mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
network detections
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
name: Detect ARP Poisoning
|
||||
id: b44bebd6-bd39-467b-9321-73971bcd1aac
|
||||
version: 2
|
||||
date: '2024-05-12'
|
||||
version: 3
|
||||
date: '2024-08-14'
|
||||
author: Mikael Bjerkeland, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -46,7 +46,7 @@ tags:
|
||||
- name: dest
|
||||
type: Other
|
||||
role:
|
||||
- Other
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -46,7 +46,7 @@ tags:
|
||||
- name: dest
|
||||
type: Other
|
||||
role:
|
||||
- Other
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect Rogue DHCP Server
|
||||
id: 6e1ada88-7a0d-4ac1-92c6-03d354686079
|
||||
version: 2
|
||||
date: '2024-05-28'
|
||||
version: 3
|
||||
date: '2024-08-14'
|
||||
author: Mikael Bjerkeland, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -42,7 +42,7 @@ tags:
|
||||
- name: dest
|
||||
type: Other
|
||||
role:
|
||||
- Other
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect Traffic Mirroring
|
||||
id: 42b3b753-5925-49c5-9742-36fa40a73990
|
||||
version: 2
|
||||
date: '2024-05-09'
|
||||
version: 3
|
||||
date: '2024-08-14'
|
||||
author: Mikael Bjerkeland, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -45,7 +45,7 @@ tags:
|
||||
- name: dest
|
||||
type: Other
|
||||
role:
|
||||
- Other
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect Windows DNS SIGRed via Splunk Stream
|
||||
id: babd8d10-d073-11ea-87d0-0242ac130003
|
||||
version: 2
|
||||
date: '2024-05-28'
|
||||
version: 3
|
||||
date: '2024-08-14'
|
||||
author: Shannon Davis, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -36,10 +36,10 @@ tags:
|
||||
mitre_attack_id:
|
||||
- T1203
|
||||
observable:
|
||||
- name: dest
|
||||
- name: flow_id
|
||||
type: Other
|
||||
role:
|
||||
- Other
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
Reference in New Issue
Block a user