu.analytic_story = ["Suspicious AWS Login Activities"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -8753,11 +8548,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Credential Dumping", "HAFNIUM Group", "CISA AA22-257A"] -action.risk = 1 -action.risk.param._risk_message = The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$, attempting to dump lsass.exe. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 80}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9039,11 +8829,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Monitor Backup Solution"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9079,11 +8864,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["DHS Report TA18-074A", "Suspicious Command-Line Executions", "Orangeworm Attack Group", "Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns", "Hidden Cobra Malware"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9119,11 +8899,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["GCP Cross Account Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9159,11 +8934,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["GCP Cross Account Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9199,11 +8969,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["GCP Cross Account Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9285,11 +9050,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Account Monitoring and Controls"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9325,11 +9085,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Role Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9365,11 +9120,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Role Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9405,11 +9155,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Role Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9445,11 +9190,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Object Access Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9485,11 +9225,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Role Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9525,11 +9260,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Role Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9565,11 +9295,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Object Access Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9605,11 +9330,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Role Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9645,11 +9365,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Object Access Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9685,11 +9400,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Object Access Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9725,11 +9435,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Scanning Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9765,11 +9470,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Scanning Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9805,11 +9505,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Role Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9845,11 +9540,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Role Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9885,11 +9575,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Object Access Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9925,11 +9610,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Role Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -9965,11 +9645,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Object Access Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -10005,11 +9680,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Kubernetes Sensitive Object Access Activity"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -10229,11 +9899,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Monitor for Unauthorized Software", "Emotet Malware DHS Report TA18-201A ", "SamSam Ransomware"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -10585,11 +10250,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Hidden Cobra Malware"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -10671,11 +10331,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Suspicious Rundll32 Activity", "Masquerading - Rename System Utilities"] -action.risk = 1 -action.risk.param._risk_message = Suspicious renamed rundll32.exe binary ran on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 63}, {"risk_object_field": "User", "risk_object_type": "user", "risk_score": 63}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -10711,11 +10366,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Collection and Staging"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -10751,11 +10401,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Privilege Escalation", "Unusual Processes", "Hermetic Wiper"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -10837,11 +10482,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Monitor Backup Solution"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"threat_object_field": "field", "threat_object_type": "unknown"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -11095,11 +10735,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Ransomware"] -action.risk = 1 -action.risk.param._risk_message = archive process $process_name$ with suspicious cmdline $process$ in host $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}, {"threat_object_field": "SourceImage", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -12779,11 +12414,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Data Destruction", "IcedID", "Log4Shell CVE-2021-44228", "WhisperGate", "Hermetic Wiper", "Living Off The Land", "Azorult", "DarkCrystal RAT", "ProxyNotShell", "Qakbot"] -action.risk = 1 -action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting spawn a new process. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 30}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 30}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -13006,11 +12636,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["SamSam Ransomware", "Ryuk Ransomware", "Ransomware", "Clop Ransomware", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = The device $dest$ wrote $file_count$ files to $path_count$ path(s) with the $file_extension$ extension. This extension and behavior may indicate a $Name$ ransomware attack. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 90}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 90}, {"threat_object_field": "file_name", "threat_object_type": "file name"}, {"threat_object_field": "file_count", "threat_object_type": "other"}, {"threat_object_field": "path_count", "threat_object_type": "other"}, {"threat_object_field": "file_extension", "threat_object_type": "other"}, {"threat_object_field": "Name", "threat_object_type": "other"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -13046,11 +12671,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["SamSam Ransomware", "Ransomware", "Ryuk Ransomware", "Clop Ransomware"] -action.risk = 1 -action.risk.param._risk_message = A file - $file_name$ was written to disk on endpoint $dest$ by user $user$, this is indicative of a known ransomware note file and should be reviewed immediately. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 90}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 90}, {"threat_object_field": "file_name", "threat_object_type": "file name"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -13592,11 +13212,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Defense Evasion Tactics"] -action.risk = 1 -action.risk.param._risk_message = csc.exe with commandline $process$ to compile .net code on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -14092,11 +13707,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Detect Zerologon Attack"] -action.risk = 1 -action.risk.param._risk_message = The following $EventCode$ occurred on $dest$ by $user$ with Logon Type 3, which may be indicative of the an account or group being changed by an anonymous account. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 49}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 49}, {"threat_object_field": "EventCode", "threat_object_type": "other"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -14412,11 +14022,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Suspicious Compiled HTML Activity", "Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = The following $process_name$ has been identified as renamed, spawning from $parent_process_name$. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 80}, {"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 80}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -14734,11 +14339,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Suspicious MSHTA Activity", "Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = The following $process_name$ has been identified as renamed, spawning from $parent_process_name$. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 80}, {"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 80}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -15004,11 +14604,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Suspicious Command-Line Executions", "Suspicious MSHTA Activity", "Suspicious Zoom Child Processes", "NOBELIUM Group"] -action.risk = 1 -action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ running prohibited applications. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 80}, {"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 80}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -15501,11 +15096,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Collection and Staging"] -action.risk = 1 -action.risk.param._risk_message = The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 27}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 27}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -15541,11 +15131,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["SamSam Ransomware", "DHS Report TA18-074A", "HAFNIUM Group", "DarkSide Ransomware", "Active Directory Lateral Movement", "CISA AA22-320A"] -action.risk = 1 -action.risk.param._risk_message = The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 27}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 27}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -15581,11 +15166,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["DarkSide Ransomware", "Ransomware"] -action.risk = 1 -action.risk.param._risk_message = The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 27}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 27}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -15621,11 +15201,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Collection and Staging", "CISA AA22-277A"] -action.risk = 1 -action.risk.param._risk_message = The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 27}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 27}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -17556,11 +17131,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = an instance of process $process_name$ with commandline $process$ in $dest$ -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -17734,11 +17304,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Domain controller discovery on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 21}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -17820,11 +17385,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Domain group discovery enumeration on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -17860,11 +17420,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery", "Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = Domain group discovery enumeration on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -17900,11 +17455,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Domain group discovery enumeration on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -17967,7 +17517,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = `sysmon` EventCode=15 process_name = "telegram.exe" TargetFilename = "*:Zone.Identifier" |stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode Image process_id TargetFilename Hash | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `download_files_using_telegram_filter` +search = `sysmon` EventCode= 15 process_name = "telegram.exe" TargetFilename = "*:Zone.Identifier" |stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode Image process_id TargetFilename Hash | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `download_files_using_telegram_filter` [ESCU - Drop IcedID License dat - Rule] action.escu = 0 @@ -17986,11 +17536,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["IcedID"] -action.risk = 1 -action.risk.param._risk_message = process $SourceImage$ create a file $TargetImage$ in host $Computer$ -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 63}, {"threat_object_field": "SourceImage", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -18007,7 +17552,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = `sysmon` EventCode=11 TargetFilename = "*\\license.dat" AND (TargetFilename="*\\appdata\\*" OR TargetFilename="*\\programdata\\*") |stats count min(_time) as firstTime max(_time) as lastTime by TargetFilename EventCode process_id process_name Computer | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_icedid_license_dat_filter` +search = `sysmon` EventCode= 11 TargetFilename = "*\\license.dat" AND (TargetFilename="*\\appdata\\*" OR TargetFilename="*\\programdata\\*") |stats count min(_time) as firstTime max(_time) as lastTime by TargetFilename EventCode process_id process_name Computer | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_icedid_license_dat_filter` [ESCU - DSQuery Domain Discovery - Rule] action.escu = 0 @@ -18228,11 +17773,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Elevated group discovery using PowerView on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 21}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -18452,11 +17992,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Credential Dumping", "Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user user$ attempting to capture credentials for offline cracking or observability. