Branch was auto-updated.

This commit is contained in:
pyth0n1c
2022-09-02 19:15:30 -04:00
committed by GitHub
14 changed files with 2051 additions and 105 deletions
+1 -1
View File
@@ -5,7 +5,7 @@
"id": {
"group": null,
"name": "DA-ESS-ContentUpdate",
"version": "3.47.0"
"version": "3.48.0"
},
"author": [
{
+286 -16
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2022-08-16T16:13:51 UTC
# On Date: 2022-08-29T17:38:30 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -527,6 +527,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp
known_false_positives = Legitimate users may miss to reply the MFA challenge within the time window or deny it by mistake.
providing_technologies = null
[savedsearch://ESCU - Azure AD Multi-Factor Authentication Disabled - Rule]
type = detection
asset_type = Azure Active Directory
confidence = medium
explanation = The following analytic identifies an attempt to disable multi-factor authentication for an Azure AD user. An adversary who has obtained access to an Azure AD tenant may disable multi-factor authentication as a way to plant a backdoor and maintain persistence using a valid account. This way the attackers can keep persistance in the environment without adding new users.
how_to_implement = You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase(https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment. Specifically, this analytic leverages the AuditLogs log category.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "mitre_attack": ["T1556"], "nist": ["DE.CM"]}
known_false_positives = Legitimate use case may require for users to disable MFA. Filter as needed.
providing_technologies = null
[savedsearch://ESCU - Azure AD Multiple Users Failing To Authenticate From Ip - Rule]
type = detection
asset_type = Azure Active Directory
@@ -4387,12 +4397,32 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp
known_false_positives = Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux apt-get Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = The apt-get is a command line tool for interacting with the Advanced Package Tool (APT) library (a package management system for Linux distributions). It allows you to search for, install, manage, update, and remove software. The tool does not build software from the source code. If sudo right is given to the tool for user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux APT Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = Advanced Package Tool, more commonly known as APT, is a collection of tools used to install, update, remove, and otherwise manage software packages on Debian and its derivative operating systems, including Ubuntu and Linux Mint. If sudo right is given to the tool for user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux At Allow Config File Creation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = The following analytic identifies a suspicious file creation of /etc/at.allow or /etc/at.deny. These 2 files are commonly abused by malware, adversaries or red teamers to persist on the targeted or compromised host. These config files can restrict or allow user to execute "at" application (another schedule task application in linux). attacker can create a user or add the compromised username to that config file to execute "at" to schedule it malicious code. This anomaly detection can be a good indicator to investigate further the entry in created config file and who created it to verify if it is a false positive.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the file name, file path, and process_guid executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the file name, file path, and process_guid executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.003", "T1053"], "nist": ["DE.CM"]}
known_false_positives = Administrator or network operator can create this file for automation purposes. Please update the filter macros to remove false positives.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
@@ -4402,7 +4432,7 @@ type = detection
asset_type = Endpoint
confidence = medium
explanation = The following analytic identifies a suspicious process creation of At application. This process can be used by malware, adversaries and red teamers to create persistence entry to the targeted or compromised host with their malicious code. This anomaly detection can be a good indicator to investigate the event before and after this process execution, when it was executed and what schedule task it will execute.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1053.002", "T1053"], "nist": ["DE.CM"]}
known_false_positives = Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
@@ -4412,11 +4442,41 @@ type = detection
asset_type = Endpoint
confidence = medium
explanation = Awk is mostly used for processing and scanning patterns. It checks one or more files to determine whether any lines fit the specified patterns, and if so, it does the appropriate action. If sudo right is given to AWK binary for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives are present based on automated tooling or system administrative usage. Filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Busybox Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = BusyBox combines tiny versions of many common UNIX utilities into a single small executable. It provides minimalist replacements for most of the utilities you usually find in GNU coreutils, util-linux, etc. If sudo right is given to BusyBox application for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux c89 Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = The c89 and cc commands compile, assemble, and link-edit C programs; the cxx or c++ command does the same for C++ programs. The c89 command should be used when compiling C programs that are written according to Standard C. If sudo right is given to c89 application for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux c99 Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = The c99 utility is an interface to the standard C compilation system; it shall accept source code conforming to the ISO C standard. The system conceptually consists of a compiler and link editor. If sudo right is given to ruby application for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Change File Owner To Root - Rule]
type = detection
asset_type = Endpoint
@@ -4447,6 +4507,36 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp
known_false_positives = Administrator or network operator can execute this command. Please update the filter macros to remove false positives.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Composer Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = Composer is a tool for dependency management in PHP. It allows you to declare the libraries your project depends on and it will manage (install/update) them for you. If sudo right is given to tool for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Cpulimit Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = cpulimit is a simple program which attempts to limit the cpu usage of a process (expressed in percentage, not in cpu time). This is useful to control batch jobs, when you don't want them to eat too much cpu. If sudo right is given to the program for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Csvtool Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = csvtool is an easy to use command-line tool to work with .CSV files. If sudo right is given to the tool for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Curl Upload File - Rule]
type = detection
asset_type = Endpoint
@@ -4562,7 +4652,7 @@ type = detection
asset_type = Endpoint
confidence = medium
explanation = Docker is an open source containerization platform. It helps programmers to bundle applications into containers, which are standardized executable parts that include the application source code along with the OS libraries and dependencies needed to run that code in any setting. The user can add mount the root directory into a container and edit the /etc/password file to add a super user. This requires the user to be privileged enough to run docker, i.e. being in the docker group or being root.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives are present based on automated tooling or system administrative usage. Filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
@@ -4577,6 +4667,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp
known_false_positives = Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Emacs Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = EMACS is a family of text editors that are characterized by their extensibility. The manual for the most widely used variant, GNU Emacs, describes it as "the extensible, customizable, self-documenting, real-time display editor". If sudo right is given to EMACS tool for the user, then the user can run special commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux File Created In Kernel Driver Directory - Rule]
type = detection
asset_type = Endpoint
@@ -4607,6 +4707,46 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp
known_false_positives = Administrator or network operator can create file in profile.d folders for automation purposes. Please update the filter macros to remove false positives.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Find Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = Find is a command-line utility that locates files based on some user-specified criteria and either prints the pathname of each matched object or, if another action is requested, performs that action on each matched object. If sudo right is given to find utility for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives are present based on automated tooling or system administrative usage. Filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux GDB Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = GDB is the acronym for GNU Debugger. This tool helps to debug the programs written in C, C++, Ada, Fortran, etc. The console can be opened using the gdb command on terminal. If sudo right is given to GDB tool for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Gem Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = RubyGems is a package manager for the Ruby programming language that provides a standard format for distributing Ruby programs and libraries (in a self-contained format called a "gem"), a tool designed to easily manage the installation of gems, and a server for distributing them. If sudo right is given to GEM utility for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux GNU Awk Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = gawk command in Linux is used for pattern scanning and processing language. The awk command requires no compiling and allows the user to use variables, numeric functions, string functions, and logical operators. It is a utility that enables programmers to write tiny and effective programs in the form of statements that define text patterns that are to be searched for, in a text document and the action that is to be taken when a match is found within a line. If sudo right is given to gawk tool for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux High Frequency Of File Deletion In Boot Folder - Rule]
type = detection
asset_type = endpoint
@@ -4707,12 +4847,32 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp
known_false_positives = unknown
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Make Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = The Linux make command is used to build and maintain groups of programs and files from the source code. In Linux, it is one of the most frequently used commands by the developers. It assists developers to install and compile many utilities from the terminal. If sudo right is given to make utility for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux MySQL Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = MySQL is an open-source relational database management system. Its name is a combination of "My", the name of co-founder Michael Widenius's daughter My, and "SQL", the abbreviation for Structured Query Language. If sudo right is given to mysql utility for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives are present based on automated tooling or system administrative usage. Filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Node Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = Node.js is a back-end JavaScript runtime environment that is open-source, cross-platform, runs on the V8 engine, and executes JavaScript code outside of a web browser. It was created to help create scalable network applications. If the binary is allowed to run as superuser by sudo, it does not drop the elevated privileges and may be used to access the file system, escalate or maintain privileged access.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives are present based on automated tooling or system administrative usage. Filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
@@ -4737,6 +4897,26 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Del
known_false_positives = False positives may be present and will require some tuning based on processes. Filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Octave Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = GNU Octave is a high-level programming language primarily intended for scientific computing and numerical computation. Octave helps in solving linear and nonlinear problems numerically, and for performing other numerical experiments using a language that is mostly compatible with MATLAB. If sudo right is given to the application for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux OpenVPN Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = OpenVPN is a virtual private network system that implements techniques to create secure point-to-point or site-to-site connections in routed or bridged configurations and remote access facilities. It implements both client and server applications. If sudo right is given to the OpenVPN application for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Persistence and Privilege Escalation Risk Behavior - Rule]
type = detection
asset_type = Endpoint
@@ -4747,6 +4927,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp
known_false_positives = False positives will be present based on many factors. Tune the correlation as needed to reduce too many triggers.
providing_technologies = null
[savedsearch://ESCU - Linux PHP Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = PHP is a general-purpose scripting language geared toward web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1994. The PHP reference implementation is now produced by The PHP Group. If sudo right is given to php application for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux pkexec Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
@@ -4857,6 +5047,36 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Del
known_false_positives = False positives may be present based on proxy usage internally. Filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Puppet Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = In computing, Puppet is a software configuration management tool which includes its own declarative language to describe system configuration. It is a model-driven solution that requires limited programming knowledge to use. If sudo right is given to the tool for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux RPM Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = RPM Package Manager is a free and open-source package management system. The name RPM refers to the .rpm file format and the package manager program itself. RPM was intended primarily for Linux distributions; the file format is the baseline package format of the Linux Standard Base. If sudo right is given to rpm utility for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives are present based on automated tooling or system administrative usage. Filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Ruby Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = Ruby is one of the most used and easy to use programming languages. Ruby is an open-source, object-oriented interpreter that can be installed on a Linux system. If sudo right is given to ruby application for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives are present based on automated tooling or system administrative usage. Filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Service File Created In Systemd Directory - Rule]
type = detection
asset_type = Endpoint
@@ -4917,6 +5137,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp
known_false_positives = Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux Sqlite3 Privilege Escalation - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = sqlite3 is a terminal-based front-end to the SQLite library that can evaluate queries interactively and display the results in multiple formats. sqlite3 can also be used within shell scripts and other applications to provide batch processing features. If sudo right is given to this application for the user, then the user can run system commands as root and possibly get a root shell.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1548.003", "T1548"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present, filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Linux SSH Authorized Keys Modification - Rule]
type = detection
asset_type = Endpoint
@@ -6306,7 +6536,7 @@ providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response"
type = detection
asset_type = Endpoint
confidence = medium
explanation = This analytic identifies the suspicious Remote Thread execution of rundll32.exe process to cmd.exe process. This technique was seen in IcedID malware to execute its malicious code in normal process for defense evasion and to steal sensitive information the the compromised host. browser process.
explanation = This analytic identifies the suspicious Remote Thread execution of rundll32.exe to any process. This technique was seen in IcedID malware to execute its malicious code in normal process for defense evasion and to steal sensitive information in the compromised host.
how_to_implement = To successfully implement this search, you need to be ingesting logs with the SourceImage, TargetImage, and EventCode executions from your endpoints related to create remote thread or injecting codes. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1055"]}
known_false_positives = unknown
@@ -7409,6 +7639,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exp
known_false_positives = False positives may be present. Filter based on pipe name or process.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Windows Autostart Execution LSASS Driver Registry Modification - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = The following analytic identifies the abuse of two undocumented registry keys that allow for a DLL to load into lsass.exe to potentially capture credentials. Upon successful modification of \CurrentControlSet\Services\NTDS\DirectoryServiceExtPt or \CurrentControlSet\Services\NTDS\LsaDbExtPt, a DLL either remote or local will be set as the value and load up into lsass.exe. Based on POC code a text file may be written to disk with credentials.
how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1547.008"], "nist": ["DE.CM"]}
known_false_positives = False positives may be present on recent Windows Operating Systems. Filtering may be required based on process_name. In addition, look for non-standard, unsigned, module loads into LSASS. If query is too noisy, modify by adding Endpoint.processes process_name to query to identify the process making the modification.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Windows Binary Proxy Execution Mavinject DLL Injection - Rule]
type = detection
asset_type = Endpoint
@@ -7648,6 +7888,26 @@ annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1562.00
known_false_positives = Some legitimate administrative tools leverage `dism.exe` to manipulate packages and features of the operating system. Filter as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Windows DLL Search Order Hijacking Hunt - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = The following hunting analytic is an experimental query built against a accidental feature using the latest Sysmon TA 3.0 (https://splunkbase.splunk.com/app/5709/) which maps the module load (ImageLoaded) to process_name. This analytic will deprecate once this is fixed. This hunting analytic identifies known libraries in Windows that may be used in a DLL search order hijack or DLL Sideloading setting. This may require recompiling the DLL, moving the DLL or moving the vulnerable process. The query looks for any running out of system32 or syswow64. Some libraries natively run out of other application paths and will need to be added to the exclusion as needed. The lookup is comprised of Microsoft native libraries identified within the Hijacklibs.net project.
