From 494f7593b90cce7497b8d2a93a85176de7c9f61c Mon Sep 17 00:00:00 2001 From: tccontre Date: Mon, 12 Dec 2022 19:00:28 +0100 Subject: [PATCH] cisa-top-malware-mitre-coverage --- ...AgentTesla_sec_content_mitre_coverage.json | 157 +++++++++++ .../Azorult_sec_content_mitre_coverage.json | 247 ++++++++++++++++++ .../Qakbot_sec_content_mitre_coverage.json | 237 +++++++++++++++++ .../Remcos_sec_content_mitre_coverage.json | 182 +++++++++++++ .../Trickbot_sec_content_mitre_coverage.json | 142 ++++++++++ 5 files changed, 965 insertions(+) create mode 100644 docs/mitre-map/cisa-2021-top-malware-coverage/AgentTesla_sec_content_mitre_coverage.json create mode 100644 docs/mitre-map/cisa-2021-top-malware-coverage/Azorult_sec_content_mitre_coverage.json create mode 100644 docs/mitre-map/cisa-2021-top-malware-coverage/Qakbot_sec_content_mitre_coverage.json create mode 100644 docs/mitre-map/cisa-2021-top-malware-coverage/Remcos_sec_content_mitre_coverage.json create mode 100644 docs/mitre-map/cisa-2021-top-malware-coverage/Trickbot_sec_content_mitre_coverage.json diff --git a/docs/mitre-map/cisa-2021-top-malware-coverage/AgentTesla_sec_content_mitre_coverage.json b/docs/mitre-map/cisa-2021-top-malware-coverage/AgentTesla_sec_content_mitre_coverage.json new file mode 100644 index 0000000000..5288a81e14 --- /dev/null +++ b/docs/mitre-map/cisa-2021-top-malware-coverage/AgentTesla_sec_content_mitre_coverage.json @@ -0,0 +1,157 @@ +{ + "version": "4.3", + "name": "AgentTesla Detection Coverage", + "description": "security_content detection coverage for AgentTesla", + "domain": "mitre-enterprise", + "techniques": [ + { + "techniqueID": "T1562.001", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml" + }, + { + "techniqueID": "T1562", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml" + }, + { + "techniqueID": "T1566.001", + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml" + }, + { + "techniqueID": "T1566", + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml" + }, + { + "techniqueID": "T1204.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml" + }, + { + "techniqueID": "T1204", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml" + }, + { + "techniqueID": "T1071.003", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml" + }, + { + "techniqueID": "T1071", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_multi_hop_proxy_tor_website_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_mail_protocol_in_non_common_process_path.yml" + }, + { + "techniqueID": "T1014", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_drivers_loaded_by_signature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_driver_load_non_standard_path.yml" + }, + { + "techniqueID": "T1068", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_drivers_loaded_by_signature.yml" + }, + { + "techniqueID": "T1059", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml" + }, + { + "techniqueID": "T1059.001", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml" + }, + { + "techniqueID": "T1548.002", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml" + }, + { + "techniqueID": "T1548", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml" + }, + { + "techniqueID": "T1543.003", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml" + }, + { + "techniqueID": "T1543", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_file_path.yml" + }, + { + "techniqueID": "T1555", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml" + }, + { + "techniqueID": "T1555.003", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml" + }, + { + "techniqueID": "T1053.005", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml" + }, + { + "techniqueID": "T1053", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml" + }, + { + "techniqueID": "T1218", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml" + }, + { + "techniqueID": "T1218.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml" + }, + { + "techniqueID": "T1036", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml" + } + ], + "gradient": { + "colors": [ + "#ffffff", + "#66b1ff", + "#096ed7" + ], + "minValue": 0, + "maxValue": 5 + }, + "filters": { + "platforms": [ + "Windows", + "Linux", + "macOS", + "AWS", + "GCP", + "Azure", + "Office 365", + "SaaS" + ] + }, + "legendItems": [ + { + "label": "NO available detections", + "color": "#ffffff" + }, + { + "label": "Some detections available", + "color": "#66b1ff" + } + ], + "showTacticRowBackground": true, + "tacticRowBackground": "#dddddd", + "sorting": 3 +} \ No newline at end of file diff --git a/docs/mitre-map/cisa-2021-top-malware-coverage/Azorult_sec_content_mitre_coverage.json b/docs/mitre-map/cisa-2021-top-malware-coverage/Azorult_sec_content_mitre_coverage.json new file mode 100644 index 0000000000..aeb5904c4b --- /dev/null +++ b/docs/mitre-map/cisa-2021-top-malware-coverage/Azorult_sec_content_mitre_coverage.json @@ -0,0 +1,247 @@ +{ + "version": "4.3", + "name": "Azorult Detection Coverage", + "description": "security_content detection coverage for Azorult", + "domain": "mitre-enterprise", + "techniques": [ + { + "techniqueID": "T1021.001", + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_remote_assistance.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_rdp_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" + }, + { + "techniqueID": "T1021", + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_remote_assistance.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_rdp_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" + }, + { + "techniqueID": "T1489", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_stop_by_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_valid_account_with_never_expires_password.yml" + }, + { + "techniqueID": "T1219", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_access_software_rms_registry.yml" + }, + { + "techniqueID": "T1566.001", + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml" + }, + { + "techniqueID": "T1566", + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml" + }, + { + "techniqueID": "T1204.