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 80}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 80}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -19732,11 +19267,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = an instance of process $process_name$ with commandline $process$ in $dest$ -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 9}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -19772,11 +19302,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = powershell process having commandline $Message$ to query domain password policy -action.risk.param._risk = [{"risk_object_field": "ComputerName", "risk_object_type": "system", "risk_score": 9}, {"risk_object_field": "User", "risk_object_type": "user", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -19812,11 +19337,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = an instance of process $process_name$ with commandline $process$ in $dest$ -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -19852,11 +19372,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = powershell process having commandline $Message$ for user enumeration -action.risk.param._risk = [{"risk_object_field": "ComputerName", "risk_object_type": "system", "risk_score": 25}, {"risk_object_field": "User", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -20364,11 +19879,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = System group discovery on $dest$ by $user$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -20408,11 +19918,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = System group discovery enumeration on $dest$ by $user$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -20448,11 +19953,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Remote system discovery enumeration on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -20488,11 +19988,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery", "CISA AA22-320A"] -action.risk = 1 -action.risk.param._risk_message = Remote system discovery enumeration on $Computer$ by $UserID$ -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -20528,11 +20023,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Domain group discovery enumeration on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -20568,11 +20058,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Domain group discovery enumeration using PowerShell on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -20608,11 +20093,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = System user discovery on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -20648,11 +20128,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = System user discovery on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -20780,11 +20255,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Remote system discovery using PowerView on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 24}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -20958,11 +20428,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Local user discovery enumeration using PowerShell on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -20998,11 +20463,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery", "Malicious PowerShell"] -action.risk = 1 -action.risk.param._risk_message = Local user discovery enumeration using PowerShell on $Computer$ by $user$ -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -21038,11 +20498,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Network Connection discovery on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -21078,11 +20533,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Network Connection discovery on $Computer$ by $user$ -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -21394,11 +20844,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Local user discovery enumeration using PowerShell on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -21434,11 +20879,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery", "Malicious PowerShell"] -action.risk = 1 -action.risk.param._risk_message = Local user discovery enumeration using PowerShell on $Computer$ by $UserID$ -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -21784,11 +21224,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["IcedID"] -action.risk = 1 -action.risk.param._risk_message = process $SourceImage$ create a file $TargetImage$ in host $Computer$ -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 72}, {"threat_object_field": "SourceImage", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -21805,7 +21240,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = `sysmon` EventCode=11 (TargetFilename = "*\\passff.tar" OR TargetFilename = "*\\cookie.tar") |stats count min(_time) as firstTime max(_time) as lastTime by TargetFilename EventCode process_id process_name Computer | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `icedid_exfiltrated_archived_file_creation_filter` +search = `sysmon` EventCode= 11 (TargetFilename = "*\\passff.tar" OR TargetFilename = "*\\cookie.tar") |stats count min(_time) as firstTime max(_time) as lastTime by TargetFilename EventCode process_id process_name Computer | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `icedid_exfiltrated_archived_file_creation_filter` [ESCU - Impacket Lateral Movement Commandline Parameters - Rule] action.escu = 0 @@ -22450,11 +21885,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] -action.risk = 1 -action.risk.param._risk_message = A commandline $process$ that may create user account on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -22490,11 +21920,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Industroyer2", "Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = A possible crontab list command $process$ executed on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -22930,11 +22355,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = A commandline $process$ with process $process_name$ on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -23612,11 +23032,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = A possible crontab edit command $process$ executed on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -24058,11 +23473,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Linux Living Off The Land", "Ingress Tool Transfer"] -action.risk = 1 -action.risk.param._risk_message = An instance of $process_name$ was identified on endpoint $dest$ by user $user$ utilizing curl or wget. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 1}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 1}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -24344,11 +23754,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["CyclopsBLink"] -action.risk = 1 -action.risk.param._risk_message = a $process_name$ with kworker commandline in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 36}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -24991,11 +24396,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = A commandline $process$ that may modify cronjob file in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 49}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -25031,11 +24431,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques", "Linux Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = A commandline $process$ that may modify cronjob file using editor in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 6}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -25781,11 +25176,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Linux Privilege Escalation", "Linux Persistence Techniques"] -action.risk = 1 -action.risk.param._risk_message = A commandline $process$ that execute sudo or su in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -25954,6 +25344,8 @@ action.notable.param.rule_description = The following correlation identifies a d action.notable.param.rule_title = RBA: Living Off The Land action.notable.param.security_domain = endpoint action.notable.param.severity = high +action.notable.param.drilldown_name = Living Off The Land +action.notable.param.drilldown_search = | from datamodel:"Risk.All_Risk" | search risk_object="$risk_object$" risk_object_type="$risk_object_type$" annotations.analytic_story="$annotations.analytic_story$" annotations.mitre_attack.mitre_tactic="$annotations.mitre_attack.mitre_tactic$" | `get_correlations` | rename annotations.mitre_attack.mitre_tactic_id as mitre_tactic_id, annotations.mitre_attack.mitre_tactic as mitre_tactic, annotations.mitre_attack.mitre_technique_id as mitre_technique_id, annotations.mitre_attack.mitre_technique as mitre_technique alert.digest_mode = 1 disabled = true enableSched = 1 @@ -26028,11 +25420,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Local user discovery enumeration on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -26068,11 +25455,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Local user discovery enumeration on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -26477,11 +25859,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Hermetic Wiper", "Malicious PowerShell", "NOBELIUM Group", "WhisperGate", "DarkCrystal RAT", "Qakbot", "CISA AA22-320A"] -action.risk = 1 -action.risk.param._risk_message = Powershell.exe running potentially malicious encodede commands on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 35}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -26728,7 +26105,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = `sysmon` EventCode=13 (TargetObject= "*\\Control Panel\\Desktop\\Wallpaper" AND Image != "*\\explorer.exe") OR (TargetObject= "*\\Control Panel\\Desktop\\Wallpaper" AND Details = "*\\temp\\*") | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Image TargetObject Details Computer process_guid process_id user_id | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `modification_of_wallpaper_filter` +search = `sysmon` EventCode =13 (TargetObject= "*\\Control Panel\\Desktop\\Wallpaper" AND Image != "*\\explorer.exe") OR (TargetObject= "*\\Control Panel\\Desktop\\Wallpaper" AND Details = "*\\temp\\*") | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Image TargetObject Details Computer process_guid process_id user_id | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `modification_of_wallpaper_filter` [ESCU - Modify ACL permission To Files Or Folder - Rule] action.escu = 0 @@ -26900,7 +26277,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = `sysmon` EventCode=7 Image IN ("*\\wscript.exe", "*\\cscript.exe") ImageLoaded IN ("*\\Wldap32.dll", "*\\adsldp.dll", "*\\adsldpc.dll") | stats min(_time) as firstTime max(_time) as lastTime count by Image EventCode process_name ProcessId ProcessGuid Computer ImageLoaded | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `ms_scripting_process_loading_ldap_module_filter` +search = `sysmon` EventCode =7 Image IN ("*\\wscript.exe", "*\\cscript.exe") ImageLoaded IN ("*\\Wldap32.dll", "*\\adsldp.dll", "*\\adsldpc.dll") | stats min(_time) as firstTime max(_time) as lastTime count by Image EventCode process_name ProcessId ProcessGuid Computer ImageLoaded | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `ms_scripting_process_loading_ldap_module_filter` [ESCU - MS Scripting Process Loading WMI Module - Rule] action.escu = 0 @@ -26940,7 +26317,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = `sysmon` EventCode=7 Image IN ("*\\wscript.exe", "*\\cscript.exe") ImageLoaded IN ("*\\fastprox.dll", "*\\wbemdisp.dll", "*\\wbemprox.dll", "*\\wbemsvc.dll" , "*\\wmiutils.dll", "*\\wbemcomn.dll") | stats min(_time) as firstTime max(_time) as lastTime count by Image EventCode process_name ProcessId ProcessGuid Computer ImageLoaded | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `ms_scripting_process_loading_wmi_module_filter` +search = `sysmon` EventCode =7 Image IN ("*\\wscript.exe", "*\\cscript.exe") ImageLoaded IN ("*\\fastprox.dll", "*\\wbemdisp.dll", "*\\wbemprox.dll", "*\\wbemsvc.dll" , "*\\wmiutils.dll", "*\\wbemcomn.dll") | stats min(_time) as firstTime max(_time) as lastTime count by Image EventCode process_name ProcessId ProcessGuid Computer ImageLoaded | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `ms_scripting_process_loading_wmi_module_filter` [ESCU - MSBuild Suspicious Spawned By Script Process - Rule] action.escu = 0 @@ -27107,11 +26484,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Windows Privilege Escalation", "Hermetic Wiper"] -action.risk = 1 -action.risk.param._risk_message = The following module $ImageLoaded$ was loaded by $Image$ outside of the normal system paths on endpoint $Computer$, potentally related to DLL side-loading. -action.risk.param._risk = [{"threat_object_field": "process_name", "threat_object_type": "process name"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -27423,11 +26795,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery", "Windows Discovery Techniques", "Azorult", "Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = Local group discovery on $dest$ by $user$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -27509,11 +26876,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery", "Qakbot", "Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = Network Connection discovery on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -27549,11 +26911,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery", "Azorult", "Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = Network Connection discovery on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -27589,11 +26946,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery", "Qakbot", "CISA