how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. This may only with with Sysmon data and the Sysmon TA. Your mileage may vary.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1574.001", "T1574"], "nist": ["DE.CM"]}
known_false_positives = False positives will be present based on paths. Filter or add other paths to the exclusion as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Windows DLL Search Order Hijacking Hunt with Sysmon - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = The following hunting analytic is an experimental query built against a accidental feature using the latest Sysmon TA 3.0 (https://splunkbase.splunk.com/app/5709/) which maps the module load (ImageLoaded) to process_name. This analytic will deprecate once this is fixed. This hunting analytic identifies known libraries in Windows that may be used in a DLL search order hijack or DLL Sideloading setting. This may require recompiling the DLL, moving the DLL or moving the vulnerable process. The query looks for any running out of system32 or syswow64. Some libraries natively run out of other application paths and will need to be added to the exclusion as needed. The lookup is comprised of Microsoft native libraries identified within the Hijacklibs.net project.
how_to_implement = The latest Sysmon TA 3.0 https://splunkbase.splunk.com/app/5709 will add the ImageLoaded name to the process_name field, allowing this query to work. Use as an example and implement for other products.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1574.001", "T1574"], "nist": ["DE.CM"]}
known_false_positives = False positives will be present based on paths. Filter or add other paths to the exclusion as needed.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Windows DLL Search Order Hijacking with iscsicpl - Rule]
type = detection
asset_type = Endpoint
@@ -8392,6 +8652,16 @@ annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1547.00
known_false_positives = updated windows application needed in safe boot may used this registry
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Windows Remote Access Software Hunt - Rule]
type = detection
asset_type = Endpoint
confidence = medium
explanation = The following hunting analytic is meant to help organizations understand what remote access software is being used in the environment. When reviewing this hunt, confirm the software identified is authorized to be utilized. Based on fidelity, create a new analytic for specific utilities banned within the organization. Adversaries use these utilities to retain remote access capabilities to the environment. Utilities in the lookup include AnyDesk, GoToMyPC, LogMeIn, TeamViewer and much more. Review the lookup for the entire list and add any others.
how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Command \u0026 Control"], "mitre_attack": ["T1219"], "nist": ["DE.CM"]}
known_false_positives = False positives will be found. Filter as needed and create higher fidelity analytics based off banned remote access software.
providing_technologies = ["Sysmon", "Microsoft Windows", "Carbon Black Response", "CrowdStrike Falcon", "Symantec Endpoint Protection"]
[savedsearch://ESCU - Windows Remote Access Software RMS Registry - Rule]
type = detection
asset_type = Endpoint
@@ -10276,7 +10546,7 @@ version = 2
references = ["https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-whatis", "https://azure.microsoft.com/en-us/services/active-directory/#overview", "https://attack.mitre.org/techniques/T1586/", "https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-compare-azure-ad-to-ad", "https://www.imperva.com/learn/application-security/account-takeover-ato/", "https://www.varonis.com/blog/azure-active-directory", "https://www.barracuda.com/glossary/account-takeover"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Mauricio Velazco"}]
spec_version = 3
searches = ["ESCU - Azure Active Directory High Risk Sign-in - Rule", "ESCU - Azure AD Authentication Failed During MFA Challenge - Rule", "ESCU - Azure AD Multiple Users Failing To Authenticate From Ip - Rule", "ESCU - Azure AD Successful PowerShell Authentication - Rule", "ESCU - Azure AD Successful Single-Factor Authentication - Rule", "ESCU - Azure AD Unusual Number of Failed Authentications From Ip - Rule"]
searches = ["ESCU - Azure Active Directory High Risk Sign-in - Rule", "ESCU - Azure AD Authentication Failed During MFA Challenge - Rule", "ESCU - Azure AD Multi-Factor Authentication Disabled - Rule", "ESCU - Azure AD Multiple Users Failing To Authenticate From Ip - Rule", "ESCU - Azure AD Successful PowerShell Authentication - Rule", "ESCU - Azure AD Successful Single-Factor Authentication - Rule", "ESCU - Azure AD Unusual Number of Failed Authentications From Ip - Rule"]
description = Monitor for activities and techniques associated with Account Takover attacks against Azure Active Directory tenants.
narrative = Azure Active Directory (Azure AD) is Microsofts enterprise cloud-based identity and access management (IAM) service. Azure AD is the backbone of most of Azure services like Office 365. It can sync with on-premise Active Directory environments and provide authentication to other cloud-based systems via the OAuth protocol. According to Microsoft, Azure AD manages more than 1.2 billion identities and processes over 8 billion authentications per day.\ Account Takeover (ATO) is an attack whereby cybercriminals gain unauthorized access to online accounts by using different techniques like brute force, social engineering, phishing & spear phishing, credential stuffing, etc. By posing as the real user, cyber-criminals can change account details, send out phishing emails, steal financial information or sensitive data, or use any stolen information to access further accounts within the organization.\ This analytic storic groups detections that can help security operations teams identify the potential compromise of Azure Active Directory accounts.
@@ -10404,7 +10674,7 @@ version = 1
references = ["https://attack.mitre.org/wiki/Command_and_Control", "https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
spec_version = 3
searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - DNS Exfiltration Using Nslookup App - Rule", "ESCU - Excessive Usage of NSLOOKUP App - Rule", "ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Detect Large Outbound ICMP Packets - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Multiple Archive Files Http Post Traffic - Rule", "ESCU - Plain HTTP POST Exfiltrated Data - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"]
searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - DNS Exfiltration Using Nslookup App - Rule", "ESCU - Excessive Usage of NSLOOKUP App - Rule", "ESCU - Windows Remote Access Software Hunt - Rule", "ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Detect Large Outbound ICMP Packets - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Multiple Archive Files Http Post Traffic - Rule", "ESCU - Plain HTTP POST Exfiltrated Data - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"]
description = Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators.
narrative = Threat actors typically architect and implement an infrastructure to use in various ways during the course of their attack campaigns. In some cases, they leverage this infrastructure for scanning and performing reconnaissance activities. In others, they may use this infrastructure to launch actual attacks. One of the most important functions of this infrastructure is to establish servers that will communicate with implants on compromised endpoints. These servers establish a command and control channel that is used to proxy data between the compromised endpoint and the attacker. These channels relay commands from the attacker to the compromised endpoint and the output of those commands back to the attacker.\
Because this communication is so critical for an adversary, they often use techniques designed to hide the true nature of the communications. There are many different techniques used to establish and communicate over these channels. This Analytic Story provides searches that look for a variety of the techniques used for these channels, as well as indications that these channels are active, by examining logs associated with border control devices and network-access control lists.
@@ -10891,7 +11161,7 @@ version = 1
references = ["https://www.imperva.com/learn/application-security/insider-threats/", "https://www.cisa.gov/defining-insider-threats", "https://www.code42.com/glossary/types-of-insider-threats/", "https://github.com/Insider-Threat/Insider-Threat", "https://ctid.mitre-engenuity.org/our-work/insider-ttp-kb/"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Jose Hernandez"}]
spec_version = 3
searches = ["ESCU - Gsuite Drive Share In External Email - Rule", "ESCU - Gsuite Outbound Email With Attachment To External Domain - Rule", "ESCU - High Frequency Copy Of Files In Network Share - Rule", "ESCU - Multiple Users Failing To Authenticate From Process - Rule", "ESCU - Potential password in username - Rule", "ESCU - Windows Users Authenticate Using Explicit Credentials - Rule"]
searches = ["ESCU - Gsuite Drive Share In External Email - Rule", "ESCU - Gsuite Outbound Email With Attachment To External Domain - Rule", "ESCU - High Frequency Copy Of Files In Network Share - Rule", "ESCU - Multiple Users Failing To Authenticate From Process - Rule", "ESCU - Potential password in username - Rule", "ESCU - Windows Remote Access Software Hunt - Rule", "ESCU - Windows Users Authenticate Using Explicit Credentials - Rule"]
description = Monitor for activities and techniques associated with insider threats and specifically focusing on malicious insiders operating with in a corporate environment.
narrative = Insider Threats are best defined by CISA: "Insider threat incidents are possible in any sector or organization. An insider threat is typically a current or former employee, third-party contractor, or business partner. In their present or former role, the person has or had access to an organization's network systems, data, or premises, and uses their access (sometimes unwittingly). To combat the insider threat, organizations can implement a proactive, prevention-focused mitigation program to detect and identify threats, assess risk, and manage that risk - before an incident occurs." An insider is any person who has or had authorized access to or knowledge of an organization's resources, including personnel, facilities, information, equipment, networks, and systems. These are the common insiders that create insider threats: Departing Employees, Security Evaders, Malicious Insiders, and Negligent Employees. This story aims at detecting the malicious insider.
@@ -10949,7 +11219,7 @@ version = 1
references = ["https://gtfobins.github.io/"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}]
spec_version = 3
searches = ["ESCU - Curl Download and Bash Execution - Rule", "ESCU - Linux Add Files In Known Crontab Directories - Rule", "ESCU - Linux Adding Crontab Using List Parameter - Rule", "ESCU - Linux At Allow Config File Creation - Rule", "ESCU - Linux At Application Execution - Rule", "ESCU - Linux AWK Privilege Escalation - Rule", "ESCU - Linux Change File Owner To Root - Rule", "ESCU - Linux Clipboard Data Copy - Rule", "ESCU - Linux Common Process For Elevation Control - Rule", "ESCU - Linux Curl Upload File - Rule", "ESCU - Linux Decode Base64 to Shell - Rule", "ESCU - Linux Docker Privilege Escalation - Rule", "ESCU - Linux Edit Cron Table Parameter - Rule", "ESCU - Linux Ingress Tool Transfer Hunting - Rule", "ESCU - Linux Ingress Tool Transfer with Curl - Rule", "ESCU - Linux Node Privilege Escalation - Rule", "ESCU - Linux Obfuscated Files or Information Base64 Decode - Rule", "ESCU - Linux pkexec Privilege Escalation - Rule", "ESCU - Linux Possible Access Or Modification Of sshd Config File - Rule", "ESCU - Linux Possible Append Cronjob Entry on Existing Cronjob File - Rule", "ESCU - Linux Possible Cronjob Modification With Editor - Rule", "ESCU - Linux Possible Ssh Key File Creation - Rule", "ESCU - Linux Proxy Socks Curl - Rule", "ESCU - Linux Service File Created In Systemd Directory - Rule", "ESCU - Linux Service Restarted - Rule", "ESCU - Linux Service Started Or Enabled - Rule", "ESCU - Linux Setuid Using Chmod Utility - Rule", "ESCU - Linux SSH Authorized Keys Modification - Rule", "ESCU - Linux SSH Remote Services Script Execute - Rule", "ESCU - Suspicious Curl Network Connection - Rule"]
searches = ["ESCU - Curl Download and Bash Execution - Rule", "ESCU - Linux Add Files In Known Crontab Directories - Rule", "ESCU - Linux Adding Crontab Using List Parameter - Rule", "ESCU - Linux apt-get Privilege Escalation - Rule", "ESCU - Linux APT Privilege Escalation - Rule", "ESCU - Linux At Allow Config File Creation - Rule", "ESCU - Linux At Application Execution - Rule", "ESCU - Linux AWK Privilege Escalation - Rule", "ESCU - Linux Busybox Privilege Escalation - Rule", "ESCU - Linux c89 Privilege Escalation - Rule", "ESCU - Linux c99 Privilege Escalation - Rule", "ESCU - Linux Change File Owner To Root - Rule", "ESCU - Linux Clipboard Data Copy - Rule", "ESCU - Linux Common Process For Elevation Control - Rule", "ESCU - Linux Composer Privilege Escalation - Rule", "ESCU - Linux Cpulimit Privilege Escalation - Rule", "ESCU - Linux Csvtool Privilege Escalation - Rule", "ESCU - Linux Curl Upload File - Rule", "ESCU - Linux Decode Base64 to Shell - Rule", "ESCU - Linux Docker Privilege Escalation - Rule", "ESCU - Linux Edit Cron Table Parameter - Rule", "ESCU - Linux Emacs Privilege Escalation - Rule", "ESCU - Linux Find Privilege Escalation - Rule", "ESCU - Linux GDB Privilege Escalation - Rule", "ESCU - Linux Gem Privilege Escalation - Rule", "ESCU - Linux GNU Awk Privilege Escalation - Rule", "ESCU - Linux Ingress Tool Transfer Hunting - Rule", "ESCU - Linux Ingress Tool Transfer with Curl - Rule", "ESCU - Linux Make Privilege Escalation - Rule", "ESCU - Linux MySQL Privilege Escalation - Rule", "ESCU - Linux Node Privilege Escalation - Rule", "ESCU - Linux Obfuscated Files or Information Base64 Decode - Rule", "ESCU - Linux Octave Privilege Escalation - Rule", "ESCU - Linux OpenVPN Privilege Escalation - Rule", "ESCU - Linux PHP Privilege Escalation - Rule", "ESCU - Linux pkexec Privilege Escalation - Rule", "ESCU - Linux Possible Access Or Modification Of sshd Config File - Rule", "ESCU - Linux Possible Append Cronjob Entry on Existing Cronjob File - Rule", "ESCU - Linux Possible Cronjob Modification With Editor - Rule", "ESCU - Linux Possible Ssh Key File Creation - Rule", "ESCU - Linux Proxy Socks Curl - Rule", "ESCU - Linux Puppet Privilege Escalation - Rule", "ESCU - Linux RPM Privilege Escalation - Rule", "ESCU - Linux Ruby Privilege Escalation - Rule", "ESCU - Linux Service File Created In Systemd Directory - Rule", "ESCU - Linux Service Restarted - Rule", "ESCU - Linux Service Started Or Enabled - Rule", "ESCU - Linux Setuid Using Chmod Utility - Rule", "ESCU - Linux Sqlite3 Privilege Escalation - Rule", "ESCU - Linux SSH Authorized Keys Modification - Rule", "ESCU - Linux SSH Remote Services Script Execute - Rule", "ESCU - Suspicious Curl Network Connection - Rule"]
description = Linux Living Off The Land consists of binaries that may be used to bypass local security restrictions within misconfigured systems.
narrative = Similar to Windows LOLBAS project, the GTFOBins project focuses solely on Unix binaries that may be abused in multiple categories including Reverse Shell, File Upload, File Download and much more. These binaries are native to the operating system and the functionality is typically native. The behaviors are typically not malicious by default or vulnerable, but these are built in functionality of the applications. When reviewing any notables or hunting through mountains of events of interest, it's important to identify the binary, review command-line arguments, path of file, and capture any network and file modifications. Linux analysis may be a bit cumbersome due to volume and how process behavior is seen in EDR products. Piecing it together will require some effort.