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml" + }, + { + "techniqueID": "T1204", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml" + }, + { + "techniqueID": "T1562.001", + "score": 14, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml" + }, + { + "techniqueID": "T1562", + "score": 16, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml" + }, + { + "techniqueID": "T1562.004", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml" + }, + { + "techniqueID": "T1222", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + }, + { + "techniqueID": "T1548", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_operation_with_consent_admin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml" + }, + { + "techniqueID": "T1112", + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_regedit_silent_reg_import.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_win_defender_raw_write_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disallow_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_suppress_win_defender_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_windows_security_center_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_toast_notifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disabling_wer_settings.yml" + }, + { + "techniqueID": "T1053.005", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml" + }, + { + "techniqueID": "T1053", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml" + }, + { + "techniqueID": "T1136.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml" + }, + { + "techniqueID": "T1136", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml" + }, + { + "techniqueID": "T1059.003", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml" + }, + { + "techniqueID": "T1059", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml" + }, + { + "techniqueID": "T1531", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_net_app.yml" + }, + { + "techniqueID": "T1548.002", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml" + }, + { + "techniqueID": "T1049", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml" + }, + { + "techniqueID": "T1543.003", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml" + }, + { + "techniqueID": "T1543", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml" + }, + { + "techniqueID": "T1555", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" + }, + { + "techniqueID": "T1555.003", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" + }, + { + "techniqueID": "T1590.005", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml" + }, + { + "techniqueID": "T1590", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml" + }, + { + "techniqueID": "T1569", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml" + }, + { + "techniqueID": "T1569.002", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml" + }, + { + "techniqueID": "T1059.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_import_applocker_policy.yml" + }, + { + "techniqueID": "T1564.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" + }, + { + "techniqueID": "T1564", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" + }, + { + "techniqueID": "T1036", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml" + }, + { + "techniqueID": "T1071", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_application_layer_protocol_rms_radmin_tool_namedpipe.yml" + }, + { + "techniqueID": "T1222.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" + }, + { + "techniqueID": "T1069", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml" + }, + { + "techniqueID": "T1069.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml" + }, + { + "techniqueID": "T1547.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml" + }, + { + "techniqueID": "T1547", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml" + } + ], + "gradient": { + "colors": [ + "#ffffff", + "#66b1ff", + "#096ed7" + ], + "minValue": 0, + "maxValue": 5 + }, + "filters": { + "platforms": [ + "Windows", + "Linux", + "macOS", + "AWS", + "GCP", + "Azure", + "Office 365", + "SaaS" + ] + }, + "legendItems": [ + { + "label": "NO available detections", + "color": "#ffffff" + }, + { + "label": "Some detections available", + "color": "#66b1ff" + } + ], + "showTacticRowBackground": true, + "tacticRowBackground": "#dddddd", + "sorting": 3 +} \ No newline at end of file diff --git a/docs/mitre-map/cisa-2021-top-malware-coverage/Qakbot_sec_content_mitre_coverage.json b/docs/mitre-map/cisa-2021-top-malware-coverage/Qakbot_sec_content_mitre_coverage.json new file mode 100644 index 0000000000..b01749d4ed --- /dev/null +++ b/docs/mitre-map/cisa-2021-top-malware-coverage/Qakbot_sec_content_mitre_coverage.json @@ -0,0 +1,237 @@ +{ + "version": "4.3", + "name": "Qakbot Detection Coverage", + "description": "security_content detection coverage for Qakbot", + "domain": "mitre-enterprise", + "techniques": [ + { + "techniqueID": "T1055", + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_remote_thread.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_shell_fetch_env_variables.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_wermgr_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml" + }, + { + "techniqueID": "T1055.002", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_remote_thread.yml" + }, + { + "techniqueID": "T1033", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_discovery_using_qwinsta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_discovery_using_ldap_nslookup.yml" + }, + { + "techniqueID": "T1566.001", + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml" + }, + { + "techniqueID": "T1566", + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml" + }, + { + "techniqueID": "T1204.