AA22-277A", "Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = Network Connection discovery on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -27629,11 +26981,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery", "Qakbot", "CISA AA22-277A", "Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = Network Connection discovery on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -28675,11 +28022,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = an instance of process $process_name$ with commandline $process$ in $dest$ -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 9}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -28902,11 +28244,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Remcos"] -action.risk = 1 -action.risk.param._risk_message = suspicious process $process_name$ contains commandline $process$ on $dest$ -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 16}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 16}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -28988,11 +28325,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Credential Dumping", "Insider Threat"] -action.risk = 1 -action.risk.param._risk_message = Potential password in username ($user$) with Shannon entropy ($ut_shannon$) -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 21}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 21}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 21}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -29049,7 +28381,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.parent_process_name Processes.process_name Processes.process Processes.user Processes.dest | `drop_dm_object_name(Processes)` | where len(process) > 200 | `potentially_malicious_code_on_cmdline_tokenize_score` | apply unusual_commandline_detection | eval score='predicted(unusual_cmdline_logits)', process=orig_process | fields - unusual_cmdline* predicted(unusual_cmdline_logits) orig_process | where score > 0.5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `potentially_malicious_code_on_commandline_filter` +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel="Endpoint.Processes" by Processes.parent_process_name Processes.process_name Processes.process Processes.user Processes.dest | `drop_dm_object_name(Processes)` | where len(process) > 200 | `potentially_malicious_code_on_cmdline_tokenize_score` | apply unusual_commandline_detection | eval score='predicted(unusual_cmdline_logits)', process=orig_process | fields - unusual_cmdline* predicted(unusual_cmdline_logits) orig_process | where score > 0.5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `potentially_malicious_code_on_commandline_filter` [ESCU - PowerShell 4104 Hunting - Rule] action.escu = 0 @@ -29068,11 +28400,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Hermetic Wiper", "Malicious PowerShell"] -action.risk = 1 -action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $Computer$ by user $user$ executing suspicious commands. -action.risk.param._risk = [{"risk_object_field": "UserID", "risk_object_type": "user", "risk_score": 80}, {"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 80}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -29108,11 +28435,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Hermetic Wiper", "Malicious PowerShell", "Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns", "HAFNIUM Group", "Log4Shell CVE-2021-44228", "AgentTesla"] -action.risk = 1 -action.risk.param._risk_message = PowerShell processes $process$ started with parameters to modify the execution policy of the run, run in a hidden window, and connect to the Internet on host $dest$ executed by user $user$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 81}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 81}, {"threat_object_field": "process", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -29540,11 +28862,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Local group discovery on $dest$ by $user$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -29584,11 +28901,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Local group discovery on $dest$ by $user$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -29801,7 +29113,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = `sysmon` EventCode=8 parent_process_name IN ("powershell_ise.exe", "powershell.exe") TargetImage IN ("*\\svchost.exe","*\\csrss.exe" "*\\gpupdate.exe", "*\\explorer.exe","*\\services.exe","*\\winlogon.exe","*\\smss.exe","*\\wininit.exe","*\\userinit.exe","*\\spoolsv.exe","*\\taskhost.exe") | stats min(_time) as firstTime max(_time) as lastTime count by SourceImage process_name SourceProcessId SourceProcessGuid TargetImage TargetProcessId NewThreadId StartAddress Computer EventCode | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `powershell_remote_thread_to_known_windows_process_filter` +search = `sysmon` EventCode = 8 parent_process_name IN ("powershell_ise.exe", "powershell.exe") TargetImage IN ("*\\svchost.exe","*\\csrss.exe" "*\\gpupdate.exe", "*\\explorer.exe","*\\services.exe","*\\winlogon.exe","*\\smss.exe","*\\wininit.exe","*\\userinit.exe","*\\spoolsv.exe","*\\taskhost.exe") | stats min(_time) as firstTime max(_time) as lastTime count by SourceImage process_name SourceProcessId SourceProcessGuid TargetImage TargetProcessId NewThreadId StartAddress Computer EventCode | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `powershell_remote_thread_to_known_windows_process_filter` [ESCU - Powershell Remove Windows Defender Directory - Rule] action.escu = 0 @@ -30387,11 +29699,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Remcos"] -action.risk = 1 -action.risk.param._risk_message = An instance of $process_name$ was identified on endpoint $dest$ downloading the DynamicWrapperX dll. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 80}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 80}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -30513,11 +29820,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Lateral Movement", "CISA AA22-257A"] -action.risk = 1 -action.risk.param._risk_message = A windows scheduled task with a suspicious task name was created on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 45}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -30553,11 +29855,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Active Directory Lateral Movement"] -action.risk = 1 -action.risk.param._risk_message = A Windows Service with a suspicious service name was installed on $ComputerName$ -action.risk.param._risk = [{"threat_object_field": "Service_File_Name", "threat_object_type": "other"}, {"risk_object_field": "ComputerName", "risk_object_type": "system", "risk_score": 45}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -31121,11 +30418,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Hidden Cobra Malware", "Active Directory Lateral Movement"] -action.risk = 1 -action.risk.param._risk_message = tbd -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -31575,11 +30867,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Remote system discovery enumeration on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -31615,11 +30902,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Remote system discovery enumeration on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -31977,11 +31259,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Privilege Escalation", "Hermetic Wiper"] -action.risk = 1 -action.risk.param._risk_message = elevated process using runas on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -32017,11 +31294,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Suspicious Rundll32 Activity", "Microsoft MSHTML Remote Code Execution CVE-2021-40444", "Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -32557,11 +31829,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Credential Dumping"] -action.risk = 1 -action.risk.param._risk_message = The following process $process_name$ accessed the object $Object_Name$ attempting to gain access to credentials on $dest$ by user $user$. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 80}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 80}, {"threat_object_field": "process_name", "threat_object_type": "process"}, {"threat_object_field": "Object_Name", "threat_object_type": "file"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -34875,11 +34142,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Trusted Developer Utilities Proxy Execution", "Cobalt Strike", "Masquerading - Rename System Utilities", "Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = Suspicious renamed microsoft.workflow.compiler.exe binary ran on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 63}, {"risk_object_field": "User", "risk_object_type": "user", "risk_score": 63}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -35007,11 +34269,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Trusted Developer Utilities Proxy Execution MSBuild", "Cobalt Strike", "Masquerading - Rename System Utilities", "Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = Suspicious renamed msbuild.exe binary ran on $dest$ by $user$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 63}, {"risk_object_field": "User", "risk_object_type": "user", "risk_score": 63}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -35853,11 +35110,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["sAMAccountName Spoofing and Domain Controller Impersonation", "Active Directory Kerberos Attacks"] -action.risk = 1 -action.risk.param._risk_message = A suspicious TGT was requested was requested -action.risk.param._risk = [{"risk_object_field": "ComputerName", "risk_object_type": "system", "risk_score": 60}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -36077,11 +35329,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Remcos"] -action.risk = 1 -action.risk.param._risk_message = dxdiag.exe process with commandline $process$ on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -36207,11 +35454,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = System user discovery on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -36247,11 +35489,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery", "Qakbot"] -action.risk = 1 -action.risk.param._risk_message = System user discovery on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -36663,11 +35900,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Lateral Movement", "Active Directory Kerberos Attacks"] -action.risk = 1 -action.risk.param._risk_message = -action.risk.param._risk = [{"risk_object_field": "Client_Address", "risk_object_type": "system", "risk_score": 42}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -36747,11 +35979,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Lateral Movement"] -action.risk = 1 -action.risk.param._risk_message = -action.risk.param._risk = [{"risk_object_field": "ComputerName", "risk_object_type": "system", "risk_score": 42}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -36867,11 +36094,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = System user discovery on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -36907,11 +36129,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = System user discovery on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -37039,11 +36256,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Unusual Processes"] -action.risk = 1 -action.risk.param._risk_message = process $process_name$ to execute possible clsid commandline $process$ in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -37244,7 +36456,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = `sysmon` EventCode=22 process_name = wermgr.exe QueryName IN ("*wtfismyip.com", "*checkip.amazonaws.com", "*ipecho.net", "*ipinfo.io", "*api.ipify.org", "*icanhazip.com", "*ip.anysrc.com","*api.ip.sb", "ident.me", "www.myexternalip.com", "*zen.spamhaus.org", "*cbl.abuseat.org", "*b.barracudacentral.org","*dnsbl-1.uceprotect.net", "*spam.dnsbl.sorbs.net") | stats min(_time) as firstTime max(_time) as lastTime count by Image process_name ProcessId QueryName QueryStatus QueryResults Computer EventCode | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `wermgr_process_connecting_to_ip_check_web_services_filter` +search = `sysmon` EventCode =22 process_name = wermgr.exe QueryName IN ("*wtfismyip.com", "*checkip.amazonaws.com", "*ipecho.net", "*ipinfo.io", "*api.ipify.org", "*icanhazip.com", "*ip.anysrc.com","*api.ip.sb", "ident.me", "www.myexternalip.com", "*zen.spamhaus.org", "*cbl.abuseat.org", "*b.barracudacentral.org","*dnsbl-1.uceprotect.net", "*spam.dnsbl.sorbs.net") | stats min(_time) as firstTime max(_time) as lastTime count by Image process_name ProcessId QueryName QueryStatus QueryResults Computer EventCode | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `wermgr_process_connecting_to_ip_check_web_services_filter` [ESCU - Wermgr Process Create Executable File - Rule] action.escu = 0 @@ -37441,11 +36653,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Brute Ratel C4"] -action.risk = 1 -action.risk.param._risk_message = A process $SourceImage$ is duplicating the handle token of winlogon.exe in $Computer$ -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 36}, {"threat_object_field": "SourceImage", "threat_object_type": "process name"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -37997,11 +37204,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Defense Evasion Tactics", "Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190"] -action.risk = 1 -action.risk.param._risk_message = A parent process $parent_process_name$ has spawned a child $process_name$ with path traversal commandline $process$ in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 36}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -39047,11 +38249,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Ransomware"] -action.risk = 1 -action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to encrypt disks. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 35}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 35}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -39179,11 +38376,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Living Off The Land", "Windows Defense Evasion Tactics"] -action.risk = 1 -action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to perform DLL search order hijacking. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 1}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 1}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -39219,11 +38411,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Living Off The Land", "Windows Defense Evasion Tactics", "Qakbot"] -action.risk = 1 -action.risk.param._risk_message = An instance of $parent_process_name$ loading $process_name$ was identified on endpoint $dest$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 1}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -39489,11 +38676,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Windows Drivers", "CISA AA22-320A", "AgentTesla"] -action.risk = 1 -action.risk.param._risk_message = A driver has loaded on $Computer$. -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 42}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -39529,11 +38711,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Windows Defense Evasion Tactics"] -action.risk = 1 -action.risk.param._risk_message = Service was disabled on $Computer$ -action.risk.param._risk = [{"risk_object_field": "ComputerName", "risk_object_type": "system", "risk_score": 36}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -39615,11 +38792,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Windows Persistence Techniques"] -action.risk = 1 -action.risk.param._risk_message = Windows eventcode 3000 triggered on $dest$ potentially indicating persistence or a monitoring of a process has occurred. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -39873,11 +39045,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Brute Ratel C4"] -action.risk = 1 -action.risk.param._risk_message = An instance of $Computer$ that loads $ImageLoaded$ that are related to accessing to SAM object information. -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -39913,11 +39080,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Azorult", "DarkCrystal RAT"] -action.risk = 1 -action.risk.param._risk_message = process connecting IP location web services on $Computer$ -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -40165,11 +39327,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Credential Dumping"] -action.risk = 1 -action.risk.param._risk_message = A process, $SourceImage$, has requested access to LSASS on $dest$. Review for further details. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 64}, {"threat_object_field": "SourceImage", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -40205,11 +39362,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing a protocol handler. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 6}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 6}, {"threat_object_field": "parent_process_name", "threat_object_type": "process name"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -40245,11 +39397,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Azorult"] -action.risk = 1 -action.risk.param._risk_message = Applocker importing xml policy command was executed in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -40285,11 +39432,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Defense Evasion Tactics", "Windows Registry Abuse"] -action.risk = 1 -action.risk.param._risk_message = Windows Defender context menu registry key deleted on $dest$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -40583,11 +39725,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = process $process_name$ with commandline $process$ is executed in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -40663,11 +39800,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Brute Ratel C4"] -action.risk = 1 -action.risk.param._risk_message = a process $Image$ loaded $ImageLoaded$ in $Computer$ -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -41076,11 +40208,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Spearphishing Attachments", "Brute Ratel C4", "AgentTesla", "Qakbot", "IcedID", "Azorult", "Remcos"] -action.risk = 1 -action.risk.param._risk_message = An ISO file was mounted on $dest$ and should be reviewed and filtered as needed. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 40}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -41678,11 +40805,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = execution of process $process_name$ in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -42332,11 +41454,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["WhisperGate"] -action.risk = 1 -action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ related to NiRSoft software usage. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 80}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 80}, {"threat_object_field": "parent_process_name", "threat_object_type": "process"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -42418,11 +41535,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Living Off The Land"] -action.risk = 1 -action.risk.param._risk_message = An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to circumvent controls. -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 6}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 6}, {"threat_object_field": "parent_process_name", "threat_object_type": "process name"}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -42596,11 +41708,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = a process with commandline $process$ that can retrieve information related to password manager databases in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -42636,11 +41743,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Brute Ratel C4", "AgentTesla", "Qakbot", "IcedID", "Azorult", "Remcos"] -action.risk = 1 -action.risk.param._risk_message = An ISO file was mounted on $dest$ and should be reviewed and filtered as needed. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 40}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -43136,11 +42238,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Brute Ratel C4"] -action.risk = 1 -action.risk.param._risk_message = process $SourceImage$ create a remote thread to process $TargetImage$ on host $Computer$ -action.risk.param._risk = [{"risk_object_field": "Computer", "risk_object_type": "system", "risk_score": 64}, {"threat_object_field": "SourceImage", "threat_object_type": "process"}, {"threat_object_field": "TargetImage", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -43302,11 +42399,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = execution of process $process_name$ in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -43744,11 +42836,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Insider Threat", "Command and Control", "Ransomware"] -action.risk = 1 -action.risk.param._risk_message = The following Remote Access Software $process_name$ was identified on $dest$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 1}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -44622,11 +43709,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = process klist.exe executed in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -44708,11 +43790,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Qakbot"] -action.risk = 1 -action.risk.param._risk_message = System nslookup domain discovery on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -44748,11 +43825,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Qakbot"] -action.risk = 1 -action.risk.param._risk_message = System qwinsta domain discovery on $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -44788,11 +43860,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Drivers", "CISA AA22-264A"] -action.risk = 1 -action.risk.param._risk_message = A new driver is present on $dest$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 10}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -44868,11 +43935,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = process $process_name$ with commandline $process$ is executed in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -44908,11 +43970,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = netsh process with command line $process$ in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -45114,11 +44171,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Windows Post-Exploitation", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = execution of process $process_name$ in $dest$ -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 9}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -45366,11 +44418,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Suspicious WMI Use", "Qakbot"] -action.risk = 1 -action.risk.param._risk_message = process with $process$ commandline executed in $dest$ -action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -45522,11 +44569,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["IcedID", "Windows Persistence Techniques", "Industroyer2", "DarkCrystal RAT", "CISA AA22-257A", "Qakbot", "Prestige Ransomware"] -action.risk = 1 -action.risk.param._risk_message = A Scheduled Task was scheduled and ran on $dest$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 80}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -45989,11 +45031,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["Active Directory Discovery"] -action.risk = 1 -action.risk.param._risk_message = Local group discovery on $dest$ by $user$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -46029,11 +45066,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"] action.escu.analytic_story = ["IcedID", "Azorult"] -action.risk = 1 -action.risk.param._risk_message = Wmic $process_name$ with command-line $process$ on $dest$ attempting to uninstall software. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 25}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 25}, {"threat_object_field": "process_name", "threat_object_type": "process"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -46396,7 +45428,7 @@ action.risk.param._risk_message = tbd action.risk.param._risk = [{"threat_object_field": "dest", "threat_object_type": "other"}] action.risk.param._risk_score = 0 action.risk.param.verbose = 0 -cron_schedule = 59 * * * * +cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 @@ -46404,9 +45436,9 @@ action.correlationsearch.label = ESCU - Detect ARP Poisoning - Rule action.correlationsearch.annotations = {"analytic_story": ["Router and Infrastructure Security"], "cis20": ["CIS 13"], "confidence": 50, "impact": 50, "kill_chain_phases": ["Delivery", "Actions On Objectives", "Exploitation"], "mitre_attack": ["T1200", "T1498", "T1557", "T1557.002"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Other"], "type": "Other"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = src_interface,firstTime,lastTime,count -action.notable.param.rule_description = ARP Poisoning has been detected on interface $src_interface$ on host $orig_host$. This may be an indication of a MITM attack. -action.notable.param.rule_title = ARP Poisoning Detected on $orig_host$ +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = By enabling Dynamic ARP Inspection as a Layer 2 Security measure on the organization's network devices, we will be able to detect ARP Poisoning attacks in the Infrastructure. +action.notable.param.rule_title = Detect ARP Poisoning action.notable.param.security_domain = network action.notable.param.severity = high alert.digest_mode = 1 @@ -46621,11 +45653,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Log4Shell CVE-2021-44228"] -action.risk = 1 -action.risk.param._risk_message = An outbound LDAP connection from $src_ip$ in your infrastructure connecting to dest ip $dest_ip$ -action.risk.param._risk = [{"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 56}, {"risk_object_field": "dest_ip", "risk_object_type": "system", "risk_score": 56}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -46758,7 +45785,7 @@ action.risk.param._risk_message = tbd action.risk.param._risk = [{"threat_object_field": "dest", "threat_object_type": "other"}] action.risk.param._risk_score = 0 action.risk.param.verbose = 0 -cron_schedule = 59 * * * * +cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 @@ -46766,9 +45793,9 @@ action.correlationsearch.label = ESCU - Detect Rogue DHCP Server - Rule action.correlationsearch.annotations = {"analytic_story": ["Router and Infrastructure Security"], "cis20": ["CIS 13"], "confidence": 50, "impact": 50, "kill_chain_phases": ["Delivery", "Actions On Objectives", "Exploitation"], "mitre_attack": ["T1200", "T1498", "T1557"], "nist": ["DE.CM"], "observable": [{"name": "dest", "role": ["Other"], "type": "Other"}]} schedule_window = auto action.notable = 1 -action.notable.param.nes_fields = src_mac,firstTime,lastTime,count,message_type -action.notable.param.rule_description = DHCP Snooping has detected a Rogue DHCP Server on $orig_host$ from $src_mac$. This may be an indication of a MITM attack. -action.notable.param.rule_title = Rogue DHCP Server Detected on $orig_host$ +action.notable.param.nes_fields = user,dest +action.notable.param.rule_description = By enabling DHCP Snooping as a Layer 2 Security measure on the organization's network devices, we will be able to detect unauthorized DHCP servers handing out DHCP leases to devices on the network (Man in the Middle attack). +action.notable.param.rule_title = Detect Rogue DHCP Server action.notable.param.security_domain = network action.notable.param.severity = high alert.digest_mode = 1 @@ -47806,11 +46833,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Splunk Vulnerabilities"] -action.risk = 1 -action.risk.param._risk_message = The following $dest$ is using the self signed Splunk certificate. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 42}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -47846,11 +46868,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["OpenSSL CVE-2022-3602"] -action.risk = 1 -action.risk.param._risk_message = A x509 certificate has been identified to have punycode in the SSL issuer email domain on $dest$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -47972,11 +46989,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["OpenSSL CVE-2022-3602"] -action.risk = 1 -action.risk.param._risk_message = A x509 certificate has been identified to have punycode in the subject alternative name on $dest$. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 15}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -48314,11 +47326,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["Log4Shell CVE-2021-44228", "CISA AA22-320A"] -action.risk = 1 -action.risk.param._risk_message = Hunting for Log4Shell exploitation has occurred. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 40}, {"threat_object_field": "http_method", "threat_object_type": "other"}, {"threat_object_field": "src", "threat_object_type": "other"}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -48659,11 +47666,6 @@ action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = null action.escu.analytic_story = ["VMware Server Side Injection and Privilege Escalation"] -action.risk = 1 -action.risk.param._risk_message = An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on $dest$ has occurred. -action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 35}] -action.risk.param._risk_score = 0 -action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -49652,7 +48654,7 @@ action.escu.creation_date = 2020-08-15 action.escu.modification_date = 2020-08-15 action.escu.analytic_story = ["Suspicious Cloud Authentication Activities"] action.escu.data_models = ["Authentication"] -cron_schedule = 0 1 1 1,4,7,10 * +cron_schedule = 0 2 * * 0 enableSched = 1 dispatch.earliest_time = -90d@d dispatch.latest_time = -1d@d @@ -49718,7 +48720,7 @@ action.escu.creation_date = 2020-09-03 action.escu.modification_date = 2020-09-03 action.escu.analytic_story = ["Suspicious Cloud User Activities"] action.escu.data_models = ["Change"] -cron_schedule = 0 1 1 1,4,7,10 * +cron_schedule = 0 2 * * 0 enableSched = 1 dispatch.earliest_time = -90d@d dispatch.latest_time = -1d@d @@ -49806,7 +48808,7 @@ action.escu.creation_date = 2020-10-08 action.escu.modification_date = 2020-10-08 action.escu.analytic_story = ["Cloud Cryptomining"] action.escu.data_models = ["Change"] -cron_schedule = 0 1 1 1,4,7,10 * +cron_schedule = 0 2 * * 0 enableSched = 1 dispatch.earliest_time = -90d@d dispatch.latest_time = -1d@d @@ -49850,7 +48852,7 @@ action.escu.creation_date = 2020-9-03 action.escu.modification_date = 2020-9-03 action.escu.analytic_story = ["Cloud Cryptomining"] action.escu.data_models = ["Change"] -cron_schedule = 0 1 1 1,4,7,10 * +cron_schedule = 0 2 * * 0 enableSched = 1 dispatch.earliest_time = -90d@d dispatch.latest_time = -1d@d @@ -49894,7 +48896,7 @@ action.escu.creation_date = 2020-07-29 action.escu.modification_date = 2020-07-29 action.escu.analytic_story = ["Suspicious Cloud Instance Activities"] action.escu.data_models = ["Change"] -cron_schedule = 0 1 1 1,4,7,10 * +cron_schedule = 0 2 * * 0 enableSched = 1 dispatch.earliest_time = -90d@d dispatch.latest_time = -1d@d @@ -49938,7 +48940,7 @@ action.escu.creation_date = 2020-08-19 action.escu.modification_date = 2020-08-19 action.escu.analytic_story = ["Suspicious Cloud Provisioning Activities"] action.escu.data_models = ["Change"] -cron_schedule = 0 1 1 1,4,7,10 * +cron_schedule = 0 2 * * 0 enableSched = 1 dispatch.earliest_time = -90d@d dispatch.latest_time = -1d@d @@ -49982,7 +48984,7 @@ action.escu.creation_date = 2020-09-02 action.escu.modification_date = 2020-09-02 action.escu.analytic_story = ["Cloud Cryptomining"] action.escu.data_models = ["Change"] -cron_schedule = 0 1 1 1,4,7,10 * +cron_schedule = 0 2 * * 0 enableSched = 1 dispatch.earliest_time = -90d@d dispatch.latest_time = -1d@d @@ -50070,7 +49072,7 @@ action.escu.creation_date = 2020-06-23 action.escu.modification_date = 2020-06-23 action.escu.analytic_story = ["Orangeworm Attack Group", "Windows Service Abuse", "NOBELIUM Group"] action.escu.data_models = [] -cron_schedule = 0 1 1 1,4,7,10 * +cron_schedule = 0 2 * * 0 enableSched = 1 dispatch.earliest_time = -90d@d dispatch.latest_time = -1d@d @@ -50136,7 +49138,7 @@ action.escu.creation_date = 2020-05-28 action.escu.modification_date = 2020-05-28 action.escu.analytic_story = ["Suspicious Cloud Authentication Activities"] action.escu.data_models = ["Authentication"] -cron_schedule = 0 1 1 1,4,7,10 * +cron_schedule = 0 2 * * 0 enableSched = 1 dispatch.earliest_time = -90d@d dispatch.latest_time = -1d@d @@ -50180,7 +49182,7 @@ action.escu.creation_date = 2020-05-20 action.escu.modification_date = 2020-05-20 action.escu.analytic_story = ["Suspicious Zoom Child Processes"] action.escu.data_models = ["Endpoint"] -cron_schedule = 0 1 1 1,4,7,10 * +cron_schedule = 0 2 * * 0 enableSched = 1 dispatch.earliest_time = -90d@d dispatch.latest_time = -1d@d @@ -50224,7 +49226,7 @@ action.escu.creation_date = 2022-05-27 action.escu.modification_date = 2022-05-27 action.escu.analytic_story = ["Splunk Vulnerabilities"] action.escu.data_models = ["Splunk_Audit"] -cron_schedule = 0 * * * * +cron_schedule = 55 * * * * enableSched = 1 dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m diff --git a/dist/escu/default/transforms.conf b/dist/escu/default/transforms.conf index ccd9b6a52b..370496c3f8 100644 --- a/dist/escu/default/transforms.conf +++ b/dist/escu/default/transforms.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2023-01-03T12:38:50 UTC +# On Date: 2023-01-09T11:37:43 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/dist/escu/default/workflow_actions.conf b/dist/escu/default/workflow_actions.conf index 6830054909..6c3415e724 100644 --- a/dist/escu/default/workflow_actions.conf +++ b/dist/escu/default/workflow_actions.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2023-01-03T12:38:50 UTC +# On Date: 2023-01-09T11:37:43 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/ssa_detections/deprecated/ssa___credential_extractionfgdump_and_cachedump.yml b/ssa_detections/deprecated/ssa___credential_extractionfgdump_and_cachedump.yml index 972b1e0703..478946af27 100644 --- a/ssa_detections/deprecated/ssa___credential_extractionfgdump_and_cachedump.yml +++ b/ssa_detections/deprecated/ssa___credential_extractionfgdump_and_cachedump.yml @@ -36,9 +36,7 @@ tags: - Unusual Processes - Credential Dumping asset_type: Windows - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 70 message: Malicious actor is accessing stored credentials via FGDump or CacheDump tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ diff --git a/ssa_detections/deprecated/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml b/ssa_detections/deprecated/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml index e230389ecc..77c82ceca1 100644 --- a/ssa_detections/deprecated/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml +++ b/ssa_detections/deprecated/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml @@ -51,9 +51,7 @@ tags: analytic_story: - Active Directory Lateral Movement asset_type: Windows - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 80 message: Potential lateral movement and credential stealing via Pass the Token or Pass the Hash techniques. Operation is performed via credentials of the account diff --git a/ssa_detections/deprecated/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml b/ssa_detections/deprecated/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml index 70036a7fa0..ff87984bae 100644 --- a/ssa_detections/deprecated/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml +++ b/ssa_detections/deprecated/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml @@ -52,9 +52,7 @@ tags: analytic_story: - Active Directory Lateral Movement asset_type: Windows - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 80 message: Potential lateral movement and credential stealing via Pass the Token or Pass the Hash techniques. Operation is performed via credentials of the account diff --git a/ssa_detections/deprecated/ssa___unusual_lolbas_in_short_period_of_time.yml b/ssa_detections/deprecated/ssa___unusual_lolbas_in_short_period_of_time.yml index b1ba836e3e..a6ff8a45c7 100644 --- a/ssa_detections/deprecated/ssa___unusual_lolbas_in_short_period_of_time.yml +++ b/ssa_detections/deprecated/ssa___unusual_lolbas_in_short_period_of_time.yml @@ -55,9 +55,7 @@ tags: analytic_story: - Unusual Processes asset_type: Endpoint - atomic_guid: [] confidence: 50 - drilldown_search: [] impact: 50 message: A system process $process_name$ with commandline $cmd_line$ spawn iin short period of time in host $dest_device_id$ diff --git a/ssa_detections/deprecated/ssa___unusually_long_command_line.yml b/ssa_detections/deprecated/ssa___unusually_long_command_line.yml index 9ec216b3b5..ea3726af4a 100644 --- a/ssa_detections/deprecated/ssa___unusually_long_command_line.yml +++ b/ssa_detections/deprecated/ssa___unusually_long_command_line.yml @@ -37,9 +37,7 @@ tags: analytic_story: - Unusual Processes asset_type: Endpoint - atomic_guid: [] confidence: 40 - drilldown_search: [] impact: 30 message: A process $process_name$ with a long commandline $cmd_line$ executed in host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___anomalous_usage_of_account_credentials.yml b/ssa_detections/endpoint/ssa___anomalous_usage_of_account_credentials.yml index cfd5fc1ec7..a28e7c7146 100644 --- a/ssa_detections/endpoint/ssa___anomalous_usage_of_account_credentials.yml +++ b/ssa_detections/endpoint/ssa___anomalous_usage_of_account_credentials.yml @@ -30,9 +30,7 @@ tags: analytic_story: - Insider Threat asset_type: Endpoint - atomic_guid: [] confidence: 30 - drilldown_search: [] impact: 20 message: Multiple interactive logins detected on $device$ mitre_attack_id: diff --git a/ssa_detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml b/ssa_detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml index 57d2debc8d..1b5fce8ee6 100644 --- a/ssa_detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml +++ b/ssa_detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml @@ -35,9 +35,7 @@ tags: - NOBELIUM Group - Insider Threat asset_type: Endpoint - atomic_guid: [] confidence: 60 - drilldown_search: [] impact: 70 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading diff --git a/ssa_detections/endpoint/ssa___attempt_to_delete_services.yml b/ssa_detections/endpoint/ssa___attempt_to_delete_services.yml index bccc679469..9a7b3f854c 100644 --- a/ssa_detections/endpoint/ssa___attempt_to_delete_services.yml +++ b/ssa_detections/endpoint/ssa___attempt_to_delete_services.yml @@ -37,9 +37,7 @@ tags: - XMRig - Ransomware asset_type: Endpoint - atomic_guid: [] confidence: 60 - drilldown_search: [] impact: 60 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. diff --git a/ssa_detections/endpoint/ssa___attempt_to_disable_services.yml b/ssa_detections/endpoint/ssa___attempt_to_disable_services.yml index 05461585b7..4df76519f4 100644 --- a/ssa_detections/endpoint/ssa___attempt_to_disable_services.yml +++ b/ssa_detections/endpoint/ssa___attempt_to_disable_services.yml @@ -39,9 +39,7 @@ tags: - XMRig - Ransomware asset_type: Endpoint - atomic_guid: [] confidence: 60 - drilldown_search: [] impact: 60 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. diff --git a/ssa_detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml b/ssa_detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml index 4665e69eaf..3105633799 100644 --- a/ssa_detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/ssa_detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml @@ -35,9 +35,7 @@ tags: analytic_story: - Credential Dumping asset_type: Endpoint - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 70 message: An attempt to save registry keys storing credentials has been performed on $dest_device_id$ by $dest_user_id$ via process $process_name$. diff --git a/ssa_detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml b/ssa_detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml index b81cc0c503..1b01cb0c2a 100644 --- a/ssa_detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml +++ b/ssa_detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml @@ -34,9 +34,7 @@ tags: - Ransomware - Information Sabotage asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 100 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability @@ -78,7 +76,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog - update_timestamp: true + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-security_bcdedit_wbadmin.log + source: WinEventLog:Security diff --git a/ssa_detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml b/ssa_detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml index 3ba8cbced9..a1da58bf42 100644 --- a/ssa_detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml +++ b/ssa_detections/endpoint/ssa___clear_unallocated_sector_using_cipher_app.yml @@ -33,9 +33,7 @@ tags: - Ransomware - Information Sabotage asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 90 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to clear the unallocated sectors @@ -82,6 +80,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.004/cipher/security.log + source: WinEventLog:Security diff --git a/ssa_detections/endpoint/ssa___delete_a_net_user.yml b/ssa_detections/endpoint/ssa___delete_a_net_user.yml index d890c32669..16c7db3ccf 100644 --- a/ssa_detections/endpoint/ssa___delete_a_net_user.yml +++ b/ssa_detections/endpoint/ssa___delete_a_net_user.yml @@ -37,9 +37,7 @@ tags: - XMRig - Ransomware asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 70 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user diff --git a/ssa_detections/endpoint/ssa___deny_permission_using_cacls_utility.yml b/ssa_detections/endpoint/ssa___deny_permission_using_cacls_utility.yml index b07454b941..82eee33114 100644 --- a/ssa_detections/endpoint/ssa___deny_permission_using_cacls_utility.yml +++ b/ssa_detections/endpoint/ssa___deny_permission_using_cacls_utility.yml @@ -35,9 +35,7 @@ tags: - XMRig - Information Sabotage asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 50 message: A cacls process $process_name$ with commandline $cmd_line$ try to deny a permission of a file or directory in host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___detect_kerberoasting.yml b/ssa_detections/endpoint/ssa___detect_kerberoasting.yml index 033f70e2c7..718e790d7e 100644 --- a/ssa_detections/endpoint/ssa___detect_kerberoasting.yml +++ b/ssa_detections/endpoint/ssa___detect_kerberoasting.yml @@ -33,9 +33,7 @@ tags: analytic_story: - Credential Dumping asset_type: Endpoint - atomic_guid: [] confidence: 20 - drilldown_search: [] impact: 70 message: Kerberoasting malware is potentially applying stolen credentials. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via diff --git a/ssa_detections/endpoint/ssa___detect_prohibited_applications_spawning_cmd_exe.yml b/ssa_detections/endpoint/ssa___detect_prohibited_applications_spawning_cmd_exe.yml index 8ffb30fc74..39eeb03add 100644 --- a/ssa_detections/endpoint/ssa___detect_prohibited_applications_spawning_cmd_exe.yml +++ b/ssa_detections/endpoint/ssa___detect_prohibited_applications_spawning_cmd_exe.yml @@ -40,9 +40,7 @@ tags: - Suspicious Command-Line Executions - Insider Threat asset_type: Endpoint - atomic_guid: [] confidence: 50 - drilldown_search: [] impact: 70 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event @@ -82,6 +80,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-security.log + source: WinEventLog:Security diff --git a/ssa_detections/endpoint/ssa___detect_rclone_command_line_usage.yml b/ssa_detections/endpoint/ssa___detect_rclone_command_line_usage.yml index f48357ac0c..67284180b3 100644 --- a/ssa_detections/endpoint/ssa___detect_rclone_command_line_usage.yml +++ b/ssa_detections/endpoint/ssa___detect_rclone_command_line_usage.yml @@ -46,9 +46,7 @@ tags: - Ransomware - Insider Threat asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 50 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a @@ -90,6 +88,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-security.log + source: WinEventLog:Security diff --git a/ssa_detections/endpoint/ssa___disable_defender_antivirus_registry.yml b/ssa_detections/endpoint/ssa___disable_defender_antivirus_registry.yml index 8add694806..6253025a3e 100644 --- a/ssa_detections/endpoint/ssa___disable_defender_antivirus_registry.yml +++ b/ssa_detections/endpoint/ssa___disable_defender_antivirus_registry.yml @@ -34,9 +34,7 @@ tags: analytic_story: - IcedID asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 70 message: Modified/added/deleted registry entry $registry_path$ in $dest$ mitre_attack_id: @@ -65,9 +63,3 @@ tags: - Exploitation risk_score: 49 security_domain: endpoint -tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog diff --git a/ssa_detections/endpoint/ssa___disable_net_user_account.yml b/ssa_detections/endpoint/ssa___disable_net_user_account.yml index f508863e77..37ab1c1fe0 100644 --- a/ssa_detections/endpoint/ssa___disable_net_user_account.yml +++ b/ssa_detections/endpoint/ssa___disable_net_user_account.yml @@ -37,9 +37,7 @@ tags: - XMRig - Ransomware asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 70 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. diff --git a/ssa_detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml b/ssa_detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml index 304bfa585e..40442b4664 100644 --- a/ssa_detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml +++ b/ssa_detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml @@ -42,9 +42,7 @@ tags: - Data Exfiltration - Command and Control asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 90 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related @@ -86,6 +84,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-security.log + source: WinEventLog:Security diff --git a/ssa_detections/endpoint/ssa___excessive_number_of_office_files_copied.yml b/ssa_detections/endpoint/ssa___excessive_number_of_office_files_copied.yml index 67453cc3e6..41d2c55ae1 100644 --- a/ssa_detections/endpoint/ssa___excessive_number_of_office_files_copied.yml +++ b/ssa_detections/endpoint/ssa___excessive_number_of_office_files_copied.yml @@ -28,9 +28,7 @@ tags: analytic_story: - Insider Threat asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 90 message: High number of files copied mitre_attack_id: diff --git a/ssa_detections/endpoint/ssa___first_time_seen_command_line_argument.yml b/ssa_detections/endpoint/ssa___first_time_seen_command_line_argument.yml index b250a0831f..98595a59a2 100644 --- a/ssa_detections/endpoint/ssa___first_time_seen_command_line_argument.yml +++ b/ssa_detections/endpoint/ssa___first_time_seen_command_line_argument.yml @@ -43,9 +43,7 @@ tags: analytic_story: - Unusual Processes asset_type: Endpoint - atomic_guid: [] confidence: 60 - drilldown_search: [] impact: 50 message: A process $process_name$ ha been identified in the environment with a command-line $cmd_line$ not previously seen before on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___fsutil_zeroing_file.yml b/ssa_detections/endpoint/ssa___fsutil_zeroing_file.yml index ae12ac3fc8..9117683be4 100644 --- a/ssa_detections/endpoint/ssa___fsutil_zeroing_file.yml +++ b/ssa_detections/endpoint/ssa___fsutil_zeroing_file.yml @@ -36,9 +36,7 @@ tags: - Insider Threat - Information Sabotage asset_type: Endpoint - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 60 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file @@ -80,6 +78,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-security.log + source: WinEventLog:Security diff --git a/ssa_detections/endpoint/ssa___grant_permission_using_cacls_utility.yml b/ssa_detections/endpoint/ssa___grant_permission_using_cacls_utility.yml index 4d4e9d1fa4..6334de9ed1 100644 --- a/ssa_detections/endpoint/ssa___grant_permission_using_cacls_utility.yml +++ b/ssa_detections/endpoint/ssa___grant_permission_using_cacls_utility.yml @@ -35,9 +35,7 @@ tags: - XMRig - Insider Threat asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 50 message: A cacls process $process_name$ with commandline $cmd_line$ try to grant user a permission to a file or directory in host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml b/ssa_detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml index aa1c0cfc56..231023330b 100644 --- a/ssa_detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml +++ b/ssa_detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml @@ -38,9 +38,7 @@ tags: - Information Sabotage - Insider Threat asset_type: Endpoint - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 80 message: Attrib.exe with +h flag to hide files on $dest$ executed by $user$ is detected. mitre_attack_id: @@ -71,6 +69,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/attrib_hidden/security.log + source: WinEventLog:Security diff --git a/ssa_detections/endpoint/ssa___high_file_deletion_frequency.yml b/ssa_detections/endpoint/ssa___high_file_deletion_frequency.yml index 24c8733b8b..e6ae267a71 100644 --- a/ssa_detections/endpoint/ssa___high_file_deletion_frequency.yml +++ b/ssa_detections/endpoint/ssa___high_file_deletion_frequency.yml @@ -36,9 +36,7 @@ tags: - Clop Ransomware - Insider Threat asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 90 message: High frequency file deletion activity detected on host $Computer$ mitre_attack_id: diff --git a/ssa_detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml b/ssa_detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml index 94029f0d71..6c79a8886a 100644 --- a/ssa_detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml +++ b/ssa_detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml @@ -38,9 +38,7 @@ tags: analytic_story: - XMRig asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 50 message: A cacls process $process_name$ with commandline $cmd_line$ try to modify a permission of a file or directory in host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___office_product_spawning_windows_script_host.yml b/ssa_detections/endpoint/ssa___office_product_spawning_windows_script_host.yml index ec3a04598a..0112949f59 100644 --- a/ssa_detections/endpoint/ssa___office_product_spawning_windows_script_host.yml +++ b/ssa_detections/endpoint/ssa___office_product_spawning_windows_script_host.yml @@ -36,9 +36,7 @@ tags: analytic_story: - Spearphishing Attachments asset_type: Endpoint - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 70 message: A Microsoft office parent process $parent_process_name$ has spawned a suspicious child process $process_name$ on host $dest$. @@ -79,7 +77,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.002/atomic_red_team/windows-security.log + source: XmlWinEventLog update_timestamp: true diff --git a/ssa_detections/endpoint/ssa___rare_parent_child_process_relationship.yml b/ssa_detections/endpoint/ssa___rare_parent_child_process_relationship.yml index a9289cd407..21b45567e8 100644 --- a/ssa_detections/endpoint/ssa___rare_parent_child_process_relationship.yml +++ b/ssa_detections/endpoint/ssa___rare_parent_child_process_relationship.yml @@ -61,9 +61,7 @@ tags: analytic_story: - Unusual Processes asset_type: Endpoint - atomic_guid: [] confidence: 50 - drilldown_search: [] impact: 50 message: Rare Parent-Child Process Relationship mitre_attack_id: diff --git a/ssa_detections/endpoint/ssa___resize_shadowstorage_volume.yml b/ssa_detections/endpoint/ssa___resize_shadowstorage_volume.yml index 7c0bf451e2..6fa651a428 100644 --- a/ssa_detections/endpoint/ssa___resize_shadowstorage_volume.yml +++ b/ssa_detections/endpoint/ssa___resize_shadowstorage_volume.yml @@ -37,9 +37,7 @@ tags: - Clop Ransomware - Ransomware asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow diff --git a/ssa_detections/endpoint/ssa___sdelete_application_execution.yml b/ssa_detections/endpoint/ssa___sdelete_application_execution.yml index 596d43c515..bb16931acb 100644 --- a/ssa_detections/endpoint/ssa___sdelete_application_execution.yml +++ b/ssa_detections/endpoint/ssa___sdelete_application_execution.yml @@ -47,9 +47,7 @@ tags: - Information Sabotage - Insider Threat asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 60 message: Sdelete process $process_name$ executed on $dest_device_id$ attempting to permanently delete files by $dest_user_id$. @@ -94,6 +92,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log + source: WinEventLog:Security diff --git a/ssa_detections/endpoint/ssa___system_process_running_from_unexpected_location.yml b/ssa_detections/endpoint/ssa___system_process_running_from_unexpected_location.yml index bce5522505..fe61bcc993 100644 --- a/ssa_detections/endpoint/ssa___system_process_running_from_unexpected_location.yml +++ b/ssa_detections/endpoint/ssa___system_process_running_from_unexpected_location.yml @@ -237,9 +237,7 @@ tags: - Windows Defense Evasion Tactics - Masquerading - Rename System Utilities asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 70 message: A system process $process_name$ with commandline $cmd_line$ spawn in non-default folder path in host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___unified_messaging_service_spawning_a_process.yml b/ssa_detections/endpoint/ssa___unified_messaging_service_spawning_a_process.yml index e5d67c3178..f97e8d6494 100644 --- a/ssa_detections/endpoint/ssa___unified_messaging_service_spawning_a_process.yml +++ b/ssa_detections/endpoint/ssa___unified_messaging_service_spawning_a_process.yml @@ -39,11 +39,9 @@ tags: - ProxyShell - ProxyNotShell asset_type: Endpoint - atomic_guid: [] confidence: 80 cve: - CVE-2021-26857 - drilldown_search: [] impact: 70 message: Possible CVE-2021-26857 exploitation on $dest$ mitre_attack_id: diff --git a/ssa_detections/endpoint/ssa___wbadmin_delete_system_backups.yml b/ssa_detections/endpoint/ssa___wbadmin_delete_system_backups.yml index 50289a974a..d395c52c9a 100644 --- a/ssa_detections/endpoint/ssa___wbadmin_delete_system_backups.yml +++ b/ssa_detections/endpoint/ssa___wbadmin_delete_system_backups.yml @@ -36,9 +36,7 @@ tags: - Ryuk Ransomware - Ransomware asset_type: Endpoint - atomic_guid: [] confidence: 50 - drilldown_search: [] impact: 30 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system diff --git a/ssa_detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml b/ssa_detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml index 336875400e..cac469e2c2 100644 --- a/ssa_detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml +++ b/ssa_detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml @@ -41,9 +41,7 @@ tags: - Insider Threat - CISA AA22-264A asset_type: Endpoint - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 70 message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear event logs in host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml b/ssa_detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml index df0a3910f6..d316aa8939 100644 --- a/ssa_detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml +++ b/ssa_detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml @@ -37,9 +37,7 @@ tags: - Insider Threat - Information Sabotage asset_type: Endpoint - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 70 message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable event logs in host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_bits_job_persistence.yml b/ssa_detections/endpoint/ssa___windows_bits_job_persistence.yml index f7abf62937..496a73d2fd 