@@ -10982,7 +11252,7 @@ version = 1
references = ["https://attack.mitre.org/tactics/TA0004/"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Teoderick Contreras"}]
spec_version = 3
searches = ["ESCU - Linux Add Files In Known Crontab Directories - Rule", "ESCU - Linux Add User Account - Rule", "ESCU - Linux Adding Crontab Using List Parameter - Rule", "ESCU - Linux At Allow Config File Creation - Rule", "ESCU - Linux At Application Execution - Rule", "ESCU - Linux AWK Privilege Escalation - Rule", "ESCU - Linux Change File Owner To Root - Rule", "ESCU - Linux Common Process For Elevation Control - Rule", "ESCU - Linux Doas Conf File Creation - Rule", "ESCU - Linux Doas Tool Execution - Rule", "ESCU - Linux Docker Privilege Escalation - Rule", "ESCU - Linux Edit Cron Table Parameter - Rule", "ESCU - Linux File Created In Kernel Driver Directory - Rule", "ESCU - Linux File Creation In Init Boot Directory - Rule", "ESCU - Linux File Creation In Profile Directory - Rule", "ESCU - Linux Insert Kernel Module Using Insmod Utility - Rule", "ESCU - Linux Install Kernel Module Using Modprobe Utility - Rule", "ESCU - Linux Node Privilege Escalation - Rule", "ESCU - Linux NOPASSWD Entry In Sudoers File - Rule", "ESCU - Linux Persistence and Privilege Escalation Risk Behavior - Rule", "ESCU - Linux pkexec Privilege Escalation - Rule", "ESCU - Linux Possible Access Or Modification Of sshd Config File - Rule", "ESCU - Linux Possible Access To Credential Files - Rule", "ESCU - Linux Possible Access To Sudoers File - Rule", "ESCU - Linux Possible Append Command To At Allow Config File - Rule", "ESCU - Linux Possible Append Command To Profile Config File - Rule", "ESCU - Linux Possible Append Cronjob Entry on Existing Cronjob File - Rule", "ESCU - Linux Possible Cronjob Modification With Editor - Rule", "ESCU - Linux Possible Ssh Key File Creation - Rule", "ESCU - Linux Preload Hijack Library Calls - Rule", "ESCU - Linux Service File Created In Systemd Directory - Rule", "ESCU - Linux Service Restarted - Rule", "ESCU - Linux Service Started Or Enabled - Rule", "ESCU - Linux Setuid Using Chmod Utility - Rule", "ESCU - Linux Setuid Using Setcap Utility - Rule", "ESCU - Linux Shred Overwrite Command - Rule", "ESCU - Linux Sudo OR Su Execution - Rule", "ESCU - Linux Sudoers Tmp File Creation - Rule", "ESCU - Linux Visudo Utility Execution - Rule"]
searches = ["ESCU - Linux Add Files In Known Crontab Directories - Rule", "ESCU - Linux Add User Account - Rule", "ESCU - Linux Adding Crontab Using List Parameter - Rule", "ESCU - Linux apt-get Privilege Escalation - Rule", "ESCU - Linux APT Privilege Escalation - Rule", "ESCU - Linux At Allow Config File Creation - Rule", "ESCU - Linux At Application Execution - Rule", "ESCU - Linux AWK Privilege Escalation - Rule", "ESCU - Linux Busybox Privilege Escalation - Rule", "ESCU - Linux c89 Privilege Escalation - Rule", "ESCU - Linux c99 Privilege Escalation - Rule", "ESCU - Linux Change File Owner To Root - Rule", "ESCU - Linux Common Process For Elevation Control - Rule", "ESCU - Linux Composer Privilege Escalation - Rule", "ESCU - Linux Cpulimit Privilege Escalation - Rule", "ESCU - Linux Csvtool Privilege Escalation - Rule", "ESCU - Linux Doas Conf File Creation - Rule", "ESCU - Linux Doas Tool Execution - Rule", "ESCU - Linux Docker Privilege Escalation - Rule", "ESCU - Linux Edit Cron Table Parameter - Rule", "ESCU - Linux Emacs Privilege Escalation - Rule", "ESCU - Linux File Created In Kernel Driver Directory - Rule", "ESCU - Linux File Creation In Init Boot Directory - Rule", "ESCU - Linux File Creation In Profile Directory - Rule", "ESCU - Linux Find Privilege Escalation - Rule", "ESCU - Linux GDB Privilege Escalation - Rule", "ESCU - Linux Gem Privilege Escalation - Rule", "ESCU - Linux GNU Awk Privilege Escalation - Rule", "ESCU - Linux Insert Kernel Module Using Insmod Utility - Rule", "ESCU - Linux Install Kernel Module Using Modprobe Utility - Rule", "ESCU - Linux Make Privilege Escalation - Rule", "ESCU - Linux MySQL Privilege Escalation - Rule", "ESCU - Linux Node Privilege Escalation - Rule", "ESCU - Linux NOPASSWD Entry In Sudoers File - Rule", "ESCU - Linux Octave Privilege Escalation - Rule", "ESCU - Linux OpenVPN Privilege Escalation - Rule", "ESCU - Linux Persistence and Privilege Escalation Risk Behavior - Rule", "ESCU - Linux PHP Privilege Escalation - Rule", "ESCU - Linux pkexec Privilege Escalation - Rule", "ESCU - Linux Possible Access Or Modification Of sshd Config File - Rule", "ESCU - Linux Possible Access To Credential Files - Rule", "ESCU - Linux Possible Access To Sudoers File - Rule", "ESCU - Linux Possible Append Command To At Allow Config File - Rule", "ESCU - Linux Possible Append Command To Profile Config File - Rule", "ESCU - Linux Possible Append Cronjob Entry on Existing Cronjob File - Rule", "ESCU - Linux Possible Cronjob Modification With Editor - Rule", "ESCU - Linux Possible Ssh Key File Creation - Rule", "ESCU - Linux Preload Hijack Library Calls - Rule", "ESCU - Linux Puppet Privilege Escalation - Rule", "ESCU - Linux RPM Privilege Escalation - Rule", "ESCU - Linux Ruby Privilege Escalation - Rule", "ESCU - Linux Service File Created In Systemd Directory - Rule", "ESCU - Linux Service Restarted - Rule", "ESCU - Linux Service Started Or Enabled - Rule", "ESCU - Linux Setuid Using Chmod Utility - Rule", "ESCU - Linux Setuid Using Setcap Utility - Rule", "ESCU - Linux Shred Overwrite Command - Rule", "ESCU - Linux Sqlite3 Privilege Escalation - Rule", "ESCU - Linux Sudo OR Su Execution - Rule", "ESCU - Linux Sudoers Tmp File Creation - Rule", "ESCU - Linux Visudo Utility Execution - Rule"]
description = Monitor for and investigate activities that may be associated with a Linux privilege-escalation attack, including unusual processes running on endpoints, schedule task, services, setuid, root execution and more.
narrative = Privilege escalation is a "land-and-expand" technique, wherein an adversary gains an initial foothold on a host and then exploits its weaknesses to increase his privileges. The motivation is simple: certain actions on a Linux machine--such as installing software--may require higher-level privileges than those the attacker initially acquired. By increasing his privilege level, the attacker can gain the control required to carry out his malicious ends. This Analytic Story provides searches to detect and investigate behaviors that attackers may use to elevate their privileges in your environment.