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml" + }, + { + "techniqueID": "T1204", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml" + }, + { + "techniqueID": "T1059", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml" + }, + { + "techniqueID": "T1049", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml" + }, + { + "techniqueID": "T1059.007", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml" + }, + { + "techniqueID": "T1047", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_wmi_process_call_create.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_wmi_impersonate_token.yml" + }, + { + "techniqueID": "T1218", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_regsvr32_renamed_binary.yml" + }, + { + "techniqueID": "T1218.010", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_regsvr32_renamed_binary.yml" + }, + { + "techniqueID": "T1574.002", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_masquerading_explorer_as_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_in_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml" + }, + { + "techniqueID": "T1574", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_masquerading_explorer_as_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_in_calc.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml" + }, + { + "techniqueID": "T1053", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_run_task_on_demand.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_schtasks_create_run_as_system.yml" + }, + { + "techniqueID": "T1016", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_discovery_using_route_windows_app.yml" + }, + { + "techniqueID": "T1016.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_discovery_using_route_windows_app.yml" + }, + { + "techniqueID": "T1027", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml" + }, + { + "techniqueID": "T1592", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recon_using_wmi_class.yml" + }, + { + "techniqueID": "T1562.001", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml" + }, + { + "techniqueID": "T1562", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml" + }, + { + "techniqueID": "T1059.003", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml" + }, + { + "techniqueID": "T1059.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recon_using_wmi_class.yml" + }, + { + "techniqueID": "T1071", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_app_layer_protocol_qakbot_namedpipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_app_layer_protocol_wermgr_connect_to_namedpipe.yml" + }, + { + "techniqueID": "T1569", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_created_with_suspicious_service_path.yml" + }, + { + "techniqueID": "T1569.002", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_created_with_suspicious_service_path.yml" + }, + { + "techniqueID": "T1036", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_copy_on_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml" + }, + { + "techniqueID": "T1036.003", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_copy_on_system32.yml" + }, + { + "techniqueID": "T1543", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml" + }, + { + "techniqueID": "T1543.003", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml" + }, + { + "techniqueID": "T1053.005", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_schtasks_create_run_as_system.yml" + }, + { + "techniqueID": "T1055.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml" + }, + { + "techniqueID": "T1566.002", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" + }, + { + "techniqueID": "T1482", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml" + }, + { + "techniqueID": "T1112", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_qakbot_binary_data_registry.yml" + }, + { + "techniqueID": "T1574.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml" + }, + { + "techniqueID": "T1547.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml" + }, + { + "techniqueID": "T1547", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml" + } + ], + "gradient": { + "colors": [ + "#ffffff", + "#66b1ff", + "#096ed7" + ], + "minValue": 0, + "maxValue": 5 + }, + "filters": { + "platforms": [ + "Windows", + "Linux", + "macOS", + "AWS", + "GCP", + "Azure", + "Office 365", + "SaaS" + ] + }, + "legendItems": [ + { + "label": "NO available detections", + "color": "#ffffff" + }, + { + "label": "Some detections available", + "color": "#66b1ff" + } + ], + "showTacticRowBackground": true, + "tacticRowBackground": "#dddddd", + "sorting": 3 +} \ No newline at end of file diff --git a/docs/mitre-map/cisa-2021-top-malware-coverage/Remcos_sec_content_mitre_coverage.json b/docs/mitre-map/cisa-2021-top-malware-coverage/Remcos_sec_content_mitre_coverage.json new file mode 100644 index 0000000000..74f966f398 --- /dev/null +++ b/docs/mitre-map/cisa-2021-top-malware-coverage/Remcos_sec_content_mitre_coverage.json @@ -0,0 +1,182 @@ +{ + "version": "4.3", + "name": "Remcos Detection Coverage", + "description": "security_content detection coverage for Remcos", + "domain": "mitre-enterprise", + "techniques": [ + { + "techniqueID": "T1562.001", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml" + }, + { + "techniqueID": "T1562", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml" + }, + { + "techniqueID": "T1059.005", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml" + }, + { + "techniqueID": "T1059", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml" + }, + { + "techniqueID": "T1566.001", + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml" + }, + { + "techniqueID": "T1566", + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_phishing_recent_iso_exec_registry.yml" + }, + { + "techniqueID": "T1204.