100644 --- a/ssa_detections/endpoint/ssa___windows_bits_job_persistence.yml +++ b/ssa_detections/endpoint/ssa___windows_bits_job_persistence.yml @@ -46,9 +46,7 @@ tags: - BITS Jobs - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 70 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $dest_user_id$ attempting to persist using BITS. diff --git a/ssa_detections/endpoint/ssa___windows_bitsadmin_download_file.yml b/ssa_detections/endpoint/ssa___windows_bitsadmin_download_file.yml index e2e4b18207..6a6685e38c 100644 --- a/ssa_detections/endpoint/ssa___windows_bitsadmin_download_file.yml +++ b/ssa_detections/endpoint/ssa___windows_bitsadmin_download_file.yml @@ -49,9 +49,7 @@ tags: - DarkSide Ransomware - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 70 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $dest_user_id$ attempting to download a file. diff --git a/ssa_detections/endpoint/ssa___windows_certutil_decode_file.yml b/ssa_detections/endpoint/ssa___windows_certutil_decode_file.yml index 27c633dfff..7a1fdc8714 100644 --- a/ssa_detections/endpoint/ssa___windows_certutil_decode_file.yml +++ b/ssa_detections/endpoint/ssa___windows_certutil_decode_file.yml @@ -44,9 +44,7 @@ tags: - Deobfuscate-Decode Files or Information - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 50 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to decode a file diff --git a/ssa_detections/endpoint/ssa___windows_certutil_urlcache_download.yml b/ssa_detections/endpoint/ssa___windows_certutil_urlcache_download.yml index a791f9fe81..fb1bc6ed42 100644 --- a/ssa_detections/endpoint/ssa___windows_certutil_urlcache_download.yml +++ b/ssa_detections/endpoint/ssa___windows_certutil_urlcache_download.yml @@ -41,9 +41,7 @@ tags: - DarkSide Ransomware - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 90 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to download a file. diff --git a/ssa_detections/endpoint/ssa___windows_certutil_verifyctl_download.yml b/ssa_detections/endpoint/ssa___windows_certutil_verifyctl_download.yml index fa02e18214..d4835f865a 100644 --- a/ssa_detections/endpoint/ssa___windows_certutil_verifyctl_download.yml +++ b/ssa_detections/endpoint/ssa___windows_certutil_verifyctl_download.yml @@ -42,9 +42,7 @@ tags: - DarkSide Ransomware - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 90 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to download a file. diff --git a/ssa_detections/endpoint/ssa___windows_com_hijacking_inprocserver32_modification.yml b/ssa_detections/endpoint/ssa___windows_com_hijacking_inprocserver32_modification.yml index f1ab2e96fe..8a71eb73d2 100644 --- a/ssa_detections/endpoint/ssa___windows_com_hijacking_inprocserver32_modification.yml +++ b/ssa_detections/endpoint/ssa___windows_com_hijacking_inprocserver32_modification.yml @@ -39,9 +39,7 @@ tags: analytic_story: - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ has spawned $process_name$ attempting to modify InProcServer32 within the registry on $dest_device_id$ by $dest_user_id$. diff --git a/ssa_detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml b/ssa_detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml index 04af506d57..ba98881411 100644 --- a/ssa_detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml +++ b/ssa_detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml @@ -54,9 +54,7 @@ tags: - Ingress Tool Transfer - Insider Threat asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote diff --git a/ssa_detections/endpoint/ssa___windows_defender_tools_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_defender_tools_in_non_standard_path.yml index a0a309f342..58e0b16ec1 100644 --- a/ssa_detections/endpoint/ssa___windows_defender_tools_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_defender_tools_in_non_standard_path.yml @@ -30,9 +30,7 @@ tags: analytic_story: - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 70 message: Process $process_name$ with commandline $cmd_line$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml b/ssa_detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml index 6fdb575019..e28ef7f3d2 100644 --- a/ssa_detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml +++ b/ssa_detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml @@ -36,9 +36,7 @@ tags: analytic_story: - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 70 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to run a script. diff --git a/ssa_detections/endpoint/ssa___windows_dotnet_binary_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_dotnet_binary_in_non_standard_path.yml index 827d56be04..7450b937ec 100644 --- a/ssa_detections/endpoint/ssa___windows_dotnet_binary_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_dotnet_binary_in_non_standard_path.yml @@ -61,9 +61,7 @@ tags: - Signed Binary Proxy Execution InstallUtil - WhisperGate asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 70 message: A system process $process_name$ with commandline $cmd_line$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_eventvwr_uac_bypass.yml b/ssa_detections/endpoint/ssa___windows_eventvwr_uac_bypass.yml index 5f10b2a513..97d07cf119 100644 --- a/ssa_detections/endpoint/ssa___windows_eventvwr_uac_bypass.yml +++ b/ssa_detections/endpoint/ssa___windows_eventvwr_uac_bypass.yml @@ -43,9 +43,7 @@ tags: - IcedID - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 80 message: Registry values were modified to bypass UAC using Event Viewer on $dest_device_id$ mitre_attack_id: diff --git a/ssa_detections/endpoint/ssa___windows_exchange_powershell_module_usage.yml b/ssa_detections/endpoint/ssa___windows_exchange_powershell_module_usage.yml index b9e1722d4f..23fa85b0f9 100644 --- a/ssa_detections/endpoint/ssa___windows_exchange_powershell_module_usage.yml +++ b/ssa_detections/endpoint/ssa___windows_exchange_powershell_module_usage.yml @@ -61,9 +61,7 @@ tags: - ProxyShell - CISA AA22-264A asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 40 message: Exchange enumeration using PowerShell on $dest_device_id$. mitre_attack_id: diff --git a/ssa_detections/endpoint/ssa___windows_execute_arbitrary_commands_with_msdt.yml b/ssa_detections/endpoint/ssa___windows_execute_arbitrary_commands_with_msdt.yml index 150dde16ae..b02949e250 100644 --- a/ssa_detections/endpoint/ssa___windows_execute_arbitrary_commands_with_msdt.yml +++ b/ssa_detections/endpoint/ssa___windows_execute_arbitrary_commands_with_msdt.yml @@ -44,11 +44,9 @@ tags: analytic_story: - Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190 asset_type: Endpoint - atomic_guid: [] confidence: 100 cve: - CVE-2022-30190 - drilldown_search: [] impact: 100 message: $process_name$ on $dest_device_id$ under user $dest_user_id$ possibly indicative of indirect command execution. diff --git a/ssa_detections/endpoint/ssa___windows_ingress_tool_transfer_using_explorer.yml b/ssa_detections/endpoint/ssa___windows_ingress_tool_transfer_using_explorer.yml index 6a6022d284..99d63d8cd5 100644 --- a/ssa_detections/endpoint/ssa___windows_ingress_tool_transfer_using_explorer.yml +++ b/ssa_detections/endpoint/ssa___windows_ingress_tool_transfer_using_explorer.yml @@ -39,9 +39,7 @@ tags: analytic_story: - DarkCrystal RAT asset_type: Endpoint - atomic_guid: [] confidence: 50 - drilldown_search: [] impact: 50 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to access a remote diff --git a/ssa_detections/endpoint/ssa___windows_lolbin_binary_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_lolbin_binary_in_non_standard_path.yml index 64a62e71cf..8628e09910 100644 --- a/ssa_detections/endpoint/ssa___windows_lolbin_binary_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_lolbin_binary_in_non_standard_path.yml @@ -70,9 +70,7 @@ tags: - Ransomware - WhisperGate asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 70 message: A system process $process_name$ with commandline $cmd_line$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_mshta_child_process.yml b/ssa_detections/endpoint/ssa___windows_mshta_child_process.yml index 65fbd449ab..bf034303b7 100644 --- a/ssa_detections/endpoint/ssa___windows_mshta_child_process.yml +++ b/ssa_detections/endpoint/ssa___windows_mshta_child_process.yml @@ -40,9 +40,7 @@ tags: - Suspicious MSHTA Activity - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to access a remote diff --git a/ssa_detections/endpoint/ssa___windows_mshta_command_line_url.yml b/ssa_detections/endpoint/ssa___windows_mshta_command_line_url.yml index 0c85a948e5..627d9dc69f 100644 --- a/ssa_detections/endpoint/ssa___windows_mshta_command_line_url.yml +++ b/ssa_detections/endpoint/ssa___windows_mshta_command_line_url.yml @@ -42,9 +42,7 @@ tags: - Suspicious MSHTA Activity - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to access a remote diff --git a/ssa_detections/endpoint/ssa___windows_mshta_inline_hta_execution.yml b/ssa_detections/endpoint/ssa___windows_mshta_inline_hta_execution.yml index b021707d18..4aaf805038 100644 --- a/ssa_detections/endpoint/ssa___windows_mshta_inline_hta_execution.yml +++ b/ssa_detections/endpoint/ssa___windows_mshta_inline_hta_execution.yml @@ -40,9 +40,7 @@ tags: - Suspicious MSHTA Activity - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ executing with inline HTA, diff --git a/ssa_detections/endpoint/ssa___windows_odbcconf_load_response_file.yml b/ssa_detections/endpoint/ssa___windows_odbcconf_load_response_file.yml index 5d275e2a7c..57f4a466ad 100644 --- a/ssa_detections/endpoint/ssa___windows_odbcconf_load_response_file.yml +++ b/ssa_detections/endpoint/ssa___windows_odbcconf_load_response_file.yml @@ -37,9 +37,7 @@ tags: analytic_story: - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 60 message: $process_name$ has been identified on $dest_device_id$ under user $dest_user_id$ attempting to circumvent controls. diff --git a/ssa_detections/endpoint/ssa___windows_os_credential_dumping_with_ntdsutil_export_ntds.yml b/ssa_detections/endpoint/ssa___windows_os_credential_dumping_with_ntdsutil_export_ntds.yml index 31e9106511..b0abdf00f9 100644 --- a/ssa_detections/endpoint/ssa___windows_os_credential_dumping_with_ntdsutil_export_ntds.yml +++ b/ssa_detections/endpoint/ssa___windows_os_credential_dumping_with_ntdsutil_export_ntds.yml @@ -47,9 +47,7 @@ tags: - HAFNIUM Group - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 50 - drilldown_search: [] impact: 100 message: Active Directory NTDS export on $dest_device_id$ using $process_name$ by $dest_user_id$. diff --git a/ssa_detections/endpoint/ssa___windows_os_credential_dumping_with_procdump.yml b/ssa_detections/endpoint/ssa___windows_os_credential_dumping_with_procdump.yml index 4ef6094637..93670c0d2f 100644 --- a/ssa_detections/endpoint/ssa___windows_os_credential_dumping_with_procdump.yml +++ b/ssa_detections/endpoint/ssa___windows_os_credential_dumping_with_procdump.yml @@ -44,9 +44,7 @@ tags: - Credential Dumping - HAFNIUM Group asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 80 message: Procdump was utilized to dump lsass on $dest_device_id$ by $dest_user_id$. mitre_attack_id: diff --git a/ssa_detections/endpoint/ssa___windows_powershell_connect_to_internet_with_hidden_window.yml b/ssa_detections/endpoint/ssa___windows_powershell_connect_to_internet_with_hidden_window.yml index 8e94ee4ea2..e993e7f93a 100644 --- a/ssa_detections/endpoint/ssa___windows_powershell_connect_to_internet_with_hidden_window.yml +++ b/ssa_detections/endpoint/ssa___windows_powershell_connect_to_internet_with_hidden_window.yml @@ -49,9 +49,7 @@ tags: - HAFNIUM Group - Log4Shell CVE-2021-44228 asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 50 message: PowerShell processes $process$ started with parameters to modify the execution policy of the run, run in a hidden window, and connect to the Internet on host diff --git a/ssa_detections/endpoint/ssa___windows_powershell_disabled_kerberos_pre_authentication_discovery_get_aduser.yml b/ssa_detections/endpoint/ssa___windows_powershell_disabled_kerberos_pre_authentication_discovery_get_aduser.yml index 2dae6375ca..53f6a0e5bb 100644 --- a/ssa_detections/endpoint/ssa___windows_powershell_disabled_kerberos_pre_authentication_discovery_get_aduser.yml +++ b/ssa_detections/endpoint/ssa___windows_powershell_disabled_kerberos_pre_authentication_discovery_get_aduser.yml @@ -39,9 +39,7 @@ tags: analytic_story: - Active Directory Kerberos Attacks asset_type: Endpoint - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 60 message: Disabled Kerberos Pre-Authentication Discovery With Get-ADUser from $dest_device_id$ mitre_attack_id: diff --git a/ssa_detections/endpoint/ssa___windows_powershell_disabled_kerberos_pre_authentication_discovery_with_powerview.yml b/ssa_detections/endpoint/ssa___windows_powershell_disabled_kerberos_pre_authentication_discovery_with_powerview.yml index 86861919c4..327575f1b4 100644 --- a/ssa_detections/endpoint/ssa___windows_powershell_disabled_kerberos_pre_authentication_discovery_with_powerview.yml +++ b/ssa_detections/endpoint/ssa___windows_powershell_disabled_kerberos_pre_authentication_discovery_with_powerview.yml @@ -38,9 +38,7 @@ tags: analytic_story: - Active Directory Kerberos Attacks asset_type: endpoint - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 60 message: Disabled Kerberos Pre-Authentication Discovery With PowerView from $dest_device_id$ mitre_attack_id: diff --git a/ssa_detections/endpoint/ssa___windows_powershell_downloadfile.yml b/ssa_detections/endpoint/ssa___windows_powershell_downloadfile.yml index 9434b03f58..6bf9f2958a 100644 --- a/ssa_detections/endpoint/ssa___windows_powershell_downloadfile.yml +++ b/ssa_detections/endpoint/ssa___windows_powershell_downloadfile.yml @@ -43,9 +43,7 @@ tags: - Ingress Tool Transfer - Log4Shell CVE-2021-44228 asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 50 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadFile diff --git a/ssa_detections/endpoint/ssa___windows_powershell_start_bitstransfer.yml