@@ -11004,7 +11274,7 @@ version = 2
references = ["https://lolbas-project.github.io/"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Lou Stella"}]
spec_version = 3
searches = ["ESCU - BITS Job Persistence - Rule", "ESCU - BITSAdmin Download File - Rule", "ESCU - CertUtil Download With URLCache and Split Arguments - Rule", "ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule", "ESCU - Certutil exe certificate extraction - Rule", "ESCU - CertUtil With Decode Argument - Rule", "ESCU - CMD Carry Out String Command Parameter - Rule", "ESCU - Control Loading from World Writable Directory - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Detect HTML Help Renamed - Rule", "ESCU - Detect HTML Help Spawn Child Process - Rule", "ESCU - Detect HTML Help URL in Command Line - Rule", "ESCU - Detect HTML Help Using InfoTech Storage Handlers - Rule", "ESCU - Detect mshta inline hta execution - Rule", "ESCU - Detect mshta renamed - Rule", "ESCU - Detect MSHTA Url in Command Line - Rule", "ESCU - Detect Regasm Spawning a Process - Rule", "ESCU - Detect Regasm with Network Connection - Rule", "ESCU - Detect Regasm with no Command Line Arguments - Rule", "ESCU - Detect Regsvcs Spawning a Process - Rule", "ESCU - Detect Regsvcs with Network Connection - Rule", "ESCU - Detect Regsvcs with No Command Line Arguments - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - Detect Rundll32 Application Control Bypass - advpack - Rule", "ESCU - Detect Rundll32 Application Control Bypass - setupapi - Rule", "ESCU - Detect Rundll32 Application Control Bypass - syssetup - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - Disable Schedule Task - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Esentutl SAM Copy - Rule", "ESCU - Eventvwr UAC Bypass - Rule", "ESCU - Living Off The Land - Rule", "ESCU - MacOS LOLbin - Rule", "ESCU - MacOS plutil - Rule", "ESCU - Mmc LOLBAS Execution Process Spawn - Rule", "ESCU - Mshta spawning Rundll32 OR Regsvr32 Process - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Regsvr32 Silent and Install Param Dll Loading - Rule", "ESCU - Regsvr32 with Known Silent Switch Cmdline - Rule", "ESCU - Remote WMI Command Attempt - Rule", "ESCU - Rundll32 Control RunDLL Hunt - Rule", "ESCU - Rundll32 Control RunDLL World Writable Directory - Rule", "ESCU - Rundll32 Create Remote Thread To A Process - Rule", "ESCU - Rundll32 CreateRemoteThread In Browser - Rule", "ESCU - Rundll32 DNSQuery - Rule", "ESCU - Rundll32 Process Creating Exe Dll Files - Rule", "ESCU - Rundll32 Shimcache Flush - Rule", "ESCU - RunDLL Loading DLL By Ordinal - Rule", "ESCU - Schedule Task with HTTP Command Arguments - Rule", "ESCU - Schedule Task with Rundll32 Command Trigger - Rule", "ESCU - Scheduled Task Creation on Remote Endpoint using At - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Scheduled Task Initiation on Remote Endpoint - Rule", "ESCU - Schtasks scheduling job on remote system - Rule", "ESCU - Services LOLBAS Execution Process Spawn - Rule", "ESCU - Suspicious IcedID Rundll32 Cmdline - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious microsoft workflow compiler usage - Rule", "ESCU - Suspicious msbuild path - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious MSBuild Spawn - Rule", "ESCU - Suspicious mshta child process - Rule", "ESCU - Suspicious mshta spawn - Rule", "ESCU - Suspicious Regsvr32 Register Suspicious Path - Rule", "ESCU - Suspicious Rundll32 dllregisterserver - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Svchost LOLBAS Execution Process Spawn - Rule", "ESCU - Windows Binary Proxy Execution Mavinject DLL Injection - Rule", "ESCU - Windows Diskshadow Proxy Execution - Rule", "ESCU - Windows DLL Search Order Hijacking with iscsicpl - Rule", "ESCU - Windows Identify Protocol Handlers - Rule", "ESCU - Windows Indirect Command Execution Via forfiles - Rule", "ESCU - Windows Indirect Command Execution Via pcalua - Rule", "ESCU - Windows InstallUtil in Non Standard Path - Rule", "ESCU - Windows InstallUtil Remote Network Connection - Rule", "ESCU - Windows InstallUtil Uninstall Option - Rule", "ESCU - Windows InstallUtil Uninstall Option with Network - Rule", "ESCU - Windows InstallUtil URL in Command Line - Rule", "ESCU - Windows MOF Event Triggered Execution via WMI - Rule", "ESCU - Windows Odbcconf Hunting - Rule", "ESCU - Windows Odbcconf Load DLL - Rule", "ESCU - Windows Odbcconf Load Response File - Rule", "ESCU - WSReset UAC Bypass - Rule"]
searches = ["ESCU - BITS Job Persistence - Rule", "ESCU - BITSAdmin Download File - Rule", "ESCU - CertUtil Download With URLCache and Split Arguments - Rule", "ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule", "ESCU - Certutil exe certificate extraction - Rule", "ESCU - CertUtil With Decode Argument - Rule", "ESCU - CMD Carry Out String Command Parameter - Rule", "ESCU - Control Loading from World Writable Directory - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Detect HTML Help Renamed - Rule", "ESCU - Detect HTML Help Spawn Child Process - Rule", "ESCU - Detect HTML Help URL in Command Line - Rule", "ESCU - Detect HTML Help Using InfoTech Storage Handlers - Rule", "ESCU - Detect mshta inline hta execution - Rule", "ESCU - Detect mshta renamed - Rule", "ESCU - Detect MSHTA Url in Command Line - Rule", "ESCU - Detect Regasm Spawning a Process - Rule", "ESCU - Detect Regasm with Network Connection - Rule", "ESCU - Detect Regasm with no Command Line Arguments - Rule", "ESCU - Detect Regsvcs Spawning a Process - Rule", "ESCU - Detect Regsvcs with Network Connection - Rule", "ESCU - Detect Regsvcs with No Command Line Arguments - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - Detect Rundll32 Application Control Bypass - advpack - Rule", "ESCU - Detect Rundll32 Application Control Bypass - setupapi - Rule", "ESCU - Detect Rundll32 Application Control Bypass - syssetup - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - Disable Schedule Task - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Esentutl SAM Copy - Rule", "ESCU - Eventvwr UAC Bypass - Rule", "ESCU - Living Off The Land - Rule", "ESCU - MacOS LOLbin - Rule", "ESCU - MacOS plutil - Rule", "ESCU - Mmc LOLBAS Execution Process Spawn - Rule", "ESCU - Mshta spawning Rundll32 OR Regsvr32 Process - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Regsvr32 Silent and Install Param Dll Loading - Rule", "ESCU - Regsvr32 with Known Silent Switch Cmdline - Rule", "ESCU - Remote WMI Command Attempt - Rule", "ESCU - Rundll32 Control RunDLL Hunt - Rule", "ESCU - Rundll32 Control RunDLL World Writable Directory - Rule", "ESCU - Rundll32 Create Remote Thread To A Process - Rule", "ESCU - Rundll32 CreateRemoteThread In Browser - Rule", "ESCU - Rundll32 DNSQuery - Rule", "ESCU - Rundll32 Process Creating Exe Dll Files - Rule", "ESCU - Rundll32 Shimcache Flush - Rule", "ESCU - RunDLL Loading DLL By Ordinal - Rule", "ESCU - Schedule Task with HTTP Command Arguments - Rule", "ESCU - Schedule Task with Rundll32 Command Trigger - Rule", "ESCU - Scheduled Task Creation on Remote Endpoint using At - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Scheduled Task Initiation on Remote Endpoint - Rule", "ESCU - Schtasks scheduling job on remote system - Rule", "ESCU - Services LOLBAS Execution Process Spawn - Rule", "ESCU - Suspicious IcedID Rundll32 Cmdline - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious microsoft workflow compiler usage - Rule", "ESCU - Suspicious msbuild path - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious MSBuild Spawn - Rule", "ESCU - Suspicious mshta child process - Rule", "ESCU - Suspicious mshta spawn - Rule", "ESCU - Suspicious Regsvr32 Register Suspicious Path - Rule", "ESCU - Suspicious Rundll32 dllregisterserver - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Svchost LOLBAS Execution Process Spawn - Rule", "ESCU - Windows Binary Proxy Execution Mavinject DLL Injection - Rule", "ESCU - Windows Diskshadow Proxy Execution - Rule", "ESCU - Windows DLL Search Order Hijacking Hunt - Rule", "ESCU - Windows DLL Search Order Hijacking Hunt with Sysmon - Rule", "ESCU - Windows DLL Search Order Hijacking with iscsicpl - Rule", "ESCU - Windows Identify Protocol Handlers - Rule", "ESCU - Windows Indirect Command Execution Via forfiles - Rule", "ESCU - Windows Indirect Command Execution Via pcalua - Rule", "ESCU - Windows InstallUtil in Non Standard Path - Rule", "ESCU - Windows InstallUtil Remote Network Connection - Rule", "ESCU - Windows InstallUtil Uninstall Option - Rule", "ESCU - Windows InstallUtil Uninstall Option with Network - Rule", "ESCU - Windows InstallUtil URL in Command Line - Rule", "ESCU - Windows MOF Event Triggered Execution via WMI - Rule", "ESCU - Windows Odbcconf Hunting - Rule", "ESCU - Windows Odbcconf Load DLL - Rule", "ESCU - Windows Odbcconf Load Response File - Rule", "ESCU - WSReset UAC Bypass - Rule"]
description = Leverage analytics that allow you to identify the presence of an adversary leveraging native applications within your environment.
narrative = Living Off The Land refers to an adversary methodology of using native applications already installed on the target operating system to achieve their objective. Native utilities provide the adversary with reduced chances of detection by antivirus software or EDR tools. This allows the adversary to blend in with native process behavior.
@@ -11267,7 +11537,7 @@ version = 1
references = ["https://web.archive.org/web/20190826231258/https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/", "https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html"]
maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}]
spec_version = 3
searches = ["ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - 7zip CommandLine To SMB Share Path - Rule", "ESCU - Allow File And Printing Sharing In Firewall - Rule", "ESCU - Allow Network Discovery In Firewall - Rule", "ESCU - Allow Operation with Consent Admin - Rule", "ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Clear Unallocated Sector Using Cipher App - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Conti Common Exec parameter - Rule", "ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Detect SharpHound Command-Line Arguments - Rule", "ESCU - Detect SharpHound File Modifications - Rule", "ESCU - Detect SharpHound Usage - Rule", "ESCU - Disable AMSI Through Registry - Rule", "ESCU - Disable ETW Through Registry - Rule", "ESCU - Disable Logs Using WevtUtil - Rule", "ESCU - Disable Windows Behavior Monitoring - Rule", "ESCU - Excessive Service Stop Attempt - Rule", "ESCU - Excessive Usage Of Net App - Rule", "ESCU - Excessive Usage Of SC Service Utility - Rule", "ESCU - Execute Javascript With Jscript COM CLSID - Rule", "ESCU - Fsutil Zeroing File - Rule", "ESCU - ICACLS Grant Command - Rule", "ESCU - Known Services Killed by Ransomware - Rule", "ESCU - Modification Of Wallpaper - Rule", "ESCU - Msmpeng Application DLL Side Loading - Rule", "ESCU - Permission Modification using Takeown App - Rule", "ESCU - Powershell Disable Security Monitoring - Rule", "ESCU - Powershell Enable SMB1Protocol Feature - Rule", "ESCU - Powershell Execute COM Object - Rule", "ESCU - Prevent Automatic Repair Mode using Bcdedit - Rule", "ESCU - Recon AVProduct Through Pwh or WMI - Rule", "ESCU - Recursive Delete of Directory In Batch CMD - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - Revil Common Exec Parameter - Rule", "ESCU - Revil Registry Entry - Rule", "ESCU - Rundll32 LockWorkStation - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Suspicious Event Log Service Behavior - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - UAC Bypass With Colorui COM Object - Rule", "ESCU - Uninstall App Using MsiExec - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Wbemprox COM Object Execution - Rule", "ESCU - Windows Disable Change Password Through Registry - Rule", "ESCU - Windows Disable Lock Workstation Feature Through Registry - Rule", "ESCU - Windows Disable LogOff Button Through Registry - Rule", "ESCU - Windows Disable Memory Crash Dump - Rule", "ESCU - Windows Disable Shutdown Button Through Registry - Rule", "ESCU - Windows Disable Windows Group Policy Features Through Registry - Rule", "ESCU - Windows DiskCryptor Usage - Rule", "ESCU - Windows DotNet Binary in Non Standard Path - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Windows Hide Notification Features Through Registry - Rule", "ESCU - Windows InstallUtil in Non Standard Path - Rule", "ESCU - Windows NirSoft AdvancedRun - Rule", "ESCU - Windows Raccine Scheduled Task Deletion - Rule", "ESCU - Windows Registry Modification for Safe Mode Persistence - Rule", "ESCU - WinEvent Scheduled Task Created to Spawn Shell - Rule", "ESCU - WinEvent Scheduled Task Created Within Public Path - Rule", "ESCU - MS Exchange Mailbox Replication service writing Active Server Pages - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task"]
searches = ["ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - 7zip CommandLine To SMB Share Path - Rule", "ESCU - Allow File And Printing Sharing In Firewall - Rule", "ESCU - Allow Network Discovery In Firewall - Rule", "ESCU - Allow Operation with Consent Admin - Rule", "ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Clear Unallocated Sector Using Cipher App - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Conti Common Exec parameter - Rule", "ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Detect SharpHound Command-Line Arguments - Rule", "ESCU - Detect SharpHound File Modifications - Rule", "ESCU - Detect SharpHound Usage - Rule", "ESCU - Disable AMSI Through Registry - Rule", "ESCU - Disable ETW Through Registry - Rule", "ESCU - Disable Logs Using WevtUtil - Rule", "ESCU - Disable Windows Behavior Monitoring - Rule", "ESCU - Excessive Service Stop Attempt - Rule", "ESCU - Excessive Usage Of Net App - Rule", "ESCU - Excessive Usage Of SC Service Utility - Rule", "ESCU - Execute Javascript With Jscript COM CLSID - Rule", "ESCU - Fsutil Zeroing File - Rule", "ESCU - ICACLS Grant Command - Rule", "ESCU - Known Services Killed by Ransomware - Rule", "ESCU - Modification Of Wallpaper - Rule", "ESCU - Msmpeng Application DLL Side Loading - Rule", "ESCU - Permission Modification using Takeown App - Rule", "ESCU - Powershell Disable Security Monitoring - Rule", "ESCU - Powershell Enable SMB1Protocol Feature - Rule", "ESCU - Powershell Execute COM Object - Rule", "ESCU - Prevent Automatic Repair Mode using Bcdedit - Rule", "ESCU - Recon AVProduct Through Pwh or WMI - Rule", "ESCU - Recursive Delete of Directory In Batch CMD - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - Revil Common Exec Parameter - Rule", "ESCU - Revil Registry Entry - Rule", "ESCU - Rundll32 LockWorkStation - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Suspicious Event Log Service Behavior - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - UAC Bypass With Colorui COM Object - Rule", "ESCU - Uninstall App Using MsiExec - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Wbemprox COM Object Execution - Rule", "ESCU - Windows Disable Change Password Through Registry - Rule", "ESCU - Windows Disable Lock Workstation Feature Through Registry - Rule", "ESCU - Windows Disable LogOff Button Through Registry - Rule", "ESCU - Windows Disable Memory Crash Dump - Rule", "ESCU - Windows Disable Shutdown Button Through Registry - Rule", "ESCU - Windows Disable Windows Group Policy Features Through Registry - Rule", "ESCU - Windows DiskCryptor Usage - Rule", "ESCU - Windows DotNet Binary in Non Standard Path - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Windows Hide Notification Features Through Registry - Rule", "ESCU - Windows InstallUtil in Non Standard Path - Rule", "ESCU - Windows NirSoft AdvancedRun - Rule", "ESCU - Windows Raccine Scheduled Task Deletion - Rule", "ESCU - Windows Registry Modification for Safe Mode Persistence - Rule", "ESCU - Windows Remote Access Software Hunt - Rule", "ESCU - WinEvent Scheduled Task Created to Spawn Shell - Rule", "ESCU - WinEvent Scheduled Task Created Within Public Path - Rule", "ESCU - MS Exchange Mailbox Replication service writing Active Server Pages - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task"]
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others.
narrative = Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise. Attackers can deploy ransomware to enterprises through spearphishing campaigns and driveby downloads, as well as through traditional remote service-based exploitation. In the case of the WannaCry campaign, there was self-propagating wormable functionality that was used to maximize infection. Fortunately, organizations can apply several techniques--such as those in this Analytic Story--to detect and or mitigate the effects of ransomware.