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml" + }, + { + "techniqueID": "T1204", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml" + }, + { + "techniqueID": "T1113", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml" + }, + { + "techniqueID": "T1218", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml" + }, + { + "techniqueID": "T1218.010", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_inprocserver32_modification.yml" + }, + { + "techniqueID": "T1055", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/loading_of_dynwrapx_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winhlp32_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml" + }, + { + "techniqueID": "T1055.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/loading_of_dynwrapx_module.yml" + }, + { + "techniqueID": "T1555.003", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_browser_pass_view_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml" + }, + { + "techniqueID": "T1555", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_browser_pass_view_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml" + }, + { + "techniqueID": "T1112", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_client_registry_install_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_inprocserver32_modification.yml" + }, + { + "techniqueID": "T1070", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml" + }, + { + "techniqueID": "T1548.002", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml" + }, + { + "techniqueID": "T1548", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml" + }, + { + "techniqueID": "T1543", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml" + }, + { + "techniqueID": "T1059.007", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" + }, + { + "techniqueID": "T1592", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_info_gathering_using_dxdiag_application.yml" + }, + { + "techniqueID": "T1559.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml" + }, + { + "techniqueID": "T1036", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml" + }, + { + "techniqueID": "T1134.004", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml" + }, + { + "techniqueID": "T1134", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml" + }, + { + "techniqueID": "T1547.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml" + }, + { + "techniqueID": "T1547", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml" + } + ], + "gradient": { + "colors": [ + "#ffffff", + "#66b1ff", + "#096ed7" + ], + "minValue": 0, + "maxValue": 5 + }, + "filters": { + "platforms": [ + "Windows", + "Linux", + "macOS", + "AWS", + "GCP", + "Azure", + "Office 365", + "SaaS" + ] + }, + "legendItems": [ + { + "label": "NO available detections", + "color": "#ffffff" + }, + { + "label": "Some detections available", + "color": "#66b1ff" + } + ], + "showTacticRowBackground": true, + "tacticRowBackground": "#dddddd", + "sorting": 3 +} \ No newline at end of file diff --git a/docs/mitre-map/cisa-2021-top-malware-coverage/Trickbot_sec_content_mitre_coverage.json b/docs/mitre-map/cisa-2021-top-malware-coverage/Trickbot_sec_content_mitre_coverage.json new file mode 100644 index 0000000000..1bec6602d3 --- /dev/null +++ b/docs/mitre-map/cisa-2021-top-malware-coverage/Trickbot_sec_content_mitre_coverage.json @@ -0,0 +1,142 @@ +{ + "version": "4.3", + "name": "Trickbot Detection Coverage", + "description": "security_content detection coverage for Trickbot", + "domain": "mitre-enterprise", + "techniques": [ + { + "techniqueID": "T1027", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" + }, + { + "techniqueID": "T1059", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" + }, + { + "techniqueID": "T1590", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" + }, + { + "techniqueID": "T1590.005", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" + }, + { + "techniqueID": "T1218", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml" + }, + { + "techniqueID": "T1218.005", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml" + }, + { + "techniqueID": "T1566", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml" + }, + { + "techniqueID": "T1566.001", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml" + }, + { + "techniqueID": "T1055", + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml" + }, + { + "techniqueID": "T1543", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_file_path.yml" + }, + { + "techniqueID": "T1053", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/schedule_task_with_rundll32_command_trigger.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml" + }, + { + "techniqueID": "T1562.001", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml" + }, + { + "techniqueID": "T1562", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml" + }, + { + "techniqueID": "T1053.005", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml" + }, + { + "techniqueID": "T1087.002", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml" + }, + { + "techniqueID": "T1087", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml" + }, + { + "techniqueID": "T1218.011", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml" + }, + { + "techniqueID": "T1021", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executable_file_written_in_administrative_smb_share.yml" + }, + { + "techniqueID": "T1021.002", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executable_file_written_in_administrative_smb_share.yml" + }, + { + "techniqueID": "T1036", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml" + } + ], + "gradient": { + "colors": [ + "#ffffff", + "#66b1ff", + "#096ed7" + ], + "minValue": 0, + "maxValue": 5 + }, + "filters": { + "platforms": [ + "Windows", + "Linux", + "macOS", + "AWS", + "GCP", + "Azure", + "Office 365", + "SaaS" + ] + }, + "legendItems": [ + { + "label": "NO available detections", + "color": "#ffffff" + }, + { + "label": "Some detections available", + "color": "#66b1ff" + } + ], + "showTacticRowBackground": true, + "tacticRowBackground": "#dddddd", + "sorting": 3 +} \ No newline at end of file