network detections

This commit is contained in:
ljstella
2024-08-15 15:38:15 -05:00
parent 2b40bbedbd
commit 638c176a44
5 changed files with 14 additions and 14 deletions
+3 -3
View File
@@ -1,7 +1,7 @@
name: Detect ARP Poisoning
id: b44bebd6-bd39-467b-9321-73971bcd1aac
version: 2
date: '2024-05-12'
version: 3
date: '2024-08-14'
author: Mikael Bjerkeland, Splunk
status: experimental
type: TTP
@@ -46,7 +46,7 @@ tags:
- name: dest
type: Other
role:
- Other
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -46,7 +46,7 @@ tags:
- name: dest
type: Other
role:
- Other
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Rogue DHCP Server
id: 6e1ada88-7a0d-4ac1-92c6-03d354686079
version: 2
date: '2024-05-28'
version: 3
date: '2024-08-14'
author: Mikael Bjerkeland, Splunk
status: experimental
type: TTP
@@ -42,7 +42,7 @@ tags:
- name: dest
type: Other
role:
- Other
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Traffic Mirroring
id: 42b3b753-5925-49c5-9742-36fa40a73990
version: 2
date: '2024-05-09'
version: 3
date: '2024-08-14'
author: Mikael Bjerkeland, Splunk
status: experimental
type: TTP
@@ -45,7 +45,7 @@ tags:
- name: dest
type: Other
role:
- Other
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Windows DNS SIGRed via Splunk Stream
id: babd8d10-d073-11ea-87d0-0242ac130003
version: 2
date: '2024-05-28'
version: 3
date: '2024-08-14'
author: Shannon Davis, Splunk
status: experimental
type: TTP
@@ -36,10 +36,10 @@ tags:
mitre_attack_id:
- T1203
observable:
- name: dest
- name: flow_id
type: Other
role:
- Other
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security