@@ -11812,7 +12082,7 @@ version = 1
references = ["https://attack.mitre.org/wiki/Defense_Evasion"]
maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}]
spec_version = 3
searches = ["ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Add or Set Windows Defender Exclusion - Rule", "ESCU - CSC Net On The Fly Compilation - Rule", "ESCU - Disable Registry Tool - Rule", "ESCU - Disable Security Logs Using MiniNt Registry - Rule", "ESCU - Disable Show Hidden Files - Rule", "ESCU - Disable UAC Remote Restriction - Rule", "ESCU - Disable Windows Behavior Monitoring - Rule", "ESCU - Disable Windows SmartScreen Protection - Rule", "ESCU - Disabling CMD Application - Rule", "ESCU - Disabling ControlPanel - Rule", "ESCU - Disabling Firewall with Netsh - Rule", "ESCU - Disabling FolderOptions Windows Feature - Rule", "ESCU - Disabling NoRun Windows App - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Disabling SystemRestore In Registry - Rule", "ESCU - Disabling Task Manager - Rule", "ESCU - Eventvwr UAC Bypass - Rule", "ESCU - Excessive number of service control start as disabled - Rule", "ESCU - Firewall Allowed Program Enable - Rule", "ESCU - FodHelper UAC Bypass - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - NET Profiler UAC bypass - Rule", "ESCU - Powershell Windows Defender Exclusion Commands - Rule", "ESCU - Sdclt UAC Bypass - Rule", "ESCU - SilentCleanup UAC Bypass - Rule", "ESCU - SLUI RunAs Elevated - Rule", "ESCU - SLUI Spawning a Process - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - UAC Bypass MMC Load Unsigned Dll - Rule", "ESCU - Windows Command and Scripting Interpreter Hunting Path Traversal - Rule", "ESCU - Windows Command and Scripting Interpreter Path Traversal Exec - Rule", "ESCU - Windows Defender Exclusion Registry Entry - Rule", "ESCU - Windows Disable Change Password Through Registry - Rule", "ESCU - Windows Disable Lock Workstation Feature Through Registry - Rule", "ESCU - Windows Disable Notification Center - Rule", "ESCU - Windows Disable Windows Group Policy Features Through Registry - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Windows DISM Remove Defender - Rule", "ESCU - Windows DLL Search Order Hijacking with iscsicpl - Rule", "ESCU - Windows Event For Service Disabled - Rule", "ESCU - Windows Excessive Disabled Services Event - Rule", "ESCU - Windows Hide Notification Features Through Registry - Rule", "ESCU - Windows Impair Defense Delete Win Defender Context Menu - Rule", "ESCU - Windows Impair Defense Delete Win Defender Profile Registry - Rule", "ESCU - Windows Impair Defenses Disable Win Defender Auto Logging - Rule", "ESCU - Windows Modify Show Compress Color And Info Tip Registry - Rule", "ESCU - Windows Process With NamedPipe CommandLine - Rule", "ESCU - Windows Rasautou DLL Execution - Rule", "ESCU - WSReset UAC Bypass - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task"]
searches = ["ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Add or Set Windows Defender Exclusion - Rule", "ESCU - CSC Net On The Fly Compilation - Rule", "ESCU - Disable Registry Tool - Rule", "ESCU - Disable Security Logs Using MiniNt Registry - Rule", "ESCU - Disable Show Hidden Files - Rule", "ESCU - Disable UAC Remote Restriction - Rule", "ESCU - Disable Windows Behavior Monitoring - Rule", "ESCU - Disable Windows SmartScreen Protection - Rule", "ESCU - Disabling CMD Application - Rule", "ESCU - Disabling ControlPanel - Rule", "ESCU - Disabling Firewall with Netsh - Rule", "ESCU - Disabling FolderOptions Windows Feature - Rule", "ESCU - Disabling NoRun Windows App - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Disabling SystemRestore In Registry - Rule", "ESCU - Disabling Task Manager - Rule", "ESCU - Eventvwr UAC Bypass - Rule", "ESCU - Excessive number of service control start as disabled - Rule", "ESCU - Firewall Allowed Program Enable - Rule", "ESCU - FodHelper UAC Bypass - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - NET Profiler UAC bypass - Rule", "ESCU - Powershell Windows Defender Exclusion Commands - Rule", "ESCU - Sdclt UAC Bypass - Rule", "ESCU - SilentCleanup UAC Bypass - Rule", "ESCU - SLUI RunAs Elevated - Rule", "ESCU - SLUI Spawning a Process - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - UAC Bypass MMC Load Unsigned Dll - Rule", "ESCU - Windows Command and Scripting Interpreter Hunting Path Traversal - Rule", "ESCU - Windows Command and Scripting Interpreter Path Traversal Exec - Rule", "ESCU - Windows Defender Exclusion Registry Entry - Rule", "ESCU - Windows Disable Change Password Through Registry - Rule", "ESCU - Windows Disable Lock Workstation Feature Through Registry - Rule", "ESCU - Windows Disable Notification Center - Rule", "ESCU - Windows Disable Windows Group Policy Features Through Registry - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Windows DISM Remove Defender - Rule", "ESCU - Windows DLL Search Order Hijacking Hunt - Rule", "ESCU - Windows DLL Search Order Hijacking Hunt with Sysmon - Rule", "ESCU - Windows DLL Search Order Hijacking with iscsicpl - Rule", "ESCU - Windows Event For Service Disabled - Rule", "ESCU - Windows Excessive Disabled Services Event - Rule", "ESCU - Windows Hide Notification Features Through Registry - Rule", "ESCU - Windows Impair Defense Delete Win Defender Context Menu - Rule", "ESCU - Windows Impair Defense Delete Win Defender Profile Registry - Rule", "ESCU - Windows Impair Defenses Disable Win Defender Auto Logging - Rule", "ESCU - Windows Modify Show Compress Color And Info Tip Registry - Rule", "ESCU - Windows Process With NamedPipe CommandLine - Rule", "ESCU - Windows Rasautou DLL Execution - Rule", "ESCU - WSReset UAC Bypass - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task"]
description = Detect tactics used by malware to evade defenses on Windows endpoints. A few of these include suspicious `reg.exe` processes, files hidden with `attrib.exe` and disabling user-account control, among many others
narrative = Defense evasion is a tactic--identified in the MITRE ATT&CK framework--that adversaries employ in a variety of ways to bypass or defeat defensive security measures. There are many techniques enumerated by the MITRE ATT&CK framework that are applicable in this context. This Analytic Story includes searches designed to identify the use of such techniques on Windows platforms.
@@ -11905,7 +12175,7 @@ version = 1
references = ["https://attack.mitre.org/techniques/T1112/", "https://redcanary.com/blog/windows-registry-attacks-threat-detection/"]
maintainers = [{"company": "Splunk", "email": "-", "name": "Teoderick Contreras"}]
spec_version = 3
searches = ["ESCU - Allow Inbound Traffic By Firewall Rule Registry - Rule", "ESCU - Allow Operation with Consent Admin - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Auto Admin Logon Registry Entry - Rule", "ESCU - Change Default File Association - Rule", "ESCU - Disable AMSI Through Registry - Rule", "ESCU - Disable Defender AntiVirus Registry - Rule", "ESCU - Disable Defender BlockAtFirstSeen Feature - Rule", "ESCU - Disable Defender Enhanced Notification - Rule", "ESCU - Disable Defender MpEngine Registry - Rule", "ESCU - Disable Defender Spynet Reporting - Rule", "ESCU - Disable Defender Submit Samples Consent Feature - Rule", "ESCU - Disable ETW Through Registry - Rule", "ESCU - Disable Registry Tool - Rule", "ESCU - Disable Security Logs Using MiniNt Registry - Rule", "ESCU - Disable Show Hidden Files - Rule", "ESCU - Disable UAC Remote Restriction - Rule", "ESCU - Disable Windows App Hotkeys - Rule", "ESCU - Disable Windows Behavior Monitoring - Rule", "ESCU - Disable Windows SmartScreen Protection - Rule", "ESCU - Disabling CMD Application - Rule", "ESCU - Disabling ControlPanel - Rule", "ESCU - Disabling Defender Services - Rule", "ESCU - Disabling FolderOptions Windows Feature - Rule", "ESCU - Disabling NoRun Windows App - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Disabling SystemRestore In Registry - Rule", "ESCU - Disabling Task Manager - Rule", "ESCU - Enable RDP In Other Port Number - Rule", "ESCU - Enable WDigest UseLogonCredential Registry - Rule", "ESCU - ETW Registry Disabled - Rule", "ESCU - Eventvwr UAC Bypass - Rule", "ESCU - Hide User Account From Sign-In Screen - Rule", "ESCU - Modification Of Wallpaper - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Remcos client registry install entry - Rule", "ESCU - Revil Registry Entry - Rule", "ESCU - Screensaver Event Trigger Execution - Rule", "ESCU - Sdclt UAC Bypass - Rule", "ESCU - SilentCleanup UAC Bypass - Rule", "ESCU - Time Provider Persistence Registry - Rule", "ESCU - Windows Disable Lock Workstation Feature Through Registry - Rule", "ESCU - Windows Disable LogOff Button Through Registry - Rule", "ESCU - Windows Disable Memory Crash Dump - Rule", "ESCU - Windows Disable Notification Center - Rule", "ESCU - Windows Disable Shutdown Button Through Registry - Rule", "ESCU - Windows Disable Windows Group Policy Features Through Registry - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Windows Hide Notification Features Through Registry - Rule", "ESCU - Windows Impair Defense Delete Win Defender Context Menu - Rule", "ESCU - Windows Impair Defense Delete Win Defender Profile Registry - Rule", "ESCU - Windows Impair Defenses Disable Win Defender Auto Logging - Rule", "ESCU - Windows Modify Show Compress Color And Info Tip Registry - Rule", "ESCU - Windows Registry Certificate Added - Rule", "ESCU - Windows Registry Delete Task SD - Rule", "ESCU - Windows Registry Modification for Safe Mode Persistence - Rule", "ESCU - Windows Service Creation Using Registry Entry - Rule", "ESCU - WSReset UAC Bypass - Rule"]
searches = ["ESCU - Allow Inbound Traffic By Firewall Rule Registry - Rule", "ESCU - Allow Operation with Consent Admin - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Auto Admin Logon Registry Entry - Rule", "ESCU - Change Default File Association - Rule", "ESCU - Disable AMSI Through Registry - Rule", "ESCU - Disable Defender AntiVirus Registry - Rule", "ESCU - Disable Defender BlockAtFirstSeen Feature - Rule", "ESCU - Disable Defender Enhanced Notification - Rule", "ESCU - Disable Defender MpEngine Registry - Rule", "ESCU - Disable Defender Spynet Reporting - Rule", "ESCU - Disable Defender Submit Samples Consent Feature - Rule", "ESCU - Disable ETW Through Registry - Rule", "ESCU - Disable Registry Tool - Rule", "ESCU - Disable Security Logs Using MiniNt Registry - Rule", "ESCU - Disable Show Hidden Files - Rule", "ESCU - Disable UAC Remote Restriction - Rule", "ESCU - Disable Windows App Hotkeys - Rule", "ESCU - Disable Windows Behavior Monitoring - Rule", "ESCU - Disable Windows SmartScreen Protection - Rule", "ESCU - Disabling CMD Application - Rule", "ESCU - Disabling ControlPanel - Rule", "ESCU - Disabling Defender Services - Rule", "ESCU - Disabling FolderOptions Windows Feature - Rule", "ESCU - Disabling NoRun Windows App - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Disabling SystemRestore In Registry - Rule", "ESCU - Disabling Task Manager - Rule", "ESCU - Enable RDP In Other Port Number - Rule", "ESCU - Enable WDigest UseLogonCredential Registry - Rule", "ESCU - ETW Registry Disabled - Rule", "ESCU - Eventvwr UAC Bypass - Rule", "ESCU - Hide User Account From Sign-In Screen - Rule", "ESCU - Modification Of Wallpaper - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Remcos client registry install entry - Rule", "ESCU - Revil Registry Entry - Rule", "ESCU - Screensaver Event Trigger Execution - Rule", "ESCU - Sdclt UAC Bypass - Rule", "ESCU - SilentCleanup UAC Bypass - Rule", "ESCU - Time Provider Persistence Registry - Rule", "ESCU - Windows Autostart Execution LSASS Driver Registry Modification - Rule", "ESCU - Windows Disable Lock Workstation Feature Through Registry - Rule", "ESCU - Windows Disable LogOff Button Through Registry - Rule", "ESCU - Windows Disable Memory Crash Dump - Rule", "ESCU - Windows Disable Notification Center - Rule", "ESCU - Windows Disable Shutdown Button Through Registry - Rule", "ESCU - Windows Disable Windows Group Policy Features Through Registry - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Windows Hide Notification Features Through Registry - Rule", "ESCU - Windows Impair Defense Delete Win Defender Context Menu - Rule", "ESCU - Windows Impair Defense Delete Win Defender Profile Registry - Rule", "ESCU - Windows Impair Defenses Disable Win Defender Auto Logging - Rule", "ESCU - Windows Modify Show Compress Color And Info Tip Registry - Rule", "ESCU - Windows Registry Certificate Added - Rule", "ESCU - Windows Registry Delete Task SD - Rule", "ESCU - Windows Registry Modification for Safe Mode Persistence - Rule", "ESCU - Windows Service Creation Using Registry Entry - Rule", "ESCU - WSReset UAC Bypass - Rule"]
description = Windows services are often used by attackers for persistence, privilege escalation, lateral movement, defense evasion, collection of data, a tool for recon, credential dumping and payload impact. This Analytic Story helps you monitor your environment for indications that Windows registry are being modified or created in a suspicious manner.
narrative = Windows Registry is one of the powerful and yet still mysterious Windows features that can tweak or manipulate Windows policies and low-level configuration settings. Because of this capability, most malware, adversaries or threat actors abuse this hierarchical database to do their malicious intent on a targeted host or network environment. In these cases, attackers often use tools to create or modify registry in ways that are not typical for most environments, providing opportunities for detection.