b/ssa_detections/endpoint/ssa___windows_powershell_start_bitstransfer.yml index b563c16494..e441b85ca8 100644 --- a/ssa_detections/endpoint/ssa___windows_powershell_start_bitstransfer.yml +++ b/ssa_detections/endpoint/ssa___windows_powershell_start_bitstransfer.yml @@ -41,9 +41,7 @@ tags: - BITS Jobs - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 70 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $dest_user_id$ attempting to download a file. diff --git a/ssa_detections/endpoint/ssa___windows_rasautou_dll_execution.yml b/ssa_detections/endpoint/ssa___windows_rasautou_dll_execution.yml index 6ae1b3cedf..5c246d54eb 100644 --- a/ssa_detections/endpoint/ssa___windows_rasautou_dll_execution.yml +++ b/ssa_detections/endpoint/ssa___windows_rasautou_dll_execution.yml @@ -40,9 +40,7 @@ tags: - Windows Defense Evasion Tactics - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ attempting to load a DLL in a suspicious manner. diff --git a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_acccheckconsole_exe_lolbas_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_acccheckconsole_exe_lolbas_in_non_standard_path.yml index 9e119f973b..405bbffa4d 100644 --- a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_acccheckconsole_exe_lolbas_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_acccheckconsole_exe_lolbas_in_non_standard_path.yml @@ -36,9 +36,7 @@ tags: - Unusual Processes - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 20 message: A system process $process_name$ with path $process_path$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_adplus_exe_lolbas_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_adplus_exe_lolbas_in_non_standard_path.yml index d04f582bdb..99e9038644 100644 --- a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_adplus_exe_lolbas_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_adplus_exe_lolbas_in_non_standard_path.yml @@ -36,9 +36,7 @@ tags: - Unusual Processes - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 20 message: A system process $process_name$ with path $process_path$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_advpack_dll_lolbas_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_advpack_dll_lolbas_in_non_standard_path.yml index cbae163b10..f4f2648881 100644 --- a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_advpack_dll_lolbas_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_advpack_dll_lolbas_in_non_standard_path.yml @@ -35,9 +35,7 @@ tags: - Unusual Processes - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 20 message: A system process $process_name$ with path $process_path$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_agentexecutor_exe_lolbas_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_agentexecutor_exe_lolbas_in_non_standard_path.yml index 7775ca999d..81eae7c5f9 100644 --- a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_agentexecutor_exe_lolbas_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_agentexecutor_exe_lolbas_in_non_standard_path.yml @@ -35,9 +35,7 @@ tags: - Unusual Processes - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 20 message: A system process $process_name$ with path $process_path$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_appinstaller_exe_lolbas_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_appinstaller_exe_lolbas_in_non_standard_path.yml index 97529350b4..23f867f58d 100644 --- a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_appinstaller_exe_lolbas_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_appinstaller_exe_lolbas_in_non_standard_path.yml @@ -36,9 +36,7 @@ tags: - Unusual Processes - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 20 message: A system process $process_name$ with path $process_path$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_appvlp_exe_lolbas_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_appvlp_exe_lolbas_in_non_standard_path.yml index 4b16f3125d..adb093a4c3 100644 --- a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_appvlp_exe_lolbas_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_appvlp_exe_lolbas_in_non_standard_path.yml @@ -36,9 +36,7 @@ tags: - Unusual Processes - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 20 message: A system process $process_name$ with path $process_path$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_aspnet_compiler_exe_lolbas_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_aspnet_compiler_exe_lolbas_in_non_standard_path.yml index 51658a5302..b6942ae04f 100644 --- a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_aspnet_compiler_exe_lolbas_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_aspnet_compiler_exe_lolbas_in_non_standard_path.yml @@ -36,9 +36,7 @@ tags: - Unusual Processes - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 20 message: A system process $process_name$ with path $process_path$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_at_exe_lolbas_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_at_exe_lolbas_in_non_standard_path.yml index 4ab2ca2b33..55626bcc2e 100644 --- a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_at_exe_lolbas_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_at_exe_lolbas_in_non_standard_path.yml @@ -35,9 +35,7 @@ tags: - Unusual Processes - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 20 message: A system process $process_name$ with path $process_path$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_atbroker_exe_lolbas_in_non_standard_path.yml b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_atbroker_exe_lolbas_in_non_standard_path.yml index 12b65fbe1e..7a9513a0fd 100644 --- a/ssa_detections/endpoint/ssa___windows_rename_system_utilities_atbroker_exe_lolbas_in_non_standard_path.yml +++ b/ssa_detections/endpoint/ssa___windows_rename_system_utilities_atbroker_exe_lolbas_in_non_standard_path.yml @@ -35,9 +35,7 @@ tags: - Unusual Processes - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 20 message: A system process $process_name$ with path $process_path$ spawn in non-default folder path on host $dest_device_id$ diff --git a/ssa_detections/endpoint/ssa___windows_rundll32_comsvcs_memory_dump.yml b/ssa_detections/endpoint/ssa___windows_rundll32_comsvcs_memory_dump.yml index 24c37f8318..017228dede 100644 --- a/ssa_detections/endpoint/ssa___windows_rundll32_comsvcs_memory_dump.yml +++ b/ssa_detections/endpoint/ssa___windows_rundll32_comsvcs_memory_dump.yml @@ -32,9 +32,7 @@ tags: - Credential Dumping - Suspicious Rundll32 Activity asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 40 message: A dump of a process was attempted using comsvcs.dll with the minidump function on endpoint $dest_device_id$ by user $dest_device_user$. diff --git a/ssa_detections/endpoint/ssa___windows_rundll32_inline_hta_execution.yml b/ssa_detections/endpoint/ssa___windows_rundll32_inline_hta_execution.yml index 0aea57e9d0..d3956a79c0 100644 --- a/ssa_detections/endpoint/ssa___windows_rundll32_inline_hta_execution.yml +++ b/ssa_detections/endpoint/ssa___windows_rundll32_inline_hta_execution.yml @@ -43,9 +43,7 @@ tags: - NOBELIUM Group - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 80 - drilldown_search: [] impact: 70 message: Suspicious $process_name$ inline HTA execution on $dest_device_id$. mitre_attack_id: diff --git a/ssa_detections/endpoint/ssa___windows_script_host_spawn_msbuild.yml b/ssa_detections/endpoint/ssa___windows_script_host_spawn_msbuild.yml index efad2b8f1d..6f3f77d63a 100644 --- a/ssa_detections/endpoint/ssa___windows_script_host_spawn_msbuild.yml +++ b/ssa_detections/endpoint/ssa___windows_script_host_spawn_msbuild.yml @@ -40,9 +40,7 @@ tags: - Trusted Developer Utilities Proxy Execution MSBuild - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$. diff --git a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_decompile.yml b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_decompile.yml index 41c0508b24..03b0ee38ee 100644 --- a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_decompile.yml +++ b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_decompile.yml @@ -39,9 +39,7 @@ tags: - Suspicious Compiled HTML Activity - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 100 message: $process_name$ has been identified using decompile against a CHM on $dest_device_id$ under user $dest_user_id$. diff --git a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_url_in_command_line.yml b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_url_in_command_line.yml index 58c8fe350b..0ae998f0f8 100644 --- a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_url_in_command_line.yml +++ b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_url_in_command_line.yml @@ -48,9 +48,7 @@ tags: - Suspicious Compiled HTML Activity - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 90 message: An instance of $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ contacting a remote destination. diff --git a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_using_infotech_storage_handlers.yml b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_using_infotech_storage_handlers.yml index 6ef40e81db..18749be1b5 100644 --- a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_using_infotech_storage_handlers.yml +++ b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_using_infotech_storage_handlers.yml @@ -51,9 +51,7 @@ tags: - Suspicious Compiled HTML Activity - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 80 message: $process_name$ has been identified using Infotech Storage Handlers to load a specific file within a CHM on $dest_device_id$ under user $dest_user_id$. diff --git a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_dllregisterserver.yml b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_dllregisterserver.yml index 2d91db0da0..69f3e0d9e5 100644 --- a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_dllregisterserver.yml +++ b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_dllregisterserver.yml @@ -35,9 +35,7 @@ tags: analytic_story: - Windows System Binary Proxy Execution MSIExec asset_type: Endpoint - atomic_guid: [] confidence: 50 - drilldown_search: [] impact: 70 message: An instance of spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to register a file. diff --git a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_remote_download.yml b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_remote_download.yml index 838f78f87e..0cff3d5528 100644 --- a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_remote_download.yml +++ b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_remote_download.yml @@ -35,9 +35,7 @@ tags: analytic_story: - Windows System Binary Proxy Execution MSIExec asset_type: Endpoint - atomic_guid: [] confidence: 50 - drilldown_search: [] impact: 70 message: An instance of spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to download a file. diff --git a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_unregister_dll.yml b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_unregister_dll.yml index 28bc9d016e..30c2cc3bb4 100644 --- a/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_unregister_dll.yml +++ b/ssa_detections/endpoint/ssa___windows_system_binary_proxy_execution_msiexec_unregister_dll.yml @@ -35,9 +35,7 @@ tags: analytic_story: - Windows System Binary Proxy Execution MSIExec asset_type: Endpoint - atomic_guid: [] confidence: 50 - drilldown_search: [] impact: 70 message: An instance of spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to unregister a DLL. diff --git a/ssa_detections/endpoint/ssa___windows_wmiprvse_spawn_msbuild.yml b/ssa_detections/endpoint/ssa___windows_wmiprvse_spawn_msbuild.yml index f1b8748669..61683a69bf 100644 --- a/ssa_detections/endpoint/ssa___windows_wmiprvse_spawn_msbuild.yml +++ b/ssa_detections/endpoint/ssa___windows_wmiprvse_spawn_msbuild.yml @@ -41,9 +41,7 @@ tags: - Trusted Developer Utilities Proxy Execution MSBuild - Living Off The Land asset_type: Endpoint - atomic_guid: [] confidence: 100 - drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$. diff --git a/ssa_detections/endpoint/ssa___windows_wsreset_uac_bypass.yml b/ssa_detections/endpoint/ssa___windows_wsreset_uac_bypass.yml index ebad2c64f6..3534547052 100644 --- a/ssa_detections/endpoint/ssa___windows_wsreset_uac_bypass.yml +++ b/ssa_detections/endpoint/ssa___windows_wsreset_uac_bypass.yml @@ -40,9 +40,7 @@ tags: - Living Off The Land - Windows Defense Evasion Tactics asset_type: Endpoint - atomic_guid: [] confidence: 90 - drilldown_search: [] impact: 70 message: tbd mitre_attack_id: diff --git a/ssa_detections/network/ssa___tcp_command_and_scripting_interpreter_outbound_ldap_traffic.yml b/ssa_detections/network/ssa___tcp_command_and_scripting_interpreter_outbound_ldap_traffic.yml index 03e54fedde..98b6bb0700 100644 --- a/ssa_detections/network/ssa___tcp_command_and_scripting_interpreter_outbound_ldap_traffic.yml +++ b/ssa_detections/network/ssa___tcp_command_and_scripting_interpreter_outbound_ldap_traffic.yml @@ -36,9 +36,7 @@ tags: analytic_story: - Log4Shell CVE-2021-44228 asset_type: endpoint - atomic_guid: [] confidence: 70 - drilldown_search: [] impact: 50 message: An outbound LDAP connection from $src_ip$ in your infrastructure connecting to dest ip $dest_ip$ diff --git a/ssa_detections/network/ssa___unusual_volume_of_data_download_from_internal_server_per_entity.yml b/ssa_detections/network/ssa___unusual_volume_of_data_download_from_internal_server_per_entity.yml index 2e083d3c86..d3bb528f7e 100644 --- a/ssa_detections/network/ssa___unusual_volume_of_data_download_from_internal_server_per_entity.yml +++ b/ssa_detections/network/ssa___unusual_volume_of_data_download_from_internal_server_per_entity.yml @@ -40,9 +40,7 @@ tags: analytic_story: - Insider Threat asset_type: endpoint - atomic_guid: [] confidence: 50 - drilldown_search: [] impact: 50 message: $src_device_ip downloaded unusually amount of data from internal server within one day