+2 -2
View File
@@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 9402
build = 9578
[triggers]
reload.analytic_stories = simple
@@ -20,7 +20,7 @@ reload.es_investigations = simple
[launcher]
author = Splunk
version = 3.47.0
version = 3.48.0
description = Explore the Analytic Stories included with ES Content Updates.
[ui]
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2022-08-16T16:13:51 UTC
# On Date: 2022-08-29T17:38:30 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,2 +1,2 @@
[content-version]
version = 3.47.0
version = 3.48.0
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2022-08-16T16:13:51 UTC
# On Date: 2022-08-29T17:38:30 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+110 -2
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2022-08-16T16:13:51 UTC
# On Date: 2022-08-29T17:38:30 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -213,6 +213,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[azure_ad_multi_factor_authentication_disabled_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[azure_ad_multiple_users_failing_to_authenticate_from_ip_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1721,6 +1725,14 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_apt_get_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_apt_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_at_allow_config_file_creation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1733,6 +1745,18 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_busybox_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_c89_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_c99_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_change_file_owner_to_root_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1745,6 +1769,18 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_composer_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_cpulimit_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_csvtool_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_curl_upload_file_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1797,6 +1833,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_emacs_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_file_created_in_kernel_driver_directory_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1809,6 +1849,22 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_find_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_gdb_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_gem_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_gnu_awk_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_high_frequency_of_file_deletion_in_boot_folder_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1849,6 +1905,14 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_make_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_mysql_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_node_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1861,10 +1925,22 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_octave_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_openvpn_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_persistence_and_privilege_escalation_risk_behavior_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_php_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_pkexec_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1909,6 +1985,18 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_puppet_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_rpm_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_ruby_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_service_file_created_in_systemd_directory_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -1933,6 +2021,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_sqlite3_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[linux_ssh_authorized_keys_modification_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -2905,6 +2997,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_autostart_execution_lsass_driver_registry_modification_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_binary_proxy_execution_mavinject_dll_injection_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -2997,6 +3093,14 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_dll_search_order_hijacking_hunt_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_dll_search_order_hijacking_hunt_with_sysmon_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_dll_search_order_hijacking_with_iscsicpl_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -3285,6 +3389,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_remote_access_software_hunt_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_remote_access_software_rms_registry_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -4416,7 +4524,7 @@ definition = convert timeformat="%Y-%m-%dT%H:%M:%S" ctime($field$)
description = convert epoch time to string
[security_content_summariesonly]
definition = summariesonly=false allow_old_summaries=true
definition = summariesonly=false allow_old_summaries=true fillnull_value=null
description = search data model's summaries only
[security_group_api_calls]
+1152 -60
View File
File diff suppressed because it is too large Load Diff
+17 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2022-08-16T16:13:51 UTC
# On Date: 2022-08-29T17:38:30 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -87,6 +87,14 @@ match_type = WILDCARD(dynamic_dns_domains)
filename = escu_search_id.csv
# description = A placeholder lookup file to hold information for ESCU Usage dashboard
[hijacklibs]
filename = hijacklibs.csv
default_match = false
case_sensitive_match = false
# description = A list of potentially abused libraries in Windows
match_type = WILDCARD(library)
min_matches = 1
[images_to_repository]
filename = images_to_repository.csv
# description = Mapping images to repositories
@@ -291,6 +299,14 @@ default_match = false
match_type = WILDCARD(ransomware_notes)
min_matches = 1
[remote_access_software]
filename = remote_access_software.csv
default_match = false
case_sensitive_match = false
# description = A list of Remote Access Software
match_type = WILDCARD(remote_software)
min_matches = 1
[s3_deletion_baseline]
filename = s3_deletion_baseline.csv
# description = A placeholder for the baseline information for AWS S3 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2022-08-16T16:13:51 UTC
# On Date: 2022-08-29T17:38:30 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+403
View File
@@ -0,0 +1,403 @@
library,islibrary
outllib.dll,TRUE
iviewers.dll,TRUE
hha.dll,TRUE
aclui.dll,TRUE
xwtpw32.dll,TRUE
xwizards.dll,TRUE
xpsservices.dll,TRUE
xolehlp.dll,TRUE
xmllite.dll,TRUE
wwapi.dll,TRUE
wwancfg.dll,TRUE
wtsapi32.dll,TRUE
wsmsvc.dll,TRUE
wshelper.dll,TRUE
wshbth.dll,TRUE
wscapi.dll,TRUE
wpdshext.dll,TRUE
wofutil.dll,TRUE
wmsgapi.dll,TRUE
wmpdui.dll,TRUE
wmiutils.dll,TRUE
wmidcom.dll,TRUE
wmiclnt.dll,TRUE
wlidprov.dll,TRUE
wldp.dll,TRUE
wlbsctrl.dll,TRUE
wlancfg.dll,TRUE
wlanapi.dll,TRUE
wkscli.dll,TRUE
winsync.dll,TRUE
winsta.dll,TRUE
winsqlite3.dll,TRUE
winscard.dll,TRUE
winrnr.dll,TRUE
winnsi.dll,TRUE
winmm.dll,TRUE
winmde.dll,TRUE
winipsec.dll,TRUE
wininet.dll,TRUE
winhttp.dll,TRUE
windowsudk.shellcommon.dll,TRUE
windowsperformancerecordercontrol.dll,TRUE
windowscodecsext.dll,TRUE
windowscodecs.dll,TRUE
windows.ui.immersive.dll,TRUE
windows.storage.search.dll,TRUE
windows.storage.dll,TRUE
winbrand.dll,TRUE
winbio.dll,TRUE
wimgapi.dll,TRUE
whhelper.dll,TRUE
wevtapi.dll,TRUE
wer.dll,TRUE
wecapi.dll,TRUE
webservices.dll,TRUE
wdscore.dll,TRUE
wdi.dll,TRUE
wcnnetsh.dll,TRUE
wcmapi.dll,TRUE
wbemsvc.dll,TRUE
wbemprox.dll,TRUE
vsstrace.dll,TRUE
vssapi.dll,TRUE
virtdisk.dll,TRUE
version.dll,TRUE
vdsutil.dll,TRUE
vaultcli.dll,TRUE
uxtheme.dll,TRUE
uxinit.dll,TRUE
utildll.dll,TRUE
userenv.dll,TRUE
urlmon.dll,TRUE
upshared.dll,TRUE
updatepolicy.dll,TRUE
unattend.dll,TRUE
umpdc.dll,TRUE
uiribbon.dll,TRUE
uireng.dll,TRUE
uiautomationcore.dll,TRUE
uianimation.dll,TRUE
twinui.appcore.dll,TRUE
twinapi.dll,TRUE
twext.dll,TRUE
ttdrecord.dll,TRUE
tsworkspace.dll,TRUE
tquery.dll,TRUE
tpmcoreprovisioning.dll,TRUE
timesync.dll,TRUE
tdh.dll,TRUE
tbs.dll,TRUE
tapi32.dll,TRUE
systemsettingsthresholdadminflowui.dll,TRUE
sxshared.dll,TRUE
structuredquery.dll,TRUE
staterepository.core.dll,TRUE
ssshim.dll,TRUE
sspicli.dll,TRUE
ssp_isv.exe_rsaenh.dll,TRUE
ssp.exe_rsaenh.dll,TRUE
srvcli.dll,TRUE
srpapi.dll,TRUE
srmtrace.dll,TRUE
srcore.dll,TRUE
srclient.dll,TRUE
sppcext.dll,TRUE
sppc.dll,TRUE
spp.dll,TRUE
spectrumsyncclient.dll,TRUE
snmpapi.dll,TRUE
slc.dll,TRUE
shell32.dll,TRUE
security.dll,TRUE
secur32.dll,TRUE
schedcli.dll,TRUE
scecli.dll,TRUE
scansetting.dll,TRUE
sas.dll,TRUE
sapi_onecore.dll,TRUE
samlib.dll,TRUE
samcli.dll,TRUE
rtworkq.dll,TRUE
rtutils.dll,TRUE
rsaenh.dll,TRUE
rpcnsh.dll,TRUE
rmclient.dll,TRUE
resutils.dll,TRUE
resetengine.dll,TRUE
reseteng.dll,TRUE
regapi.dll,TRUE
reagent.dll,TRUE
rasmontr.dll,TRUE
rasman.dll,TRUE
rasgcw.dll,TRUE
rasdlg.dll,TRUE
rasapi32.dll,TRUE
radcui.dll,TRUE
puiapi.dll,TRUE
prvdmofcomp.dll,TRUE
proximityservicepal.dll,TRUE
proximitycommon.dll,TRUE
propsys.dll,TRUE
profapi.dll,TRUE
prntvpt.dll,TRUE
printui.dll,TRUE
powrprof.dll,TRUE
polstore.dll,TRUE
policymanager.dll,TRUE
pnrpnsp.dll,TRUE
playsndsrv.dll,TRUE
pla.dll,TRUE
pkeyhelper.dll,TRUE
peerdistsh.dll,TRUE
pdh.dll,TRUE
pcaui.dll,TRUE
p9np.dll,TRUE
p2pnetsh.dll,TRUE
p2p.dll,TRUE
osuninst.dll,TRUE
osksupport.dll,TRUE
osbaseln.dll,TRUE
opcservices.dll,TRUE
onex.dll,TRUE
omadmapi.dll,TRUE
oleacc.dll,TRUE
oci.dll,TRUE
ntshrui.dll,TRUE
ntmarta.dll,TRUE
ntlmshared.dll,TRUE
ntlanman.dll,TRUE
ntdsapi.dll,TRUE
nshwfp.dll,TRUE
nshipsec.dll,TRUE
nshhttp.dll,TRUE
npmproxy.dll,TRUE
nlansp_c.dll,TRUE
nlaapi.dll,TRUE
ninput.dll,TRUE
newdev.dll,TRUE
networkexplorer.dll,TRUE
netutils.dll,TRUE
nettrace.dll,TRUE
netshell.dll,TRUE
netsetupapi.dll,TRUE
netprovfw.dll,TRUE
netprofm.dll,TRUE
netplwiz.dll,TRUE
netjoin.dll,TRUE
netiohlp.dll,TRUE
netid.dll,TRUE
netapi32.dll,TRUE
ndfapi.dll,TRUE
ncrypt.dll,TRUE
napinsp.dll,TRUE
mtxclu.dll,TRUE
msxml3.dll,TRUE
mswsock.dll,TRUE
mswb7.dll,TRUE
msvcp110_win.dll,TRUE
msutb.dll,TRUE
mstracer.dll,TRUE
msiso.dll,TRUE
msi.dll,TRUE
msftedit.dll,TRUE
msdtctm.dll,TRUE
msdrm.dll,TRUE
msctfmonitor.dll,TRUE
msctf.dll,TRUE
mscoree.dll,TRUE
mscms.dll,TRUE
msacm32.dll,TRUE
mrmcorer.dll,TRUE
mpsvc.dll,TRUE
mprapi.dll,TRUE
mpr.dll,TRUE
mpclient.dll,TRUE
mobilenetworking.dll,TRUE
mmdevapi.dll,TRUE
mlang.dll,TRUE
miutils.dll,TRUE
mintdh.dll,TRUE
midimap.dll,TRUE
mi.dll,TRUE
mfplat.dll,TRUE
mfcore.dll,TRUE
mfc42u.dll,TRUE
mdmdiagnostics.dll,TRUE
mbaexmlparser.dll,TRUE
mapistub.dll,TRUE
maintenanceui.dll,TRUE
magnification.dll,TRUE
lrwizdll.dll,TRUE
lpksetupproxyserv.dll,TRUE
logoncontroller.dll,TRUE
logoncli.dll,TRUE
lockhostingframework.dll,TRUE
loadperf.dll,TRUE
linkinfo.dll,TRUE
licensingdiagspp.dll,TRUE
licensemanagerapi.dll,TRUE
ktmw32.dll,TRUE
ksuser.dll,TRUE
kdstub.dll,TRUE
joinutil.dll,TRUE
iumsdk.dll,TRUE
iumbase.dll,TRUE
isv.exe_rsaenh.dll,TRUE
iscsium.dll,TRUE
iscsidsc.dll,TRUE
iri.dll,TRUE
iphlpapi.dll,TRUE
inproclogger.dll,TRUE
ifsutil.dll,TRUE
ifmon.dll,TRUE
iertutil.dll,TRUE
iedkcs32.dll,TRUE
ieadvpack.dll,TRUE
idstore.dll,TRUE
icmp.dll,TRUE
httpapi.dll,TRUE
hnetmon.dll,TRUE
hid.dll,TRUE
gpapi.dll,TRUE
getuname.dll,TRUE
fxstiff.dll,TRUE
fxsst.dll,TRUE
fxsapi.dll,TRUE
fwpuclnt.dll,TRUE
fwpolicyiomgr.dll,TRUE
fwcfg.dll,TRUE
fwbase.dll,TRUE
fvewiz.dll,TRUE
fveskybackup.dll,TRUE
fveapi.dll,TRUE
framedynos.dll,TRUE
fltlib.dll,TRUE
flightsettings.dll,TRUE
firewallapi.dll,TRUE
fhsvcctl.dll,TRUE
fhcfg.dll,TRUE
feclient.dll,TRUE
fddevquery.dll,TRUE
faultrep.dll,TRUE
fastprox.dll,TRUE
explorerframe.dll,TRUE
execmodelproxy.dll,TRUE
esent.dll,TRUE
efsutil.dll,TRUE
efsadu.dll,TRUE
edputil.dll,TRUE
edgeiso.dll,TRUE
eappprxy.dll,TRUE
eappcfg.dll,TRUE
dynamoapi.dll,TRUE
dxva2.dll,TRUE
dxgi.dll,TRUE
dxcore.dll,TRUE
dwrite.dll,TRUE
dwmcore.dll,TRUE
dwmapi.dll,TRUE
dusmapi.dll,TRUE
duser.dll,TRUE
dui70.dll,TRUE
dsrole.dll,TRUE
dsreg.dll,TRUE
dsprop.dll,TRUE
dsparse.dll,TRUE
dsclient.dll,TRUE
drvstore.dll,TRUE
drprov.dll,TRUE
dpx.dll,TRUE
dot3cfg.dll,TRUE
dot3api.dll,TRUE
dnsapi.dll,TRUE
dmxmlhelputils.dll,TRUE
dmpushproxy.dll,TRUE
dmprocessxmlfiltered.dll,TRUE
dmoleaututils.dll,TRUE
dmiso8601utils.dll,TRUE
dmenterprisediagnostics.dll,TRUE
dmenrollengine.dll,TRUE
dmcommandlineutils.dll,TRUE
dmcmnutils.dll,TRUE
dmcfgutils.dll,TRUE
dismcore.dll,TRUE
dismapi.dll,TRUE
directmanipulation.dll,TRUE
dhcpcsvc6.dll,TRUE
dhcpcsvc.dll,TRUE
dhcpcmonitor.dll,TRUE
devrtl.dll,TRUE
devobj.dll,TRUE
devicepairing.dll,TRUE
devicecredential.dll,TRUE
deviceassociation.dll,TRUE
desktopshellext.dll,TRUE
defragproxy.dll,TRUE
dcomp.dll,TRUE
dcntel.dll,TRUE
dbghelp.dll,TRUE
dbgcore.dll,TRUE
davclnt.dll,TRUE
dataexchange.dll,TRUE
d3dcompiler_47.dll,TRUE
d3d9.dll,TRUE
d3d12.dll,TRUE
d3d11.dll,TRUE
d3d10warp.dll,TRUE
d3d10core.dll,TRUE
d3d10_1core.dll,TRUE
d3d10_1.dll,TRUE
d3d10.dll,TRUE
d2d1.dll,TRUE
cscui.dll,TRUE
cscobj.dll,TRUE
cscapi.dll,TRUE
cryptxml.dll,TRUE
cryptui.dll,TRUE
cryptsp.dll,TRUE
cryptdll.dll,TRUE
cryptbase.dll,TRUE
credui.dll,TRUE
coreuicomponents.dll,TRUE
coremessaging.dll,TRUE
coredplus.dll,TRUE
connect.dll,TRUE
configmanager2.dll,TRUE
comdlg32.dll,TRUE
colorui.dll,TRUE
coloradapterclient.dll,TRUE
cmutil.dll,TRUE
cmpbk32.dll,TRUE
clusapi.dll,TRUE
clipc.dll,TRUE
cldapi.dll,TRUE
certenroll.dll,TRUE
certcli.dll,TRUE
cabview.dll,TRUE
cabinet.dll,TRUE
bootux.dll,TRUE
bootmenuux.dll,TRUE
bderepair.dll,TRUE
bcrypt.dll,TRUE
bcp47mrm.dll,TRUE
bcp47langs.dll,TRUE
bcd.dll,TRUE
batmeter.dll,TRUE
avrt.dll,TRUE
authz.dll,TRUE
authfwcfg.dll,TRUE
auditpolcore.dll,TRUE
audioses.dll,TRUE
atl.dll,TRUE
archiveint.dll,TRUE
appxdeploymentclient.dll,TRUE
appxalluserstore.dll,TRUE
appvpolicy.dll,TRUE
applicationframe.dll,TRUE
apphelp.dll,TRUE
aepic.dll,TRUE
adsldpc.dll,TRUE
activeds.dll,TRUE
amsi.dll,TRUE
1 library islibrary
2 outllib.dll TRUE
3 iviewers.dll TRUE
4 hha.dll TRUE
5 aclui.dll TRUE
6 xwtpw32.dll TRUE
7 xwizards.dll TRUE
8 xpsservices.dll TRUE
9 xolehlp.dll TRUE
10 xmllite.dll TRUE
11 wwapi.dll TRUE
12 wwancfg.dll TRUE
13 wtsapi32.dll TRUE
14 wsmsvc.dll TRUE
15 wshelper.dll TRUE
16 wshbth.dll TRUE
17 wscapi.dll TRUE
18 wpdshext.dll TRUE
19 wofutil.dll TRUE
20 wmsgapi.dll TRUE
21 wmpdui.dll TRUE
22 wmiutils.dll TRUE
23 wmidcom.dll TRUE
24 wmiclnt.dll TRUE
25 wlidprov.dll TRUE
26 wldp.dll TRUE
27 wlbsctrl.dll TRUE
28 wlancfg.dll TRUE
29 wlanapi.dll TRUE
30 wkscli.dll TRUE
31 winsync.dll TRUE
32 winsta.dll TRUE
33 winsqlite3.dll TRUE
34 winscard.dll TRUE
35 winrnr.dll TRUE
36 winnsi.dll TRUE
37 winmm.dll TRUE
38 winmde.dll TRUE
39 winipsec.dll TRUE
40 wininet.dll TRUE
41 winhttp.dll TRUE
42 windowsudk.shellcommon.dll TRUE
43 windowsperformancerecordercontrol.dll TRUE
44 windowscodecsext.dll TRUE
45 windowscodecs.dll TRUE
46 windows.ui.immersive.dll TRUE
47 windows.storage.search.dll TRUE
48 windows.storage.dll TRUE
49 winbrand.dll TRUE
50 winbio.dll TRUE
51 wimgapi.dll TRUE
52 whhelper.dll TRUE
53 wevtapi.dll TRUE
54 wer.dll TRUE
55 wecapi.dll TRUE
56 webservices.dll TRUE
57 wdscore.dll TRUE
58 wdi.dll TRUE
59 wcnnetsh.dll TRUE
60 wcmapi.dll TRUE
61 wbemsvc.dll TRUE
62 wbemprox.dll TRUE
63 vsstrace.dll TRUE
64 vssapi.dll TRUE
65 virtdisk.dll TRUE
66 version.dll TRUE
67 vdsutil.dll TRUE
68 vaultcli.dll TRUE
69 uxtheme.dll TRUE
70 uxinit.dll TRUE
71 utildll.dll TRUE
72 userenv.dll TRUE
73 urlmon.dll TRUE
74 upshared.dll TRUE
75 updatepolicy.dll TRUE
76 unattend.dll TRUE
77 umpdc.dll TRUE
78 uiribbon.dll TRUE
79 uireng.dll TRUE
80 uiautomationcore.dll TRUE
81 uianimation.dll TRUE
82 twinui.appcore.dll TRUE
83 twinapi.dll TRUE
84 twext.dll TRUE
85 ttdrecord.dll TRUE
86 tsworkspace.dll TRUE
87 tquery.dll TRUE
88 tpmcoreprovisioning.dll TRUE
89 timesync.dll TRUE
90 tdh.dll TRUE
91 tbs.dll TRUE
92 tapi32.dll TRUE
93 systemsettingsthresholdadminflowui.dll TRUE
94 sxshared.dll TRUE
95 structuredquery.dll TRUE
96 staterepository.core.dll TRUE
97 ssshim.dll TRUE
98 sspicli.dll TRUE
99 ssp_isv.exe_rsaenh.dll TRUE
100 ssp.exe_rsaenh.dll TRUE
101 srvcli.dll TRUE
102 srpapi.dll TRUE
103 srmtrace.dll TRUE
104 srcore.dll TRUE
105 srclient.dll TRUE
106 sppcext.dll TRUE
107 sppc.dll TRUE
108 spp.dll TRUE
109 spectrumsyncclient.dll TRUE
110 snmpapi.dll TRUE
111 slc.dll TRUE
112 shell32.dll TRUE
113 security.dll TRUE
114 secur32.dll TRUE
115 schedcli.dll TRUE
116 scecli.dll TRUE
117 scansetting.dll TRUE
118 sas.dll TRUE
119 sapi_onecore.dll TRUE
120 samlib.dll TRUE
121 samcli.dll TRUE
122 rtworkq.dll TRUE
123 rtutils.dll TRUE
124 rsaenh.dll TRUE
125 rpcnsh.dll TRUE
126 rmclient.dll TRUE
127 resutils.dll TRUE
128 resetengine.dll TRUE
129 reseteng.dll TRUE
130 regapi.dll TRUE
131 reagent.dll TRUE
132 rasmontr.dll TRUE
133 rasman.dll TRUE
134 rasgcw.dll TRUE
135 rasdlg.dll TRUE
136 rasapi32.dll TRUE
137 radcui.dll TRUE
138 puiapi.dll TRUE
139 prvdmofcomp.dll TRUE
140 proximityservicepal.dll TRUE
141 proximitycommon.dll TRUE
142 propsys.dll TRUE
143 profapi.dll TRUE
144 prntvpt.dll TRUE
145 printui.dll TRUE
146 powrprof.dll TRUE
147 polstore.dll TRUE
148 policymanager.dll TRUE
149 pnrpnsp.dll TRUE
150 playsndsrv.dll TRUE
151 pla.dll TRUE
152 pkeyhelper.dll TRUE
153 peerdistsh.dll TRUE
154 pdh.dll TRUE
155 pcaui.dll TRUE
156 p9np.dll TRUE
157 p2pnetsh.dll TRUE
158 p2p.dll TRUE
159 osuninst.dll TRUE
160 osksupport.dll TRUE
161 osbaseln.dll TRUE
162 opcservices.dll TRUE
163 onex.dll TRUE
164 omadmapi.dll TRUE
165 oleacc.dll TRUE
166 oci.dll TRUE
167 ntshrui.dll TRUE
168 ntmarta.dll TRUE
169 ntlmshared.dll TRUE
170 ntlanman.dll TRUE
171 ntdsapi.dll TRUE
172 nshwfp.dll TRUE
173 nshipsec.dll TRUE
174 nshhttp.dll TRUE
175 npmproxy.dll TRUE
176 nlansp_c.dll TRUE
177 nlaapi.dll TRUE
178 ninput.dll TRUE
179 newdev.dll TRUE
180 networkexplorer.dll TRUE
181 netutils.dll TRUE
182 nettrace.dll TRUE
183 netshell.dll TRUE
184 netsetupapi.dll TRUE
185 netprovfw.dll TRUE
186 netprofm.dll TRUE
187 netplwiz.dll TRUE
188 netjoin.dll TRUE
189 netiohlp.dll TRUE
190 netid.dll TRUE
191 netapi32.dll TRUE
192 ndfapi.dll TRUE
193 ncrypt.dll TRUE
194 napinsp.dll TRUE
195 mtxclu.dll TRUE
196 msxml3.dll TRUE
197 mswsock.dll TRUE
198 mswb7.dll TRUE
199 msvcp110_win.dll TRUE
200 msutb.dll TRUE
201 mstracer.dll TRUE
202 msiso.dll TRUE
203 msi.dll TRUE
204 msftedit.dll TRUE
205 msdtctm.dll TRUE
206 msdrm.dll TRUE
207 msctfmonitor.dll TRUE
208 msctf.dll TRUE
209 mscoree.dll TRUE
210 mscms.dll TRUE
211 msacm32.dll TRUE
212 mrmcorer.dll TRUE
213 mpsvc.dll TRUE
214 mprapi.dll TRUE
215 mpr.dll TRUE
216 mpclient.dll TRUE
217 mobilenetworking.dll TRUE
218 mmdevapi.dll TRUE
219 mlang.dll TRUE
220 miutils.dll TRUE
221 mintdh.dll TRUE
222 midimap.dll TRUE
223 mi.dll TRUE
224 mfplat.dll TRUE
225 mfcore.dll TRUE
226 mfc42u.dll TRUE
227 mdmdiagnostics.dll TRUE
228 mbaexmlparser.dll TRUE
229 mapistub.dll TRUE
230 maintenanceui.dll TRUE
231 magnification.dll TRUE
232 lrwizdll.dll TRUE
233 lpksetupproxyserv.dll TRUE
234 logoncontroller.dll TRUE
235 logoncli.dll TRUE
236 lockhostingframework.dll TRUE
237 loadperf.dll TRUE
238 linkinfo.dll TRUE
239 licensingdiagspp.dll TRUE
240 licensemanagerapi.dll TRUE
241 ktmw32.dll TRUE
242 ksuser.dll TRUE
243 kdstub.dll TRUE
244 joinutil.dll TRUE
245 iumsdk.dll TRUE
246 iumbase.dll TRUE
247 isv.exe_rsaenh.dll TRUE
248 iscsium.dll TRUE
249 iscsidsc.dll TRUE
250 iri.dll TRUE
251 iphlpapi.dll TRUE
252 inproclogger.dll TRUE
253 ifsutil.dll TRUE
254 ifmon.dll TRUE
255 iertutil.dll TRUE
256 iedkcs32.dll TRUE
257 ieadvpack.dll TRUE
258 idstore.dll TRUE
259 icmp.dll TRUE
260 httpapi.dll TRUE
261 hnetmon.dll TRUE
262 hid.dll TRUE
263 gpapi.dll TRUE
264 getuname.dll TRUE
265 fxstiff.dll TRUE
266 fxsst.dll TRUE
267 fxsapi.dll TRUE
268 fwpuclnt.dll TRUE
269 fwpolicyiomgr.dll TRUE
270 fwcfg.dll TRUE
271 fwbase.dll TRUE
272 fvewiz.dll TRUE
273 fveskybackup.dll TRUE
274 fveapi.dll TRUE
275 framedynos.dll TRUE
276 fltlib.dll TRUE
277 flightsettings.dll TRUE
278 firewallapi.dll TRUE
279 fhsvcctl.dll TRUE
280 fhcfg.dll TRUE
281 feclient.dll TRUE
282 fddevquery.dll TRUE
283 faultrep.dll TRUE
284 fastprox.dll TRUE
285 explorerframe.dll TRUE
286 execmodelproxy.dll TRUE
287 esent.dll TRUE
288 efsutil.dll TRUE
289 efsadu.dll TRUE
290 edputil.dll TRUE
291 edgeiso.dll TRUE
292 eappprxy.dll TRUE
293 eappcfg.dll TRUE
294 dynamoapi.dll TRUE
295 dxva2.dll TRUE
296 dxgi.dll TRUE
297 dxcore.dll TRUE
298 dwrite.dll TRUE
299 dwmcore.dll TRUE
300 dwmapi.dll TRUE
301 dusmapi.dll TRUE
302 duser.dll TRUE
303 dui70.dll TRUE
304 dsrole.dll TRUE
305 dsreg.dll TRUE
306 dsprop.dll TRUE
307 dsparse.dll TRUE
308 dsclient.dll TRUE
309 drvstore.dll TRUE
310 drprov.dll TRUE
311 dpx.dll TRUE
312 dot3cfg.dll TRUE
313 dot3api.dll TRUE
314 dnsapi.dll TRUE
315 dmxmlhelputils.dll TRUE
316 dmpushproxy.dll TRUE
317 dmprocessxmlfiltered.dll TRUE
318 dmoleaututils.dll TRUE
319 dmiso8601utils.dll TRUE
320 dmenterprisediagnostics.dll TRUE
321 dmenrollengine.dll TRUE
322 dmcommandlineutils.dll TRUE
323 dmcmnutils.dll TRUE
324 dmcfgutils.dll TRUE
325 dismcore.dll TRUE
326 dismapi.dll TRUE
327 directmanipulation.dll TRUE
328 dhcpcsvc6.dll TRUE
329 dhcpcsvc.dll TRUE
330 dhcpcmonitor.dll TRUE
331 devrtl.dll TRUE
332 devobj.dll TRUE
333 devicepairing.dll TRUE
334 devicecredential.dll TRUE
335 deviceassociation.dll TRUE
336 desktopshellext.dll TRUE
337 defragproxy.dll TRUE
338 dcomp.dll TRUE
339 dcntel.dll TRUE
340 dbghelp.dll TRUE
341 dbgcore.dll TRUE
342 davclnt.dll TRUE
343 dataexchange.dll TRUE
344 d3dcompiler_47.dll TRUE
345 d3d9.dll TRUE
346 d3d12.dll TRUE
347 d3d11.dll TRUE
348 d3d10warp.dll TRUE
349 d3d10core.dll TRUE
350 d3d10_1core.dll TRUE
351 d3d10_1.dll TRUE
352 d3d10.dll TRUE
353 d2d1.dll TRUE
354 cscui.dll TRUE
355 cscobj.dll TRUE
356 cscapi.dll TRUE
357 cryptxml.dll TRUE
358 cryptui.dll TRUE
359 cryptsp.dll TRUE
360 cryptdll.dll TRUE
361 cryptbase.dll TRUE
362 credui.dll TRUE
363 coreuicomponents.dll TRUE
364 coremessaging.dll TRUE
365 coredplus.dll TRUE
366 connect.dll TRUE
367 configmanager2.dll TRUE
368 comdlg32.dll TRUE
369 colorui.dll TRUE
370 coloradapterclient.dll TRUE
371 cmutil.dll TRUE
372 cmpbk32.dll TRUE
373 clusapi.dll TRUE
374 clipc.dll TRUE
375 cldapi.dll TRUE
376 certenroll.dll TRUE
377 certcli.dll TRUE
378 cabview.dll TRUE
379 cabinet.dll TRUE
380 bootux.dll TRUE
381 bootmenuux.dll TRUE
382 bderepair.dll TRUE
383 bcrypt.dll TRUE
384 bcp47mrm.dll TRUE
385 bcp47langs.dll TRUE
386 bcd.dll TRUE
387 batmeter.dll TRUE
388 avrt.dll TRUE
389 authz.dll TRUE
390 authfwcfg.dll TRUE
391 auditpolcore.dll TRUE
392 audioses.dll TRUE
393 atl.dll TRUE
394 archiveint.dll TRUE
395 appxdeploymentclient.dll TRUE
396 appxalluserstore.dll TRUE
397 appvpolicy.dll TRUE
398 applicationframe.dll TRUE
399 apphelp.dll TRUE
400 aepic.dll TRUE
401 adsldpc.dll TRUE
402 activeds.dll TRUE
403 amsi.dll TRUE
+52
View File
@@ -0,0 +1,52 @@
remote_utility, description, isutility
aweray_remote*.exe,AweRay (AweSun), TRUE
aa_v*.exe, Ammyy Admin, TRUE
AeroAdmin.exe, AeroAdmin, TRUE
anydesk.exe, AnyDesk, TRUE
AnyViewerSetup.exe, AnyViewer, TRUE
RCClient.exe, AnyViewer, TRUE
CService.exe, AnyViewer, TRUE
atera_agent.exe, Atera, TRUE
bomgar-scc.exe, BeyondTrust (Bomgar), TRUE
bomgar-rdp.exe, BeyondTrust (Bomgar), TRUE
screenconnect.clientservice.exe, ConnectWise Control, TRUE
screenconnect.windowsclient.exe, ConnectWise Control, TRUE
dwrcs.exe, Dameware, TRUE
distant-desktop.exe, Distant Desktop, TRUE
dwagsvc.exe, DW Service, TRUE
g2comm.exe, GoToMyPC, TRUE
g2fileh.exe, GoToMyPC, TRUE
g2host.exe, GoToMyPC, TRUE
g2mainh.exe, GoToMyPC, TRUE
g2printh.exe, GoToMyPC, TRUE
g2svc.exe, GoToMyPC, TRUE
g2tray.exe, GoToMyPC, TRUE
gopcsrv.exe, GoToMyPC, TRUE
ROMServer.exe, LiteManager, TRUE
ROMFUSClient.exe, LiteManager, TRUE
lmiignition.exe, LogMeIn, TRUE
lmiguardiansvc.exe, LogMeIn, TRUE
logmein*.exe, LogMeIn, TRUE
awrem32.exe, PCAnywhere Client, TRUE
awhost32.exe, PCAnywhere Server, TRUE
PCMonitorManager.exe, Pulseway, TRUE
pcmonitorsrv.exe, Pulseway, TRUE
radmin3.exe, RAdmin, TRUE
famitrfc.exe, RAdmin, TRUE
rutserv.exe, RemoteUtilities, TRUE
smpcsetup.exe, ShowMyPC, TRUE
showmypc*.exe, ShowMyPC, TRUE
strwinclt.exe, Splashtop, TRUE
supremo.exe, Supremo, TRUE
supremohelper.exe, Supremo, TRUE
supremosystem.exe, Supremo, TRUE
teamviewer_desktop.exe, TeamViewer Desktop, TRUE
teamviewer.exe, TeamViewer Service, TRUE
teamviewer_service.exe, TeamViewer Service, TRUE
winvnc.exe, VNC, TRUE
vncviewer.exe, VNC, TRUE
winvncsc.exe, VNC, TRUE
winwvc.exe, VNC, TRUE
Zaservice.exe, Zoho Assist, TRUE
Zohours.exe, Zoho Assist, TRUE
ZohoMeeting.exe, Zoho Assist, TRUE
1 remote_utility description isutility
2 aweray_remote*.exe AweRay (AweSun) TRUE
3 aa_v*.exe Ammyy Admin TRUE
4 AeroAdmin.exe AeroAdmin TRUE
5 anydesk.exe AnyDesk TRUE
6 AnyViewerSetup.exe AnyViewer TRUE
7 RCClient.exe AnyViewer TRUE
8 CService.exe AnyViewer TRUE
9 atera_agent.exe Atera TRUE
10 bomgar-scc.exe BeyondTrust (Bomgar) TRUE
11 bomgar-rdp.exe BeyondTrust (Bomgar) TRUE
12 screenconnect.clientservice.exe ConnectWise Control TRUE
13 screenconnect.windowsclient.exe ConnectWise Control TRUE
14 dwrcs.exe Dameware TRUE
15 distant-desktop.exe Distant Desktop TRUE
16 dwagsvc.exe DW Service TRUE
17 g2comm.exe GoToMyPC TRUE
18 g2fileh.exe GoToMyPC TRUE
19 g2host.exe GoToMyPC TRUE
20 g2mainh.exe GoToMyPC TRUE
21 g2printh.exe GoToMyPC TRUE
22 g2svc.exe GoToMyPC TRUE
23 g2tray.exe GoToMyPC TRUE
24 gopcsrv.exe GoToMyPC TRUE
25 ROMServer.exe LiteManager TRUE
26 ROMFUSClient.exe LiteManager TRUE
27 lmiignition.exe LogMeIn TRUE
28 lmiguardiansvc.exe LogMeIn TRUE
29 logmein*.exe LogMeIn TRUE
30 awrem32.exe PCAnywhere Client TRUE
31 awhost32.exe PCAnywhere Server TRUE
32 PCMonitorManager.exe Pulseway TRUE
33 pcmonitorsrv.exe Pulseway TRUE
34 radmin3.exe RAdmin TRUE
35 famitrfc.exe RAdmin TRUE
36 rutserv.exe RemoteUtilities TRUE
37 smpcsetup.exe ShowMyPC TRUE
38 showmypc*.exe ShowMyPC TRUE
39 strwinclt.exe Splashtop TRUE
40 supremo.exe Supremo TRUE
41 supremohelper.exe Supremo TRUE
42 supremosystem.exe Supremo TRUE
43 teamviewer_desktop.exe TeamViewer Desktop TRUE
44 teamviewer.exe TeamViewer Service TRUE
45 teamviewer_service.exe TeamViewer Service TRUE
46 winvnc.exe VNC TRUE
47 vncviewer.exe VNC TRUE
48 winvncsc.exe VNC TRUE
49 winwvc.exe VNC TRUE
50 Zaservice.exe Zoho Assist TRUE
51 Zohours.exe Zoho Assist TRUE
52 ZohoMeeting.exe Zoho Assist TRUE
File diff suppressed because one or more lines are too long
@@ -9,5 +9,5 @@ tests:
- file_name: linux-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1082/atomic_red_team/linux-sysmon.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: linux_sysmon
sourcetype: sysmon_linux
update_timestamp: true